Skip to Content

Data Backup for Manufacturers

A Shop Owner's Checklist
August 12, 2025 by
Jay Stoltzfus
Jay Stoltzfus

The compressor kicks on at 5:50 Monday morning. Coffee is going, first shift is walking in, and your lead guy opens the folder to pull the print for the job that ships Thursday.

It is empty. So is the folder next to it, and the one after that.

Now you are standing in the office at six in the morning trying to remember the last time anybody actually checked that the backup ran. That question decides your whole week, which is why data backup for manufacturers is a production issue before it is ever an IT issue. The crash is not the disaster. Not being able to come back from it is.

Forget the scary statistics for a minute and do your own math instead. Take your shop rate. Multiply it by the machines that cannot run without a print or a program. Multiply that by the hours it would take to get files back. Add the office time to re-key everything that was lost, and the ship date you now have to explain to a customer who has other options. That number is what your backups are actually worth, and most owners have never run it.

Here is the plain-English version we walk through with shops around Parkesburg and across Chester and Lancaster County. No acronym soup. Just the things that have to be true before something goes wrong.

Why Losing Files Is a Production Problem, Not an IT Problem

A shop with fifteen people does not have "data" in the abstract sense. It has the operational memory of the business sitting on one or two boxes in a closet, usually next to a mop bucket:

  • Prints and revisions, including the ones a customer will swear they never approved
  • SolidWorks, Mastercam, and Fusion 360 files, plus the post processors and tool libraries somebody spent years dialing in
  • Travelers, routers, and job history inside your JobBOSS, E2, or Epicor database
  • Quality records, inspection reports, and material certs a customer can ask for two years after the parts shipped
  • Quotes and pricing history, which is the only reason you know what a job like this one should cost
  • QuickBooks, payroll, and every vendor agreement you have signed

Lose the shared drive and you do not lose files. You lose the ability to run the jobs already on the floor while simultaneously trying to prove to a customer that you are still a going concern.

There is a second reason this has stopped being optional. Two outside forces now audit your backups whether you invite them to or not. The first is your insurance carrier, which asks pointed questions at renewal about offsite copies, encryption, and testing, and prices the policy on your answers. That is what your cyber insurance carrier is really asking about when the form gets long. The second is your biggest customer. Tier-one OEM security questionnaires have worked their way down to shops with twenty employees, and "we think our IT guy handles that" is not a passing answer.

What Actually Takes Shops Down

The failures that put a floor at a standstill are almost never dramatic:

  • Drives fail. More often than the guy who sold you the server implied, and usually on the oldest machine holding the most important data.
  • People make ordinary mistakes. A folder gets dragged into another folder. Somebody saves over the good revision at 4:45 on a Friday.
  • Ransomware finds small manufacturers on purpose. Attackers know a shop that cannot ship has strong motivation to pay fast. This is also why antivirus alone stopped being enough years ago.
  • Physical trouble happens. Fire, a sprinkler head, a roof leak over the office, a break-in that takes the tower under the desk.
  • Corruption spreads quietly. A database goes bad in March and nobody notices until June, by which point every "good" backup is a copy of the bad file.

Only one of those five is a hacker. A plan built for all five survives the boring failures too.

A Data Backup Plan Any 15-Person Shop Can Run

None of this requires an enterprise budget or a full-time IT department. It requires nine things being true.

1. Find out what you actually have

Find every place data lives. Not where it is supposed to live: where it actually is. The server, sure, but also the CMM that saves reports locally, the estimator's laptop that rides around in a truck, the personal cloud account somebody created in 2019 to send a customer a file, and the desktop of the office manager's PC, which is doing more load-bearing work than anyone admits.

Then check the size and the growth curve. Most shops find out they are near capacity only when backups start failing silently. Keep at least 25 percent free space in your backup storage so a big month of new files does not quietly break the job.

2. Get a copy off the property

If every copy of your prints is inside the same building as your machines, you do not have a backup. You have a second hard drive with the same exposure to fire, water, and theft.

An encrypted offsite copy fixes that: the data is scrambled in transit and at rest, it lives somewhere geographically separate, and it is reachable from anywhere if the building itself is the problem. This is also the copy that saves you during ransomware, since it is the one an attacker on your network cannot easily reach.

3. Keep a local copy too

Offsite copies are for surviving. Local copies are for speed.

Do the bandwidth math once and it becomes obvious. Pulling two terabytes of CAD data back down a normal shop internet connection can take days, and days is not a number your Thursday ship date can absorb. A local backup puts prints and programs back in hours instead. Encrypt that drive, keep it in a locked cabinet or a fireproof safe, and swap the media on a schedule so a five-year-old drive is not your last line of defense.

Most shops that get this right end up with both: a local copy for fast recovery, an offsite copy for real disasters. That combination is the backbone of any backup and recovery plan worth the name.

4. Automate it and stop trusting memory

Manual backups fail for one reason: they depend on a person remembering during the exact week nobody has time to remember anything. Every "we copy it to a drive when we think of it" system eventually becomes "the last copy is from when we still had that other machinist."

Schedule it instead. Run the heavy jobs overnight or between shifts, throttle the bandwidth so the ERP does not crawl while it runs, and let it happen without anybody deciding to make it happen. Daily for what the floor and office touch, weekly for full system images, monthly for archives.

5. Test a restore before you need one

This is the step almost everybody skips, and it is the only one that proves the other eight worked.

Skip the acronyms and ask two owner questions instead. First: how long can the floor sit idle before it costs you real money? Second: how much re-entered work can you live with, an hour of it or a full day? Those two answers tell you how fast your recovery needs to be and how often the backup needs to run. Everything else is just plumbing.

Then test it quarterly. Pick a few random files from different backup sets, restore them to a machine that is not production, time how long it takes, and write down what broke. A backup you have never restored from is a theory. The middle of a crisis is a terrible place to discover the theory was wrong.

6. Keep versions, not just last night's copy

One copy of last night protects you from a drive failure. It does nothing for corruption, a bad revision, or ransomware that sat quiet for two weeks before it triggered.

Keep at least three historical versions of critical files so you can go back to a known-good point, and snapshot before major software updates, especially anything touching the ERP or the CAD workstations.

7. Watch the logs weekly, on every shift

Backup systems break the way everything else in the shop breaks: gradually, then all at once. A job that started failing in March is worthless in November, and nothing about it announced itself.

Somebody needs to review completion logs and error reports weekly, verify capacity, and confirm the schedule is still running after every software update. If you run second or third shift, that monitoring needs to cover those hours too. A backup that fails at 11pm is not a smaller problem than one that fails at noon.

8. Train the people who touch the files

Your crew is either your biggest exposure or your best sensor, and the difference is about twenty minutes a month. Cover the basics: save to the server and not the desktop, what a phishing email looks like this year, how to handle passwords without a sticky note on the monitor, and who to call when something looks wrong.

Short monthly conversations beat one long annual session nobody remembers. The goal is simple. When a machinist sees a folder full of files with strange new extensions, he tells someone in the next five minutes instead of assuming it will fix itself.

9. Put one name on it

"Everybody" owning the backups means nobody owns them. Name the person responsible for checking logs, scheduling tests, and knowing who to call at 2am. Write down the recovery steps and where the copies live, and keep that documentation somewhere more durable than one person's head. Shops that skip this learn the hard way that one resignation can freeze the whole operation.

When It Does Go Wrong: The First Two Hours

Preparation is what buys you a calm morning. Here is how that morning goes.

Scope it before you touch anything. Figure out what is affected and what is clean, and do not start wiping or reimaging yet. If it looks like ransomware, disconnect affected systems from the network rather than deleting anything, because what is on those drives may matter to your insurance carrier later.

Restore in ship-date order, not alphabetical order. The job going out Thursday comes back before the archive from 2019. Work the documented sequence, verify the data actually opens after each phase, and keep a log of what you restored and when.

Give updates from one mouth. One person tells the floor what is running and what is not, with real timelines instead of optimistic ones. Nothing burns a shift like fifteen people guessing.

Write down what happened once it is over. Root cause, how long recovery actually took versus what you expected, and which gap let it happen. That document is what keeps the same Monday from happening twice.

The Quiet Bonus: Easier Renewals and Customer Questionnaires

The work above does double duty, and nobody tells shop owners that part.

The same evidence that gets your floor running again is what your insurance carrier wants at renewal and what your biggest customer wants on their vendor security questionnaire. Tested restores, an encrypted offsite copy, versioning, monitoring that covers off hours. Documented, renewal season becomes paperwork instead of a scramble, and a Tier-one questionnaire stops being the thing you avoid for three weeks. We package that documentation for exactly that reason, so clients can hand it straight to their broker or their customer.

Data Backup FAQs for Small Manufacturers

Is OneDrive or Dropbox a backup?

No. Sync tools copy whatever is in the folder, including the bad version. Delete a print, overwrite a program, or get hit with ransomware, and the damage syncs to every other device in seconds. Sync is convenience. A backup is a separate, versioned copy that a bad Tuesday cannot reach and rewrite.

How often should a machine shop back up its data?

Nightly at minimum for anything the floor and the office touch daily: prints, CAM programs, the ERP database, quotes, and accounting. Some shops run their ERP database more often than that, because a day of re-entered jobs and shipments is a week of arguments. Full system images weekly, archives monthly.

What is the 3-2-1 backup rule?

Three copies of your data, on two different kinds of storage, with one copy off the property. For a small shop that usually looks like the live server, a local backup drive or appliance, and an encrypted cloud copy. It is old advice because it keeps working: no single fire, theft, or failure takes all three.

Can ransomware encrypt my backups too?

Yes, and that is exactly what attackers go looking for first. A backup drive sitting on the network with the same login as everything else gets encrypted right along with the server. Protection means at least one copy that cannot be changed or deleted after it is written, using credentials that are not your everyday admin account.

Does cyber insurance require backups?

Most applications and renewal questionnaires now ask about backups directly: whether you have an offsite copy, whether it is encrypted, and whether restores get tested. Your answers affect pricing and, in some cases, whether the carrier writes the policy at all. Guessing on that form is a bad idea. Knowing your real answers is worth an afternoon.

How long should it take to get the shop running after a file server dies?

That depends entirely on where the copy lives. Restoring from a local drive on the same network can put prints and programs back in a few hours. Pulling a couple of terabytes down a normal shop internet connection can run days. Set a target you can live with, then test whether your current setup actually hits it.

Not Sure Your Backups Would Actually Come Back?

Starlux IT is based in Parkesburg and we work with manufacturers in Coatesville, Downingtown, Gap, and across Chester and Lancaster County. We know what a CAD and CAM file server does to a network, we monitor around the clock because your second shift does not stop at five, and we put together the backup documentation your insurance broker and your biggest customer keep asking for. That is managed IT built around a shop floor, not a generic small business package with your name on the invoice.

Give us thirty minutes and no pressure. We will look at what you have running now, show you exactly where the gaps are, and you will walk away knowing whether your shop could come back from a bad Monday, whether you hire us or not.

Book your free 30 minutes →

Jay Stoltzfus
Jay Stoltzfus August 12, 2025
Share this post
Archive