Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglishESEspañolFRFrançaisTRTürkçe
Technician working on the cabling inside a server cabinet

Data & Business Continuity

A backup is worth nothing until you have restored it. We set up backup, archiving and recovery for your whole estate, agree recovery times up front and prove every year that they hold.

The question is not whether you have a backup

Almost every organisation has a backup running somewhere. The uncomfortable question is a different one: how long does it take to get back up, and who has ever actually tried? In practice that is where things go wrong. The backup runs, but nobody has tested a restore since the migration two years ago, and the one system everything else depends on turns out not to be included.

We turn that around. We start with what your business cannot do without: which processes have to be running again within an hour, which can wait until tomorrow, and which are annoying but survivable. That produces two numbers per system, RPO and RTO, and those numbers determine the design, not the other way round.

This service is worth it when you run several sites, when a standstill costs money by the hour, or when a client, auditor or insurer asks you to demonstrate that recovery works. Running a single office with everything in Microsoft 365 and no legal retention obligation? Then a lighter arrangement will do, and we will tell you so.

What we take on

SME

Backup and recovery for SMEs

Almost every smaller business has a backup. Far fewer have ever restored one. That difference is the whole subject: a backup that runs proves something is being written away, not that you can carry on with it tomorrow. Ransomware, moreover, aims precisely at wherever that copy is kept.

So we put down a copy that cannot be altered, not even by an administrator with the right passwords, and we restore it for real once a year. Then you know how long that takes. What that means in recovery time and recovery point is worked out under recovery time objective.

  • A copy nobody can erase Written immutably, so an attacker holding administrator rights still cannot reach it.
  • Restored for real once a year Not a report that is green but a recovery that was carried out, with the elapsed time recorded.
  • Knowing what a day of downtime costs Before we build anything we work out what an outage costs per day; the level follows from that and not from a package.
  • Also without a server room If your organisation works entirely in Microsoft 365 this applies in full: that data is not backed up by itself.
Enterprise

Continuity for enterprise organisations

In an organisation with several sites, recovery is not an action but an order of play. Which system first, who calls whom, which location keeps running while another is down, and what you do with a production line that cannot wait for a mail server. That is often written down and rarely rehearsed.

We fix that order, rehearse it, and measure what it actually cost in time. That turns a recovery time into a figure you can commit to instead of an estimate. How it ties into business continuity sits under disaster recovery planning.

  • A recovery time per system Not everything has to come back equally fast; the difference between an hour and a day changes the cost considerably.
  • Failover between sites One location taking over another’s work, with the data needed for that already present.
  • Rehearsed, not only described An annual exercise with the real elapsed time recorded, usable towards an auditor and an insurer.
  • In line with NIS2 Continuity and recovery are explicit requirements; what else is in it is on the NIS2 page.
How it works

From inventory to a tested plan in four steps

The lead time depends on the size of your estate. This is the route we follow as standard.

Impact analysis

One to two weeks. We go through your processes with you and record for each system what a standstill costs and how much data loss is acceptable. That produces the RPO and RTO per system.

Design and agreement

We translate those numbers into a design: what gets backed up where, how often, how long it is kept and who may restore. The recovery times end up in the SLA in black and white.

Implementation

Installation, configuration and the first full backup, phased so your production is not disrupted. We run in parallel until the new arrangement is demonstrably complete.

Test and review

A recovery test at least once a year, with a report you can show to your auditor. Anything that emerges from it is fixed and retested.

What you get

Recovery times that are agreed, not hoped for

Continuity is a promise about time. These are the components that make that promise verifiable.

  • RPO and RTO per systemHow much data you may lose and how quickly you have to be back, recorded per system instead of one number for everything.
  • Immutable backupCopies that cannot be modified or deleted for the agreed period, so ransomware cannot reach them.
  • Off-site copyAt least one copy outside the location where the original runs, so a fire or flood does not take both.
  • Restore on requestYou can ask for a restore of a file, a mailbox or a whole server without it counting as an incident.
  • Annual recovery testA scenario run through end to end, with the measured recovery time in the report.
  • Retention that matches your obligationsArchiving set to what your sector requires, including a demonstrable trail.
  • Reporting per monthWhich jobs ran, which failed, what was fixed and how the estate is developing.
  • Handover documentationIf you move on, you leave with a working description of the arrangement instead of a black box.
Testing

A backup you have never restored is a hypothesis

The moment when a recovery is needed is the worst possible moment to discover that a step was missing. So we test in advance, on a schedule, with the people who would actually have to do it.

  • A scenario, not a checkboxWe agree a realistic scenario in advance: a failed server, an encrypted file share, a mailbox lost weeks ago. Then we run it.
  • The measured time countsThe report states how long the recovery actually took, not how long it should have taken. If that is over the agreed RTO, the design changes.
  • Your own people take partThe colleague who would have to do this at two in the morning is at the table, so the procedure is familiar before it is needed.
  • Findings are fixedEverything the test throws up gets an owner and a date, and is retested at the next round.
Narrow aisle between server racks with bundles of cabling and orange indicator lights
Related services

What this connects to

Continuity leans on the systems around it. These services keep that base in order.

We work with
Veeam Datto Synology Schneider Electric
Frequently asked

Questions we get about this

The ones that come up most, answered briefly.

We already make backups. What do you add?

The question is not whether you have a backup, but whether you have ever restored it. A backup you have never restored is an assumption. We test the restore and demonstrate annually that it works, against recovery times agreed in advance.

What is a realistic recovery time?

It differs per system, which is exactly why we agree it per system rather than naming one figure for everything. Your tills and your email have a different urgency than an archive. Those times are agreed, not hoped for.

Does this protect against ransomware?

That is part of what it is for. Immutable backups cannot be altered or deleted afterwards, not even by somebody who has taken over administrator rights. We validate integrity before restoring, so you do not put back an infected copy.

Does this work across several sites?

Yes, and it is built for that. For organisations with several locations we look at what runs per site and what sits centrally, because a plan tested only at head office says little about a branch.

What do RTO and RPO mean, and which do you achieve?

RPO is how much work you may lose at most, measured in time: with an RPO of one hour you lose the last hour in the worst case. RTO is how long it may take before you are running again. We do not fill those two numbers in ourselves; you set them per system, because the answer for the accounts department is different from the answer for the production line. We then design the backup and the restore so the numbers are met, and every test measures whether that still holds.

How often do you test that a restore actually works?

On a fixed schedule, and the outcome goes into the report with the time it took. A backup that has never been restored is an assumption, not a backup; in practice the problems a test uncovers are almost never the backup itself but the things around it, a licence that does not come along, an integration pointing at an old address, a password nobody has any more. That is precisely why you test.

What exactly is an immutable backup?

A copy you cannot change or delete for an agreed period, not even with administrator rights. It is the only kind of backup worth anything against ransomware, because an attacker who is inside deletes the backups first. We keep those copies separate, with their own access, so the account used to manage your systems cannot reach them.

Brands

The brands above, one page each

What the brand makes, which lines we supply and what we do around it.

What we are audited on ourselves

Our own certifications

ITproposal is certified for ISO 9001 (quality), ISO/IEC 27001 (information security), ISO 14001 (environment) and Kiwa NEN 4400-1 (labour hire and secondment). That says something about how we work and how we have our own processes assessed; it is not a certification you inherit from us.

Know what a standstill actually costs you

In a half-hour conversation we go through your critical systems. Afterwards you know where your current arrangement leaves gaps and what closing them takes.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. See our privacy policy.

Request a quote Call