Service

Disaster Recovery and Backup

A backup you have never restored from is a hope, not a plan. We build recovery systems that survive ransomware, and we prove they work on a schedule.

Backups attackers cannot delete

Immutable and air gapped copies mean encrypting your production data does not give an attacker your recovery data too.

Restores that are proven

We test recoveries on a schedule and send you the results. Discovering a corrupt backup during an outage is not a discovery you want to make.

A number you can plan around

Defined recovery time and recovery point objectives per system, agreed with you, so everyone knows what an outage actually costs.

The assumption that gets tested exactly once

Nearly every business believes it is backed up. A meaningful share of them are wrong, and they find out on the worst possible day.

The common failure modes are boring and consistent. The backup job has been failing silently for eight months because nobody reads the report. The backup includes the file server but not the database, which is open and locked during the backup window. The only copy sits on a drive plugged into the server it protects, so ransomware encrypted it too. The offsite copy exists but restoring 4TB over the available upstream bandwidth would take eleven days.

All of these are discoverable in advance. None of them are discoverable if nobody looks.

How we build it

Image based, not file based. We back up the whole system, not selected folders. That means a failed server can be recovered as a complete working machine rather than reassembled from files onto a fresh operating system install while your staff waits.

Three copies, two media, one offsite. A local appliance for fast recovery, replication to a geographically separate data center for site loss, and retention configured to your actual requirements rather than a default.

Immutable. This is the part that matters against ransomware. Modern attackers specifically hunt for and destroy backups before they encrypt anything, because that is what forces payment. Immutable storage means a backup, once written, cannot be modified or deleted for its retention period by anyone, including someone holding full administrator credentials. If your backups can be deleted from your network, assume they will be.

Microsoft 365 included. Cloud data needs backing up too. Microsoft’s retention is short and built for accidental deletion, not for a departing employee wiping a mailbox or a ransomware event propagating through OneDrive sync. We back up Exchange Online, SharePoint, OneDrive and Teams separately. See cloud solutions for the wider tenant picture.

Objectives, agreed in advance

Two numbers govern every recovery decision, and both are business decisions rather than technical ones.

Recovery point objective is how much data you can afford to lose, which determines how often backups run. Hourly snapshots cost more than nightly ones. For a busy order entry system, losing a day of transactions may be unacceptable. For an archive share, it may be entirely fine.

Recovery time objective is how long you can afford to be down, which determines the recovery method. Restoring from offsite is cheapest and slowest. Spinning a failed server up directly on a local appliance is fastest and requires hardware onsite.

We set these per system with you, because paying for one hour recovery on systems nobody would miss for a week is a waste, and discovering that your critical system was in the cheap tier is a lot worse.

Testing, because the report is not the proof

Backup software reports success when the job completed. It does not report that the data inside is consistent, that the database will actually mount, or that the recovery documentation still matches reality after last year’s server replacement.

We run scheduled restore tests. Files, applications and full system recoveries into an isolated environment, verified as functional, documented in a report you receive. When something fails a test, we fix it while it is a scheduling inconvenience rather than a crisis.

Once a year we recommend a full exercise with your leadership team, walking through an actual scenario and timing it. It is consistently the most useful hour our clients spend on this subject, because it surfaces the non technical gaps: nobody knows who calls the insurer, the emergency contact list is on the file server that is down, and the person who knows the phone system password is on vacation.

Ransomware specifically

Ransomware recovery is different from hardware failure recovery, and the difference is that you cannot trust anything.

Our playbooks assume the attacker had time inside the network before encrypting. That means containing and isolating before restoring, verifying that backups predate the initial compromise rather than just the encryption event, rebuilding rather than restoring anything that could carry persistence, and forcing credential resets across the board.

We build this plan with you in advance, alongside your cybersecurity controls, because the first hour of a ransomware incident is not when you want to be making architectural decisions.

FAQ

Disaster Recovery and Backup questions

Still stuck? Send us the question and a real engineer will answer it.

We already back up to an external drive. Is that enough?

No, for two reasons. A drive connected to the machine it is protecting gets encrypted along with everything else during a ransomware event, and a drive sitting in the same building does not survive a fire, flood or theft. External drives are also mechanical, unmonitored and frequently fail silently. They are better than nothing, and they should not be your only copy.

What does the 3-2-1 rule mean?

Three copies of your data, on two different types of media, with one copy offsite. It is the baseline standard, and we extend it with immutability so at least one copy cannot be altered or deleted even by someone holding your administrator credentials.

How long would it take to get us running again?

That depends on what fails and what you have chosen to pay for. With a local backup appliance we can typically bring a failed server back as a virtual machine in under an hour. A full site loss recovered from offsite replication is usually a matter of hours to a day. We define these targets per system with you in advance rather than leaving it to chance.

Do you test the backups or do we?

We do, on a schedule, and we send you the verification report. Automated success messages from backup software mean the job ran, not that the data is usable. The only meaningful test is an actual restore.

Is this different from business continuity?

Yes. Backup protects data. Disaster recovery restores systems. Business continuity is the plan for keeping the company operating while that happens, including where staff work, how customers are told and which processes run manually in the meantime. We build all three, because data restored to a business that has lost a week of customer confidence is only a partial win.

Next step

Get a quote for disaster recovery and backup

Tell us about your environment and what you are trying to solve. We will come back the same business day with questions, a rough scope and a realistic number.

  • Free assessment before any commitment
  • Written findings you keep either way
  • Same day on site across Westchester County, NY, Rockland County, NY, Putnam County, NY, nationwide for projects

Ask about disaster recovery and backup

Fill this out and we will get back to you the same business day. Prefer to talk it through? Call 914-214-9210.

Let us take a look

Revolutionizing Technology Solutions

Tell us what is slowing your business down. We will assess your environment, show you what we found and quote the fix in plain English. No obligation and no sales theater.