The images in this article were generated with artificial intelligence. How we publish
There is a widespread idea between IT managers and managers: to hire Microsoft 365 is to have the data protected. This belief is not sustained when the facts and official documentation are examined. Microsoft guarantees the availability of the service and the security of its infrastructure, but the support, long-term retention and responsibility for data restoration rests with the customer; that's what sets out the shared responsibility model explained by Microsoft. https: / / learn.microsoft.com / en-us / azure / security / fundamentals / share-responsibility
In practice, this operational gap is translated into real risks. In the face of a Ransomware attack, in many incidents the OneDrive or SharePoint files are encrypted and that change is synchronized at high speed, contaminating versions and reciles. Native tools offer a history of versions and stationery, but do not automatically distinguish which restoration points are "clean" and do not provide unchangeable storage by default. This is why more and more equipment combines external copies, abnormal encryption detection and verified recovery points to be able to reverse without uncertainty.

The second critical crack is regulation and retention. Microsoft 365's retention policies serve basic governance, but many industries - health, finance, legal services - require time frames and audits that exceed what these rules allow. Retention is not synonymous with backup: to keep a message for X years does not ensure full restoration to mass erased, corruption or litigation. To meet regulatory requirements, a separate storage strategy, with traceability and regular restoration tests, must be designed.
Granular recovery is another area where expectations collide with operational reality. In most incidents it is not necessary to restore the entire tenant; the useful thing is to recover a specific mail, a Teams conversation or a folder in SharePoint without interrupting the rest of the business. Native options can force complex processes or complete restorations, increasing inactivity time. A backup solution focused on precise recoveries reduces the operational impact and human cost of incidents.
Internal threats and phishing complete the risk table: compromised accounts allow to remove, modify or exfilter data from legitimate sessions and detection may be late. Although Microsoft incorporates prevention and detection controls, the rapid restoration of "clean data" is part of the incident response and is not always automated. Integrating cybersecurity capabilities with backup accelerates recovery and makes restoration part of the response plan, not a manual and reactive task.
There is also an economic and organizational problem: the native backup model may not scale up efficiently for growing companies or for managed service providers (MSP). Costs and administrative complexity increase when the data footprint grows or multiple tenants are managed. This is why many organizations value architectures with predictable prices, centralized administration and user-by-user models that facilitate unsurprised expansion on the bill.
What to do today, in a practical way? Start by clearly documenting your liability model and audit the actual coverage of your data in Microsoft 365. Mapée regulatory obligations to retention policies and require technical evidence of recoverability. Incorporate independent backup to provide Unchangeable storage, ansomware detection and automated restoration tests. Ensure that the solution allows granular recoveries and supports multi-tenant if your organization works with MSPs. For resources and practical guides on Ransomware prevention and response, the authorities offer useful material: see the CISA StopRansomware initiative. https: / / www.cisa.gov / stopransomware

In addition to the copies, keep the foundations of good governance: MFA and conditional access, principle of less privilege, DLP to control exfiltration, monitoring and retention of logs outside the productive environment, and regular recovery exercises that validate processes and times. Also plan segregation and storage outside the productive environment (air-gapped or independent) to protect against attacks directed at the service provider itself.
Not all organizations will have exactly the same solution; some will opt for platforms that combine backup and detection (such as commercial alternatives available on the market), others for specialized toolsets made up of the security team. The essential thing is stop considering backup as optional and design it as an integral part of cyberresilience strategy. If you are looking for information on commercial offers that address these gaps, you can review the pages of suppliers that describe specific Microsoft 365 protection capabilities and verified recovery. https: / / www.acronis.com / en-us / cloud / office-365-backup /
The conclusion for IT and compliance managers is clear: Microsoft 365 is a powerful productivity platform, but it does not replace a deliberate data protection strategy. It assumes responsibility, measures risk, tests restorations and deployments external copies with technical guarantees. That previous work is the one that reduces the real cost of an incident, protects business continuity and avoids lost weekends trying to guess which version of a file is "safe."
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...