Backup & Disaster Recovery

Backup and disaster recovery

Most businesses have backups. Far fewer have proof those backups restore.

A backup that has never been restored is a hypothesis, not a safety net. We design backup and disaster recovery for small and mid-sized businesses, run the restores on a schedule, and send you the results whether they went well or not.

Remote + on-site
Tested restores
The problem

The gap is not backup. It's recovery.

Ask a business owner whether they're backed up and almost everyone says yes. Something is running. There's a console somewhere. Green checkmarks appear.

Ask when someone last restored a server from that backup and watched it boot, and the answer changes.

That gap has now been measured. In Veeam's Data Trust and Resilience Report 2026, a survey of more than 900 IT, security, and risk leaders, 90% said they were confident in their ability to recover from a cyber incident. Among organizations that were actually hit by ransomware, fewer than one in three fully recovered their data. Confidence and proof turned out to be two different things.

Said they were confident they could recover 90%
Actually recovered their data after ransomware Fewer than 1 in 3
Veeam, Data Trust and Resilience Report 2026 (900+ IT, security, and risk leaders). Confidence is across all respondents; recovery is among those actually hit by ransomware.

The uncomfortable part is that nobody in that 90% thought they were wrong. They had backups. The backups reported success. The problem surfaced on the one day it couldn't be fixed.

What's included

What we actually deliver

Backups that run where you work

Servers, workstations, virtual machines, and Microsoft 365. On-premises, cloud, or both. If it holds data your business needs on Monday, it gets a retention policy and someone’s name against it.

An immutable copy

At least one copy that cannot be altered or deleted, including by an administrator account an attacker has taken over. This is the specific control that decides whether a ransomware incident is an outage or a negotiation.

Scheduled restore testing

We restore from your backups on a recurring schedule and document the result. Not a checksum. An actual restore, verified, with the time it took written down.

Defined RTO and RPO, in writing

How much data you can afford to lose, and how long you can afford to be down. Those two numbers drive every design decision, and most businesses have never been asked either question.

A recovery plan a human can follow

Documented order of operations, dependencies, credentials location, and who calls whom. Kept offline, because the plan stored on the encrypted file server is not a plan.

Monitoring and reporting you can read

Failed jobs get chased the day they fail. You get a monthly summary in plain language, including the restore test result.

The evidence

What the public data actually shows

Every figure in this section comes from a published, dated, third-party report. None of it is our own measurement, and we've noted the source for each so you can check it.

Encryption is going up, not down

Sophos’s State of Ransomware 2026, based on 2,158 organizations across 17 countries that were hit in the previous twelve months, found 56% of attacks succeeded in encrypting data — up from 50% the year before.

Small businesses are losing ground

In the same report, only 34% of organizations with 100 to 250 employees stopped an attack before encryption or extortion. At organizations of 3,001 to 5,000 employees, 46% did. The gap is twelve points, and it is widening.

Backups are the thing that ends it

Backup-based recovery rose to 66% of encrypted-data cases in 2026, up twelve percentage points in a year. Forty-eight percent of encrypted victims paid the ransom. The organizations that recovered from backup were the ones that had a choice.

When it goes wrong, it’s expensive

Average recovery cost across the Sophos 2026 sample was $1.7 million per incident, up 11% year over year — and that figure excludes any ransom paid.

Attackers go after the backups first

Sophos’s dedicated research on backup compromise (2024 survey data) found 94% of organizations hit by ransomware said attackers attempted to compromise their backups during the attack. Where those attempts succeeded, median ransom demands were roughly double and total recovery costs ran about eight times higher. Backups are not incidental to a ransomware attack. They are a target inside it.

Sources: Sophos, State of Ransomware 2026 (2,158 respondents, 17 countries); Sophos, The Impact of Compromised Backups on Ransomware Outcomes (2024 survey data); Veeam, Data Trust and Resilience Report 2026 (900+ respondents). Figures from published third-party research, current as of July 2026.

The common gap

Microsoft is not backing up your Microsoft 365 data

This is the single most common gap we find, and it isn't a criticism of Microsoft. It's how the service is designed and documented.

Microsoft replicates your data across data centers so the service stays available. Replication is not backup. A file that gets deleted replicates as deleted. A file that gets encrypted by ransomware syncing through OneDrive replicates as encrypted.

What you get natively is a short recovery window, not an archive:

Workload Native window
SharePoint and OneDrive 93 days in the recycle bin, then permanent deletion
Exchange Online deleted items 14 days by default, configurable to 30
Departed user mailbox Deleted 30 days after the license is removed

The SharePoint figure is Microsoft's own published documentation, not a vendor claim. After the 93-day window closes, the data is gone, including for Microsoft support.

That window is fine for the intern who deleted a folder on Tuesday. It is not fine for a finance-department mailbox nobody opened for four months, a former employee's OneDrive that turns out to have held the only copy of something, or a compliance request that reaches back a year.

Reference: Microsoft Learn — Microsoft 365 SharePoint data deletion . Exchange Online figures are tenant defaults and can be changed per tenant.

Getting started

How we set it up

1

Find out what you have

Inventory of servers, endpoints, cloud workloads, and SaaS data. What’s protected, what isn’t, and what everyone assumed was covered. This is usually the part that surprises people.

2

Set the two numbers

RPO is how far back you’d be restoring from, meaning how much work gets redone. RTO is how long you’re down. Both are business decisions with cost attached, not IT decisions. We ask; you decide.

3

Build to 3-2-1-1-0

Three copies of the data, on two types of media, one off-site, one immutable, and zero errors on the last verified restore.

4

Restore it before you need to

We run scheduled restores and record what came back and how long it took. If a restore fails, that is a finding to fix now, on a normal Tuesday, rather than a discovery to make during an incident.

5

Write the plan down and keep it offline

Recovery order, dependencies, contacts, credentials location. Printed and stored where an encrypted network can’t reach it.

Step 3 is the working version of federal guidance: CISA's #StopRansomware Guide recommends offline, encrypted backups with regular testing of availability and integrity.

Fit

Who this is for

Businesses running line-of-business servers

ERP, practice management, accounting, a file server everyone maps a drive to. These are the systems where an outage stops billable work.

Anyone who moved to Microsoft 365 and stopped thinking about backup

The move was probably correct. The assumption that came with it usually isn’t.

Regulated and contract-bound businesses

HIPAA, CMMC, PCI, cyber insurance applications, and client security questionnaires all ask about backup and tested recovery. Several now ask for the date of your last restore test. Having an answer is the difference between a renewal and a re-underwrite.

Businesses that have already had a scare

A drive failure, a deleted folder, a phishing incident that could have gone worse. The scare is the cheapest information you will ever get about your recovery posture.

Businesses with one person who knows how it all works

Backup and recovery is where key-person risk becomes company risk.

Honest expectations

What backup does not do

Worth saying plainly, because the industry usually doesn't.

It doesn’t prevent the attack

Backup is the last layer, not the first. It determines what a bad day costs, not whether you have one. Sophos’s 2026 data found malicious email and phishing together accounted for half of all ransomware incidents, and 79% of attacks started with an identity-based approach — which is where prevention lives.

It doesn’t undo data theft

If an attacker copied your data before encrypting it, restoring clean systems doesn’t unpublish anything. A clean restore removes their leverage over your operations. It does not remove their leverage over your reputation. Those are separate problems and we won’t pretend otherwise.

It isn’t instant

Restoring a file takes minutes. Restoring a server takes hours. Restoring an environment after a full compromise takes longer than that, because the systems have to be verified clean before they go back on the network. Anyone quoting you a recovery time before they’ve seen your environment is guessing.

You will lose something

Everything between your last good backup and the incident is gone. That interval is your RPO. It is a number you choose and pay for, and the honest conversation is about how much it’s worth, not about pretending it’s zero.

We can’t promise a number until we’ve tested yours

We’ll tell you what we measured, on your equipment, after we’ve run it.

FAQ

Common questions

Do we still need backup if we’re all in the cloud?

Yes, and this is the most common misunderstanding we correct. Microsoft and Google protect the platform’s availability. Your data inside it is your responsibility, with a native recovery window measured in weeks, not years.

How often do you test restores?

On a defined schedule agreed up front, with the result documented either way. If you’re asking because your current provider doesn’t, that’s the answer to your real question.

Can ransomware reach our backups?

It tries. Sophos found 94% of ransomware victims said attackers attempted to compromise their backups during the attack (2024 survey data). This is why at least one copy has to be immutable, meaning it can’t be deleted or altered even by a compromised administrator account.

How long will we be down?

It depends on what failed and what you’re restoring. We won’t quote a number before we’ve inventoried your environment and run a real restore. After that, we’ll give you a measured figure rather than a marketing one.

What’s the difference between backup and disaster recovery?

Backup is the copy. Disaster recovery is the plan, the order of operations, and the tested ability to bring a business back. Plenty of companies buy the first and assume they got the second.

We already have a backup product. Do we need to switch?

Often not. Owning a backup product and having tested recovery are different things, and the gap is usually process rather than software. We’ll tell you if what you have is fine.

Do you handle Macs and Linux servers?

Yes.

What does this cost?

It scales with how much data you have, how far back you need to go, and how fast you need to be back. The RTO and RPO conversation happens before the pricing conversation, because it’s what sets the price.

Find out whether your backups actually restore.

We'll inventory what's being protected, check whether any copy is immutable, review your Microsoft 365 retention settings, and pull a real restore so you can see how long it takes. You get the findings whether they're good or bad. Plain findings, no pressure.

Trusted by dozens of businesses