MicroBackupsMicroBackups

Customer stories

How businesses use MicroBackups to recover from disasters, achieve compliance, and sleep better at night.

Ransomware RecoveryMicrosoft 365OneDrive

Ransomware encrypted 400GB of OneDrive data

Restored clean files in under 2 hours. Zero ransom paid.

A mid-sized law firm with 120 employees was hit by a ransomware attack that encrypted 400GB of OneDrive data across their Microsoft 365 environment. The firm's native retention had been wiped out by the attacker, who had gained admin access days earlier.

The challenge

The attack exploited a compromised admin account to delete SharePoint and OneDrive version history before encrypting files. By the time IT discovered the breach, the native recycle bin had been purged. The firm faced either paying a ransom exceeding $500,000 or losing years of case files, contracts, and client communications.

The solution

MicroBackups' immutable WORM storage meant the attacker's deletion of native backups had no effect on the firm's MicroBackups snapshots. The IT team used the point-in-time restore feature to identify a clean snapshot from 72 hours before the detected infection. Using MicroBackups' parallel processing, the full 400GB was restored in under 2 hours.

The results

  • 400GB restored in under 2 hours
  • Zero ransom paid
  • Clean snapshot from 72 hours prior preserved
  • Full file metadata and permissions intact
  • No data permanently lost
The attackers deleted everything they could reach — but they couldn't reach our MicroBackups snapshots. We were back up and running before most of our staff arrived that morning.

IT Director, Legal

HIPAAComplianceGoogle Workspace

HIPAA compliance required for patient data in Google Workspace

Full HIPAA compliance achieved. BAA signed. Audit passed.

A healthcare technology company building patient management software needed to ensure their Google Workspace environment — used to store patient-related documents and communications — met HIPAA requirements.

The challenge

Their compliance team identified that Google Workspace's native backup capabilities did not meet HIPAA's requirements for ePHI protection: no BAA for backup, limited retention, no audit trail for data access, and no immutable storage to prevent data tampering.

The solution

MicroBackups signed a Business Associate Agreement (BAA) with the company. Data residency was configured to the US region. Granular audit logs were enabled for all backup access and restore operations. Immutable storage was activated for all ePHI-containing workloads.

The results

  • BAA signed within 24 hours of request
  • HIPAA audit passed without findings
  • Full audit trail for all data access
  • ePHI stored with AES-256 encryption
  • Data residency confirmed to US region
Our compliance officer specifically asked for MicroBackups by name after reviewing our options. The BAA was signed the same day, and we had everything documented for our audit within a week.

CTO, Healthcare Technology

Accidental DeletionGoogle WorkspaceRecovery

Accidental mass deletion of shared Drive files by a contractor

All files restored in 45 minutes. No client work lost.

A 60-person marketing agency experienced a major incident when a departing contractor mistakenly deleted a Shared Drive containing three years of client creative assets — approximately 80GB of files.

The challenge

The contractor had been granted Shared Drive manager permissions for their final week of handover. During a bulk cleanup, they deleted the wrong drive entirely. Google's native 30-day trash retention was the only safety net — and that window was almost exhausted, with other recent deletions making it unclear which files had been properly archived.

The solution

The agency used MicroBackups' full-text search to identify the exact state of the Shared Drive from a snapshot taken the previous evening — before the deletion occurred. The entire drive was restored to its original location using MicroBackups' cross-location restore feature, preserving all folder structures, document IDs, and sharing permissions.

The results

  • 80GB of creative assets fully restored
  • Restoration complete in 45 minutes
  • All folder structures and permissions intact
  • Google Doc IDs preserved — no broken links
  • Client deliverables unaffected
We had three years of client work disappear in seconds. MicroBackups had it back in 45 minutes. The clients never knew anything had happened.

Operations Manager, Marketing Agency

PCI DSSSOC 2ComplianceMicrosoft 365

PCI DSS and SOC 2 compliance with data residency requirements

Compliance achieved across two jurisdictions. Audit documentation complete.

A financial services firm operating across the US and EU needed to ensure their Microsoft 365 backup solution was compliant with both PCI DSS (for cardholder data environments) and GDPR (for EU customer data), with strict data residency requirements in both regions.

The challenge

Their existing backup vendor could only store data in the US, creating a GDPR violation for their EU operations. Additionally, the vendor could not provide a SOC 2 Type II report, which was required for their own SOC 2 audit.

The solution

MicroBackups configured separate storage regions for US and EU data within a single multi-tenant dashboard. US cardholder data was stored in the US region (PCI DSS compliant). EU customer data was routed to the EU region (GDPR compliant). MicroBackups provided their SOC 2 Type II report and PCI DSS certification documentation for inclusion in the firm's own audit.

The results

  • Separate US and EU storage regions configured
  • GDPR DPA signed for EU data
  • PCI DSS compliance documentation provided
  • SOC 2 Type II report provided under NDA
  • Passed own SOC 2 audit with no backup-related findings
No other vendor could give us separate US and EU data residency in a single product at this price point. MicroBackups solved a problem that was blocking our EU launch.

Head of Engineering, Financial Services

Write your own success story

Start a free trial today — no credit card required.

Start Free Trial