Most Singapore SMEs don’t have a backup problem — they have a backup sizing problem. A quote arrives, someone compares the per-GB or per-seat numbers, picks the middle tier, signs a 12-month term, and only discovers six months later that the retention window is too short for the auditor or the storage cap is being hit every single month. By then the contract is locked in and the overage fees are quietly eating the IT budget. Getting the sizing right before you sign is far cheaper than renegotiating after.
Why backup sizing goes wrong in the first place
The root cause is that most buyers size backup by price and seat count, not by recovery requirements. A 50-person Singapore SME with Microsoft 365 mailboxes, a file server and two VMs looks ‘small’ on paper — until you account for mailbox growth, Teams chat retention, versioning, and the fact that PDPA obligations don’t shrink just because your headcount is modest.
There’s a second, very Singapore-specific factor: PDPA. The Personal Data Protection Commission expects organisations to protect personal data with reasonable security arrangements, and to stop retaining it once the purpose is served. That cuts both ways. Retain too little and you can’t produce records during an investigation or a customer dispute. Retain everything forever without a defined purpose and you’re arguably over-retaining. Neither extreme is comfortable in an audit.
The third factor is that storage and retention are usually sold as one bundle. They aren’t the same thing, and treating them as one number is how SMEs end up overbuying capacity they never touch while underbuying the retention that actually matters. A cloud-to-cloud service such as Barracuda Cloud Backup separates the two, which is exactly why sizing it properly is worth the effort.
Step 1: Size retention by obligation, not by habit
Retention should be driven by what you’re required to keep, not by whatever the default tier happens to offer. Work through these categories for your own organisation:
- Regulatory and PDPA-driven records — know how long you genuinely need to hold personal data and the business records around it, and make sure your backup retention at least covers that window.
- Contractual and customer commitments — service agreements, warranties and client contracts often imply a retention period longer than your internal policy.
- Operational recovery — how far back do you realistically need to restore a mailbox, a file or a VM after a mistake, a ransomware event or an accidental deletion?
- Litigation and dispute readiness — if a customer dispute lands 18 months from now, can you produce the correspondence and records that support your position?
Take the longest of those windows and use it as your baseline. Unlimited retention sounds like overkill until you realise that ‘unlimited’ simply means you stop guessing — you keep what you need for as long as the obligation exists, and you stop paying to store data that no longer serves a purpose. For most SMEs the honest answer is that the retention requirement is longer than the default tier, and shorter than forever.
Step 2: Separate storage from retention and stop paying for both blindly
Storage capacity and retention length are different line items and should be evaluated separately. A few practical checks before you commit to a term:
- Measure your actual data footprint — total mailbox size, file server volume, VM disk usage, plus a growth buffer. Don’t estimate from seat count.
- Check what counts toward the cap — versioning, deleted-item retention and archive data all consume storage. Ask specifically how each is counted.
- Model the overage rate — if you exceed the cap in month four, what does the next gigabyte cost? An unlimited-retention plan with a clear storage model is easier to budget than a tier that surprises you.
- Confirm the recovery target — how quickly can a single mailbox or an entire VM be restored, and is that tested or just promised?
This is where a cloud-to-cloud approach earns its place. Because the backup lives in the cloud rather than on a local appliance you maintain, capacity planning becomes a conversation about data, not about hardware refresh cycles. If you’d rather not run this analysis in-house, Sakal Network’s managed IT team can scope it against your actual environment before you sign anything.
Step 3: Set recovery targets you can actually meet
Two numbers define your backup, and both should be written into the contract rather than assumed:
- RPO (Recovery Point Objective) — how much data can you afford to lose? If your answer is ‘a few hours’, your backup frequency needs to match, not default to a nightly job that leaves a full working day exposed.
- RTO (Recovery Time Objective) — how long can the business be down? For a Singapore SME with tight customer SLAs, ‘we’ll get to it’ is not a recovery target.
Write both into the agreement and confirm they’re tested, not just stated. A backup you’ve never restored from is a subscription, not a safety net. The same discipline applies to Microsoft 365 data — many SMEs assume Microsoft backs it up for them, when in fact the shared responsibility model puts that obligation squarely on the organisation.
Do the sizing before the 12-month term, not after
Backup is one of the few IT decisions where the cheapest option and the right option are rarely the same, and where the cost of getting it wrong shows up at the worst possible moment — during an audit, a ransomware incident or a customer dispute. Before you sign a 12-month term in 2026, write down your retention obligation, your real data footprint, and your RPO and RTO. If those three answers fit the plan you’re being quoted, sign with confidence. If they don’t, change the plan — not your requirements. Need help sizing it against your actual environment? Talk to Sakal Network and we’ll scope it with you, no pressure and no obligation.