A self-storage facility office runs on a stream of ordinary operational files that keep the property running day to day: tenant records and rental agreements, billing and autopay history, delinquency and payment-status records, gate-access codes and unit-assignment and unit-status data, insurance certificates and vendor records, move-in and move-out records, unit photos, accounting files, and payroll. Most of that lives on one or two Windows computers in the office. The honest question every self-storage operator needs to answer is whether they could pull up a specific tenant's rental agreement, current unit assignment, and payment history on the day the office PC crashes, a drive fails, or ransomware locks the network down.
Everyday Backups provides managed, encrypted cloud backup for Windows computers, with monitoring, restore support, and regular backup health reporting. Paid plans from $5.99/mo.
A self-storage or mini-storage facility builds its record of every tenant and every unit it has ever rented, one rental agreement at a time. That record lives almost entirely as digital files on a Windows PC at the front office, a facility manager's workstation, or a shared network folder. The list below covers what a working facility office should be able to recover, for a specific tenant and a specific unit, when a hardware failure or a security incident demands it.
A gap in any of these categories becomes a real problem in a specific moment. If a tenant disputes a charge and the payment history cannot be found, the office has nothing to show them. If the gate-access list is gone after a hard drive failure, staff cannot confirm who is authorized to enter the property. If a unit's move-out condition photos disappear, there is no record to compare against a later damage or cleanliness dispute.
The situations below are the practical moments when a backup matters, or a backup gap becomes a crisis. Each one has a different trigger, but they share a common outcome when no independent off-site backup exists.
A failed hard drive on the main office computer during a busy rental season means no access to current tenant records, no way to confirm which units are occupied or vacant, and no visibility into who is current or past due on rent. If the machine also held the QuickBooks file, the accounting gap compounds the operational one immediately. A backup means you recover the data and lose hours; without one, you may be rebuilding tenant and unit records from scratch while walk-in customers are still asking to rent a unit.
CISA and the FTC both identify small businesses as ransomware targets. When ransomware runs, it typically encrypts all accessible files on the local machine and any network shares mounted at the time. A cloud sync folder replicates the encrypted versions within seconds. A backup that is not continuously connected to your network is the copy that survives with usable data intact. Without it, recovery means paying a ransom with no certainty of results, or rebuilding tenant, billing, and unit-assignment records from nothing.
A hardware failure or corrupted database on the machine running your gate-access system can leave staff unable to confirm which codes are active, which units are currently occupied, or who is authorized to enter the property. Without a backup of that data, restoring accurate access permissions and unit-status records can mean manually re-verifying every unit on the property against paper records, if those exist at all.
A tenant contacts the office weeks or months after vacating a unit, disputing a late fee, a cleanout charge, or the condition the unit was left in. The signed rental agreement, the payment history, and the move-out photos are the office's only documentation. If those records exist only on the office machine and no backup was running during that period, the documentation needed to respond to the dispute is gone.
A routine cleanup of the unit-photo folder, a wrong-folder deletion during a file reorganization, or an application update that corrupts a local database does not require a dramatic hardware event to cause real data loss. Cloud sync propagates the deletion or overwrites the corrupted version immediately. A backup with version history lets you recover the folder as it existed before the deletion, from a point in time before the problem occurred. Sync alone offers no such recovery path.
When the person who has run the front office for years departs, they often take with them the organizational logic of where files are stored. Delinquency tracking spreadsheets, unit-assignment notes kept outside the main system, and vendor files saved to personal desktop folders may never transfer to the incoming manager. A backup that captures everything on the machine, regardless of folder structure, preserves what is there even when the departing person's organization approach is not obvious to anyone else.
The 3-2-1 rule is a straightforward framework promoted by CISA and used widely in small-business backup guidance. For a self-storage facility running a Windows front office, here is what it looks like applied to the files that actually matter in this business.
Your working copy on the office PC or server counts as one. A second copy might be a local external drive or a secondary workstation. A third copy, off-site in encrypted cloud storage, is the copy that protects against a local disaster affecting both of the first two copies at once. All three copies have to exist before the failure event for the rule to help. A facility that runs on a single office PC with no secondary copy anywhere is operating with a single point of failure for every tenant record, rental agreement, and unit photo the business has ever produced.
Keeping backups only on the same type of storage, such as two drives in the same machine or on the same local network, does not provide meaningful redundancy against hardware failure or a building event. CISA guidance calls for at least two different storage types, for example a local drive and a separate cloud destination, as distinct and independent layers of protection.
Off-site means physically separated from your facility office. Cloud backup satisfies this requirement when the data is sent to a separate data center rather than just an external drive in the same room. The off-site copy is the one that matters most when everything at the office location is affected at once, whether that is a fire, a theft, or a ransomware attack that hits every connected device on the network at the same time.
CISA specifically recommends maintaining at least one backup copy that is not continuously connected to the network. Ransomware increasingly targets connected backup systems as part of the same encryption sweep that hits production files. A cloud backup that is not directly mounted on your local network provides a layer that ransomware cannot reach and encrypt alongside your primary data, which is the version most likely to survive a ransomware event with usable files intact.
The checklist below reflects CISA small-business backup principles and FTC small-business cybersecurity guidance, applied to the file environment of a working self-storage facility office. This is a starting framework for backup decisions, not legal, regulatory, or compliance advice.
For a broader self-assessment of your current backup posture, see the small-business backup checklist. If your operation also manages residential rental housing alongside storage units, see backup for property management companies for how similar principles apply to leases and tenants-in-homes. If you want a deeper look at recovering specifically from a ransomware incident, see ransomware restore readiness.
Two software categories generate the bulk of a self-storage facility's critical operational data: the storage or facility-management platform, which typically also drives gate access and unit assignment, and the accounting system. Understanding what your backup does and does not cover for each is essential before you assume you are protected.
Storage and facility-management platforms store their data in different ways depending on the software. Some install a local database on a Windows server or workstation in the office. Others operate as web-based platforms where the primary database lives on the vendor's servers rather than your machines. A separate gate-access system, whether integrated with your facility-management software or running as its own product, maintains its own database of active codes, unit assignments, and entry logs. The key questions to answer for your backup configuration are: where does each system store its data files on your Windows machine, are those files included in your backup scope, and are they captured in a consistent state when the application is not actively writing to them.
If your storage or facility-management software is cloud-based with data primarily on the vendor's servers, the local backup question shifts to what you save locally from that system: rental agreement PDFs downloaded to the office PC, move-in and move-out photos transferred from a manager's phone, delinquency tracking exports, and any other files written to Windows machines in your office. Those locally stored files remain your responsibility to back up independently. The vendor's copy of your data in their cloud is not a substitute for your own backup of what lives on your machines, and vendor data retention policies can change.
Some facility-management platforms allow you to configure automatic export paths or scheduled data exports that write to a specific local folder. If your software has this capability, setting up an export to a known folder path and including that folder in your backup scope is a practical way to ensure tenant records and unit-assignment data are covered alongside your other business files. Verify this with your specific software's documentation, as behavior varies across platforms.
Many self-storage operators use QuickBooks for revenue tracking, payroll, vendor payments, and tax preparation. QuickBooks company files (.QBW) can grow to several gigabytes, are frequently stored on a single office desktop or network share, and are the source of truth for the business's complete financial history. Intuit's own documentation recommends maintaining backup copies of QuickBooks data files in a separate location from the original, and specifically notes that backing up only to the same machine is not adequate protection against hardware failure.
Common QuickBooks backup oversights at small self-storage operations include the company file stored on one machine with no second copy, the Intuit automatic backup feature saving to a different folder on the same drive as the original, and portable company files (.QBM) treated as complete backups when they are actually compressed snapshots that may not include all supporting files. A complete backup of QuickBooks for a self-storage facility covers the company file itself, the backup copy that QuickBooks may write to its own backup folder, and any exported rent-roll or delinquency reports the business saves separately.
For a detailed look at QuickBooks backup practices, consult Intuit's own backup documentation, which is the authoritative source for QuickBooks-specific backup configuration steps.
Many small self-storage operators have OneDrive, Dropbox, or a similar sync service running on their office machines and assume that sync protects their business data. The distinction between sync and backup matters significantly in the situations where you actually need to recover something.
Cloud sync mirrors the current state of your files on the device to a cloud destination. When a file changes on your machine, the change replicates to the cloud, usually within seconds or minutes. When a file is deleted, the deletion replicates. When ransomware encrypts a folder of unit photos or rental agreements, the encrypted versions overwrite the cloud copies before you have a chance to notice the attack. At that point, both the local copy and the cloud sync copy are encrypted, and the sync service has preserved nothing useful.
Backup retains point-in-time copies with version history. You can restore files as they existed at a specific date and time in the past, before the deletion, before the corruption, or before the ransomware ran. That version history is what makes backup genuinely useful in a recovery event, as opposed to sync, which can only give you the current state of the file, whatever that current state happens to be.
Microsoft's own OneDrive documentation describes Personal Vault and version history features, but these are not a substitute for an independent backup with a defined retention window and monitoring. The version history available through OneDrive is limited by duration and plan, and the restoration interface is not designed for recovering a business's complete data set after a significant incident.
The FTC and CISA both publish guidance specifically noting that small businesses, including small property and facility operations, are targets of ransomware campaigns. The reason is practical: small businesses often have less IT infrastructure than larger organizations, making them easier to compromise, while still holding tenant data, billing histories, and financial records that create pressure to pay a ransom rather than lose years of business documentation.
For a self-storage facility, the factors that make ransomware particularly consequential include tenant records, billing history, and gate-access data concentrated on a small number of Windows machines, QuickBooks accounting covering years of revenue and tax data stored locally, delinquency and payment-status records with no off-site copy, and typically no dedicated IT staff checking backup health on a regular basis.
CISA's #StopRansomware guidance identifies offline and encrypted backup copies as the primary technical recovery mechanism when ransomware has encrypted production files. The critical point is that a backup connected to the same network as the infected machines, or a sync folder that replicates changes in real time, may itself be encrypted before the attack is detected. A backup that is not continuously mounted on your local network is the copy most likely to survive with usable data intact.
Ransomware recovery is not only a technology question. Even with a solid backup in place, a ransomware incident typically means some period of downtime while systems are cleaned and data is restored. A backup does not eliminate downtime, but it is the difference between recovering from a difficult week and potentially losing years of tenant records, billing history, and financial history with no path back. A backup you have tested and confirmed works is worth substantially more than one you have never restored from. For a deeper look at preparing for that specific scenario, see ransomware restore readiness.
Yes, for two distinct reasons. First, even with a cloud-based storage or facility-management platform, your business almost certainly saves files locally to Windows machines: rental agreement PDFs, move-in and move-out photos transferred from a manager's phone, gate-access exports, QuickBooks accounting files, and tenant correspondence. Those locally stored files are not backed up by the software vendor. Second, the vendor storing your data in their cloud is not the same as you having an independent backup of that data that you control and can restore from on your own timeline. Vendor data retention policies, subscription terms, and access rules can all change. Your own backup is a separate protection layer.
The most common discovery moments are a hard drive failure on the main office PC, a ransomware incident that encrypts multiple machines at once, and a tenant dispute over a charge or a move-out condition where a specific rental agreement or unit photo from a past date cannot be found. Each of those events surfaces gaps that were invisible while the business was running normally. The gap is real whether it is discovered or not; discovering it in a quiet moment with time to fix it is much better than discovering it mid-crisis when the documentation is already gone.
No. Everyday Backups is a general file-backup service, not a legal or records-compliance tool, and does not satisfy any lien-law, auction-notice, record-retention, state self-storage regulation, or other legal or regulatory obligation that may apply to your facility. Rental agreements, delinquency records, and gate-access data are treated here only as ordinary operational business files, the same way an invoice or a spreadsheet is treated. Your facility keeps its own regulatory, lien, and recordkeeping obligations regardless of what backup service you use. For any actual lien-law, auction, or compliance requirement, consult qualified legal advisors familiar with self-storage regulation in your state.
For most self-storage facilities, move-in and move-out photos are among the most valuable files in the business, and among the most likely to be lost, because they are often captured on a manager's personal phone and only sometimes transferred to a shared office folder. If those photos exist in only one place, whether that is one phone or one office folder, they have no protection against loss, damage, or accidental deletion. Backing up the office folder where photos are consolidated, and encouraging prompt transfer of photos off individual devices, closes a common and costly gap.
No, and the difference matters significantly for ransomware protection and accidental deletion. Cloud sync mirrors the current state of your files. If a file is deleted, overwritten, or encrypted by ransomware, that change replicates to the sync destination, often within seconds. Backup retains point-in-time copies with version history so you can restore files as they existed before the damage. Microsoft's OneDrive documentation describes version history features, but those are limited by duration and plan, and are not designed as a replacement for a managed backup with a defined retention window and monitoring.
CISA guidance recommends maintaining enough backup history to recover from incidents that are not discovered immediately. Ransomware and file corruption are often not noticed for days or even weeks after the event that caused them. A backup window of 24 to 48 hours is almost never sufficient for a working business. Thirty days of version history is a practical minimum. Some self-storage operators choose to retain longer histories for rental agreements and delinquency records that might be referenced in a dispute months after the original transaction.
A backup job failure should get immediate attention, not be deferred to a weekly review. The first step is understanding why it failed: the machine was off during the scheduled backup window, a file was locked by a running application, available disk space ran out, or a network or credential issue prevented the upload. Each of those has a different resolution path. If backup failures go unnoticed for an extended period, the business is operating without coverage, and a failure or ransomware event during that window has no recovery path. Backup monitoring that sends an alert on failure is the baseline way to avoid discovering a months-long gap only at the moment you need to restore.
Institutional backup knowledge leaving with one person is one of the more common ways a backup that was once configured and working gradually becomes unreliable. The backup may continue running, but no one in the business knows what it covers, where the data goes, or how to start a restore. The practical mitigation is to write down the answers to three questions while that person is still available: what is backed up (which machines, which folders), where does the backup data go (which service, which account), and how do you initiate a restore. Those three answers, stored somewhere accessible to the owner or another manager, preserve the value of the backup investment through personnel changes.
Everyday Backups installs on Windows machines, monitors backup job health, sends alerts when a backup fails or goes overdue, maintains version history so you can recover files from a prior point in time, encrypts data in transit and at rest, and stores backups in off-site cloud infrastructure rather than local media that could be affected by the same event as your primary machines. The service is designed to be configured once and then run automatically in the background, with monitoring and health reporting so you know the backup is working without checking it manually each day. For facilities with more than one Windows machine, such as a front-desk PC and a manager's accounting computer, each machine requires its own backup coverage.
Whether you want to check your current situation on your own first or talk it through with someone who can give you a second set of eyes, there is a starting point that fits.
The 2-minute self-check at everydaybackups.com/a/backup-risk-check.html asks a short set of questions about your current setup and tells you where the gaps are. No signup required. It takes about two minutes and gives you a clear picture of where you stand right now.
If you would rather talk through your specific setup, our team offers a free 15-minute Backup Risk Check. We look at what you have, identify the gaps, and give you honest guidance on what to fix first, whether or not you use Everyday Backups to do it. Schedule at app.everydaybackups.com/contact or call us at 850-980-3691.
Everyday Backups is a general file-backup service, not a legal, regulatory, or records-compliance tool. It does not by itself satisfy any lien-law, auction-notice, record-retention, state self-storage regulation, consumer-protection, privacy, or other legal or regulatory requirement applicable to a self-storage or mini-storage facility. Your facility keeps its own regulatory, lien, and recordkeeping obligations regardless of what backup service is used. References to tenant records, rental or lease agreements, billing and delinquency records, gate-access and unit-assignment data, insurance certificates, and move-in and move-out records refer only to ordinary operational files saved to Windows machines and are not claims that Everyday Backups satisfies any regulatory recordkeeping, lien, or auction obligation. No compatibility with any specific storage-management, gate-access, accounting, or other application is guaranteed or implied; verify backup scope and file coverage with your own IT review. Mention of software categories such as storage-management software, facility-management software, or gate-access systems is for illustrative purposes only and does not constitute endorsement of or claimed compatibility with any specific vendor or product. References to CISA, FTC, Intuit, and Microsoft documentation are for informational context only and do not constitute endorsement by those organizations. Consult qualified legal, tax, and industry-specific advisors for requirements specific to your business.
Everyday Backups runs on Windows, iPhone, iPad, and Android. Set it once; it backs up automatically, encrypted, off-site. Paid plans from $5.99/mo.
Prefer to talk to a person? Call 850-980-3691
Want a second set of eyes? Schedule your free 15-minute Backup Risk Check with our team