Services
Backup & Disaster Recovery
What happens in the event of a fire, a flood, or a ransomware attack? The answer should be something you already know, not something you find out.
What this covers
- Data backup and replication
- Disaster recovery planning
- Business continuity testing
- Ransomware recovery
- Recovery time and recovery point objectives
Backups you have actually tested
An untested backup is a hope, not a plan. We verify that yours restore, and we tell you how long a real restore takes before you need to know.
The failure is rarely that no backup existed. It is that the backup covered the file server and not the database, or it ran for eleven months and stopped in month twelve, or it restored — slowly — into an environment that no longer had anywhere to put it. None of that is visible until someone tries.
The two numbers that decide everything
Recovery time and recovery point objectives are the whole design, and most businesses have never been asked for them.
Your recovery point objective is how much data you can afford to lose, measured in time. Backing up nightly means accepting that a Thursday afternoon failure costs you Thursday. Your recovery time objective is how long you can afford to be down. These are business decisions with a cost attached, not technical settings — and the honest version of the conversation is that halving either one roughly doubles what it takes to achieve.
Set them deliberately and everything else follows. Skip them and you end up with whatever the software defaulted to, discovered at the worst possible moment.
Ransomware changed what a backup has to be
The old advice — three copies, two media, one offsite — was written for fire and hardware failure. It assumes your backups are bystanders.
They are not. Modern ransomware looks for backup systems first, because an attacker who encrypts your data and your backups has removed your only alternative to paying. Deleting or encrypting the backup server is a standard step, not an unlucky one.
What answers that is immutability: copies that cannot be altered or deleted for a defined period, by anyone, including someone holding your administrator credentials. If a backup can be deleted by a compromised admin account, it is not protecting you from the thing most likely to happen.
Microsoft 365 is not backing up your data
This is the most common and most expensive misconception we meet, and it is entirely understandable — the data is in the cloud, so it feels handled.
Microsoft's responsibility is keeping the service running. Yours is the content in it. Retention policies, the recycle bin and version history are useful, and they are not backup: they expire, they can be changed by an administrator, and they do not help against a deletion nobody noticed for a quarter or a mailbox emptied by an account takeover.
If your business runs on SharePoint, OneDrive, Exchange Online and Teams, that is the data you cannot lose — and it is worth knowing exactly what would happen to it, rather than assuming.
Recovery is more than restoring files
A real recovery has an order, and the order is where unrehearsed plans fall apart. Identity comes back before the applications that authenticate against it. DNS and network routing come back before anyone can reach either. Dependencies nobody documented surface exactly here.
There is also the question nobody plans for: where do people work while this is happening? A recovery that is technically complete in two days is still two days your business did not operate. Continuity — what staff do in the meantime, how customers are told, who decides — is a separate plan from recovery and it is usually the one missing.
The way to find these things out is a rehearsal, on a day you chose, rather than a Tuesday you did not.
If you handle CUI, this is in scope
Backup and recovery are not an operational nicety for a defense contractor. Media protection, system and information integrity, and incident response are all families of NIST SP 800-171, and an assessor will ask what your plan is and expect evidence rather than intent.
Where the backups themselves hold CUI, they inherit the same boundary as everything else — where they are stored, who can reach them, and under whose control. Our shared responsibility matrix sets out which of those rows typically sit with a provider and which stay with you.
Common questions
How often should backups be tested?
Regularly, and on a schedule you can point at — not the day you need one. We build the testing into the service rather than leaving it as something to get around to. The test that matters is a restore, not a green tick on a backup job: those two things fail independently.
Doesn't Microsoft back up our Microsoft 365 data?
No, and this catches a great many businesses. Microsoft is responsible for keeping the service available; you are responsible for the content in it. Retention policies, version history and the recycle bin are useful, but they expire, they can be changed by an administrator, and they will not help you against a deletion nobody noticed for three months or a mailbox emptied after an account takeover. If your business runs on SharePoint, Exchange Online and Teams, that is exactly the data you cannot afford to lose.
What is the difference between RTO and RPO?
RPO is how much data you can afford to lose, measured in time — back up nightly and a Thursday afternoon failure costs you Thursday. RTO is how long you can afford to be down. Both are business decisions with a cost attached rather than technical settings, and roughly speaking, halving either one doubles what it takes to achieve. Most businesses have never been asked for either number, which is how they end up with whatever the software defaulted to.
Will backups protect us from ransomware?
Only if the backups themselves cannot be reached. Attackers target backup systems first, because removing your alternative to paying is the point of the exercise. What answers that is immutability — copies that cannot be altered or deleted for a set period by anyone, including someone holding your administrator credentials. A backup a compromised admin account can delete is not protecting you from the most likely scenario.
How long would a real restore actually take?
That depends on how much data there is, where it has to come from, and what has to come back before it — identity and networking usually precede everything else. The useful thing is that it is knowable in advance. If nobody has told you the number for your environment, that is worth asking, because it is the number your continuity plan should be built around.
We are entirely in the cloud. Do we still need this?
Yes, and arguably more so, because the failure modes shift from hardware to accounts. Cloud platforms are extremely good at staying available and they do not undo an accidental deletion, a departed employee's clear-out, or an attacker operating with valid credentials. Availability and recoverability are different problems, and only one of them is included.
The other things we do
-
Managed IT Services
We take responsibility for your systems. Unlimited helpdesk, proactive maintenance, and status monitoring, so your team stops losing hours to technology that should just work.
-
Compliance & CMMC
CMMC Level 2 readiness and Microsoft GCC High / Azure Government environments for the defense supply chain, built so evidence of every control is ready to produce.
-
Cyber Security
End-to-end protection built on a zero-trust approach: we map normal activity and act on the outliers, rather than waiting to be told something has gone wrong.
-
Cloud Solutions
Microsoft Azure, Azure Virtual Desktop, and Microsoft 365 — designed, migrated, and run by engineers who hold the certifications for all three.
-
AI Services
Practical AI inside the tools your team already uses — with the same care about where your data goes that we apply to everything else.
-
Web Development
Websites built to be fast, findable, and owned by you — treated as infrastructure to be maintained rather than a project that ends at launch.
Get in touch
Talk to us about backup & recovery
Tell us what you're dealing with and we'll respond as soon as possible.