
Data & Business Continuity
A backup is worth nothing until you have restored it. We set up backup, archiving and recovery for your whole estate, agree recovery times up front and prove every year that they hold.
The question is not whether you have a backup
Almost every organisation has a backup running somewhere. The uncomfortable question is a different one: how long does it take to get back up, and who has ever actually tried? In practice that is where things go wrong. The backup runs, but nobody has tested a restore since the migration two years ago, and the one system everything else depends on turns out not to be included.
We turn that around. We start with what your business cannot do without: which processes have to be running again within an hour, which can wait until tomorrow, and which are annoying but survivable. That produces two numbers per system, RPO and RTO, and those numbers determine the design, not the other way round.
This service is worth it when you run several sites, when a standstill costs money by the hour, or when a client, auditor or insurer asks you to demonstrate that recovery works. Running a single office with everything in Microsoft 365 and no legal retention obligation? Then a lighter arrangement will do, and we will tell you so.
What we take on
- Backup across your whole estate. Servers, virtual machines, endpoints, Microsoft 365 and your cloud workloads, in one arrangement instead of four separate ones.
- Immutable copies. A copy that cannot be modified or deleted, not even with administrator rights. That is what stops ransomware from taking the backup with it.
- The 3-2-1 rule as a starting point. Three copies, two types of media, one off-site. Simple, and still the reason most recoveries succeed.
- Archiving with retention. Mailboxes and files kept for as long as the law or your sector requires, findable and demonstrably unaltered.
- A tested recovery plan. Not a document in a drawer, but a scenario we run through with you at least once a year.
- Monitored by our own team. Failed jobs are picked up the same day, including outside office hours, from our delivery team.
From inventory to a tested plan in four steps
The lead time depends on the size of your estate. This is the route we follow as standard.
Impact analysis
One to two weeks. We go through your processes with you and record for each system what a standstill costs and how much data loss is acceptable. That produces the RPO and RTO per system.
Design and agreement
We translate those numbers into a design: what gets backed up where, how often, how long it is kept and who may restore. The recovery times end up in the SLA in black and white.
Implementation
Installation, configuration and the first full backup, phased so your production is not disrupted. We run in parallel until the new arrangement is demonstrably complete.
Test and review
A recovery test at least once a year, with a report you can show to your auditor. Anything that emerges from it is fixed and retested.
Recovery times that are agreed, not hoped for
Continuity is a promise about time. These are the components that make that promise verifiable.
- RPO and RTO per systemHow much data you may lose and how quickly you have to be back, recorded per system instead of one number for everything.
- Immutable backupCopies that cannot be modified or deleted for the agreed period, so ransomware cannot reach them.
- Off-site copyAt least one copy outside the location where the original runs, so a fire or flood does not take both.
- Restore on requestYou can ask for a restore of a file, a mailbox or a whole server without it counting as an incident.
- Annual recovery testA scenario run through end to end, with the measured recovery time in the report.
- Retention that matches your obligationsArchiving set to what your sector requires, including a demonstrable trail.
- Reporting per monthWhich jobs ran, which failed, what was fixed and how the estate is developing.
- Handover documentationIf you move on, you leave with a working description of the arrangement instead of a black box.
A backup you have never restored is a hypothesis
The moment when a recovery is needed is the worst possible moment to discover that a step was missing. So we test in advance, on a schedule, with the people who would actually have to do it.
- A scenario, not a checkboxWe agree a realistic scenario in advance: a failed server, an encrypted file share, a mailbox lost weeks ago. Then we run it.
- The measured time countsThe report states how long the recovery actually took, not how long it should have taken. If that is over the agreed RTO, the design changes.
- Your own people take partThe colleague who would have to do this at two in the morning is at the table, so the procedure is familiar before it is needed.
- Findings are fixedEverything the test throws up gets an owner and a date, and is retested at the next round.
What this connects to
Continuity leans on the systems around it. These services keep that base in order.
Know what a standstill actually costs you
In a half-hour conversation we go through your critical systems. Afterwards you know where your current arrangement leaves gaps and what closing them takes.