Skip to content

Backup & Disaster Recovery

Isolated, tested backups and a clear recovery plan, so ransomware or hardware failure is a bad day, not a closed business.

Backups you can actually restore from, kept isolated so ransomware cannot reach them. We set up a proper 3-2-1 approach, test real restores rather than assuming they work, and document a recovery plan, so your worst day stays recoverable.

The gap between a backup and a recovery

A backup is a copy of data. A recovery is your business operating again. The distance between them is where most disaster recovery plans quietly fail, and it is made up of things nobody thinks about until they are in it: which system has to come back first, where the licence keys are, who can authorise a rebuild, what the phone number of the internet provider is, and whether the person who knows all of this is on a plane.

So this engagement covers both. The backups, verified. And the plan for turning those backups back into a working business, written in the order it has to happen, readable by somebody who is having a very bad day.

Isolation is the property that matters

Ransomware operators learnt years ago that encrypting your data is not enough if you can simply restore it. So they go for the backups first, and they do it with your own administrator credentials, which they have because that is how they got in.

A backup that lives on the same network, reachable with the same credentials, is not protection against the most likely serious incident you face. It protects against hardware failure and human error, which are both worth protecting against, but it is not the control people believe it is.

The copy that matters is the one that cannot be deleted or altered even by somebody holding full access to your environment: immutable storage, a genuinely separate account, or offline media. That is the difference between a week of disruption and a business that does not reopen.

Recovery targets, in business terms

Two numbers drive every design decision, and both are business questions rather than technical ones.

How much data can you afford to lose? If backups run nightly, a failure at 4pm loses a day of work. For some businesses that is an inconvenience. For others it is unrecoverable.

How long can you be down? An hour, a day, a week. Each answer implies a different and differently priced architecture.

Most businesses have never been asked these questions directly and are surprised by their own answers. Getting them stated, agreed, and written down is the part of this work that determines everything else, and it is worth doing even if you then decide the affordable option is the right one.

Testing, on a schedule

We restore at setup, and then again periodically, because environments change. New systems appear, somebody moves a share, a licence lapses, a retention setting gets adjusted. A backup regime that was verified in March and not since is a belief rather than a fact.

Each test is recorded: what was restored, how long it took, and what did not go to plan. That record is also exactly what an insurer or an auditor asks for.

Typical timeframe
Setup in 1 to 3 weeks, then tested restores on a schedule
Best for
Anybody who has never actually restored from their backups
Why the third copy is the one that decides a ransomware outcomeThree copies is the easy half of 3-2-1. Reachability is the half that decides the outcome.

The engagement

How it runs

Every engagement follows the same shape, so you always know which part you are in and what is coming next.

  1. 1

    Work out what actually matters

    Not everything needs the same protection. We identify what the business genuinely cannot operate without, and how long it could survive without it.

  2. 2

    Design to 3-2-1

    Three copies, two types of media, one kept off-site and isolated. The isolated copy is the one that matters when an attacker holds your administrator credentials.

  3. 3

    Implement and verify

    We set it up and then restore from it. Until a restore has been performed, you have backup jobs rather than backups.

  4. 4

    Write the plan

    A recovery plan in the order things must happen, readable by somebody who is stressed, that does not assume any one person is available.

  5. 5

    Test on a schedule

    Restores are re-tested periodically and the results recorded, because environments change and a backup that worked last year proves nothing today.

Common questions

We have backups running. Is that not enough?

It is the necessary half. The question that matters is when somebody last restored from them, and for most businesses the honest answer is never, or not since setup. Backups fail quietly: a job that has been excluding a folder for eight months reports success every night. The restore is the test, and everything before it is a hope.

What does 3-2-1 actually mean?

Three copies of your data, on two different types of storage, with one kept off-site. The modern addition is that the off-site copy should also be immutable or otherwise isolated, meaning it cannot be deleted or encrypted even by somebody holding your administrator credentials. That last property is what decides ransomware outcomes, because modern ransomware deliberately goes looking for the backups first.

How fast could we be back up?

That is a design decision rather than a fact, and it is the conversation we have at the start. Recovering in an hour costs considerably more than recovering in two days. The right answer depends on what an hour of downtime costs your business, and most businesses have never put a number on it. We help you do that, then design to it.

Does Microsoft 365 back itself up?

Not in the way most people assume. Microsoft protects the service and its infrastructure, and offers limited retention windows for deleted items, but that is not a backup of your data against deletion, corruption, a malicious insider, or a compromised account. Microsoft's own shared responsibility model puts your data on your side of the line. Third-party backup for Microsoft 365 is inexpensive and we recommend it routinely.

What if we get hit while you are managing this?

Then we run the recovery plan, which exists precisely so that decisions are made in advance rather than at 2am. Recovery and incident response are the same event viewed from two angles, and we plan them together.

Need help with Backup & Disaster Recovery?

Tell us where you are and what is worrying you. We will tell you honestly what we would do first.

Get in touch