Backup & Disaster RecoveryA backup is only real once you have restored from it. We do that every quarter.
Ransomware goes for the backups first, because a business that can restore does not pay. Servers, laptops and the cloud services you rely on need copies held somewhere an attacker with your admin password cannot reach, and a plan with a number on it for how long it takes to get back. We build that, we run it on N-able Cove and Acronis, and we restore something real from every client's backup each quarter and write down what happened.
Who this is for
Any business that still has a server, a line-of-business application or a NAS, and any business whose insurer, auditor or biggest customer has asked how long it would take to recover from a ransomware attack. If the honest answer today is 'we think there is a backup', this is the service.
What the NCSC says backups should look like
The National Cyber Security Centre's guidance has not changed in years, because it is right. Keep at least one copy offline or otherwise disconnected from the live network at all times. Keep at least three copies of the data, on two different types of storage, with one offsite. Back up everything the business needs to operate, not just the server you remember. Protect cloud backups so that a deleted version cannot be removed straight away. And test the restores, regularly.
The NCSC's ransomware guidance adds the reason this matters: ransomware actively targets backups to increase the likelihood of payment. A backup that sits on a share the server can write to, or in a cloud account the same administrator can empty, is part of the attack surface rather than the recovery plan.
Source: Offline backups in an online world (NCSC), Backing up your data (NCSC small organisations guide), Mitigating malware and ransomware attacks (NCSC)
What the ICO expects
Article 32 of the UK GDPR requires organisations to be able to restore the availability of and access to personal data in a timely manner after a physical or technical incident. The ICO's own data security guidance uses a ransomware recovery with 3-2-1 backups as its worked example. For a business that holds client or employee records, that is any business, a backup you cannot restore from is a compliance problem before it is an IT one.
Source: A guide to data security (ICO)
Two numbers that make the plan real
Disaster recovery planning comes down to two numbers per system. The recovery point objective is how much work you can afford to lose: the point in time the data must be recovered to. The recovery time objective is how long the system can be down before the business is damaged. A finance system might be four hours and one day; a file share for an archive might be a week and a week.
We agree those numbers with you per system, size the backup schedule and the recovery method to meet them, and then measure the quarterly test against them. A plan that says 'as fast as possible' is not a plan.
Source: Recovery point objective (NIST glossary), Recovery time objective (NIST glossary)
How we build it
Servers, physical and virtual, are backed up as full images direct to cloud storage with no appliance to buy, with an optional local copy for fast restores of a single file. Laptops and desktops that hold data outside OneDrive are backed up the same way. Microsoft 365 and Google Workspace are covered by their own services, because the data lives with Microsoft and Google rather than on your server.
We run two platforms. N-able Cove backs up straight to the cloud, holds copies off your network behind mandatory two-factor authentication and end-to-end encryption, includes bare-metal and file-level recovery, automated recovery testing, and a Standby Image that keeps a ready-to-boot copy of a server in Azure, Hyper-V or VMware for disaster recovery. Acronis Cyber Protect adds immutable backups, continuous data protection and failover to a virtual machine, and it is the platform we use where a client needs those specifically or has workloads Cove does not cover.
Which one you get depends on what you run and what your recovery numbers are, and we say which and why on the quotation.
Immutable means immutable
An immutable backup cannot be altered or deleted for a set period, by anyone, including an administrator with the right password. That is the modern answer to the NCSC's offline rule for businesses that no longer want to rotate tapes. We hold backups in a separate account from your Microsoft tenant and your servers, with retention locks so that a compromised administrator or a ransomware operator with your credentials cannot empty the backup before encrypting the live data.
Tested every quarter, and written down
Every quarter we restore something real from each client's backup: a server to a virtual machine, a database to a point in time, a folder to a laptop. We time it against the agreed recovery objectives and record the result. You get the record, and so does your insurer or auditor when they ask. If the restore fails or runs slow, that is the quarter we fix it, not the day the server dies.
Monitoring is the other half. Failed backup jobs raise an alert to our helpdesk, not an email to an inbox nobody reads, and a backup that has not completed in 24 hours is a ticket.
What is included
Server backup
Windows and Linux servers, physical or virtual, backed up as full images to UK cloud storage, with an optional local copy for fast single-file restores.
Device backup
Laptops and desktops that hold data outside OneDrive or SharePoint backed up the same way, so a stolen laptop is a hardware claim rather than a data loss.
Microsoft 365 and Google Workspace
Mail, files, calendars and Teams or Drive backed up outside the vendor, kept seven years in the UK, at £3 per user per month, through our separate services.
Immutable, offsite copies
Backups held in a separate account from your production systems, encrypted, behind two-factor authentication, with retention locks that an administrator cannot override.
Disaster recovery
A ready-to-boot copy of critical servers kept in the cloud or on standby hardware, with an agreed recovery point and time per system and a written runbook for who does what.
Quarterly restore tests
A real restore from every client's backup each quarter, timed against the objectives and recorded for your insurer and auditor.
Monitoring and restores by us
Failed jobs alerted to the helpdesk and chased the same day. One file, one mailbox, one server or the whole lot restored when you ask; there is no portal for you to learn.
What is not included, and why
- A promise that nothing will ever be lost. Backups run on a schedule, and work done between the last backup and the incident is the recovery point you agreed. Shorter windows cost more, and we will show you the trade-off.
- Standby hardware or Azure compute you have not asked for. Disaster recovery to the cloud is sized and priced per server; a business that only needs file restores does not pay for failover.
- Rebuilding after an incident outside the agreed plan. Restores within the runbook are included. A full rebuild after a ransomware attack that reaches beyond the covered systems is scoped and quoted when it happens, and you will know before it starts.
- Data you have not told us about. We inventory what you run at onboarding and again at each quarterly review. A new server or an application installed without a word to us is not backed up until it is on the list.
What it costs
Server and device backup is priced per server and per device per month, including storage and restores, on the quotation. Disaster recovery with a standby server image is priced per server. Microsoft 365 and Google Workspace backup are £3 per user per month. Prices for your estate are available on request: get in touch or book a call, and bring a list of what you run.
How it starts
- 1Free IT Health CheckA short online check that benchmarks your security and business risk and tells you where you stand.
- 2Discovery callAn engineer, not a salesperson. What you have, what is broken, what it would cost to fix, in writing.
- 3OnboardingEverything moves across on a plan, with no gap in cover and nothing lost.
Questions people ask before signing
What is the 3-2-1 backup rule?
At least three copies of your data, on two different types of storage, with one offsite. The NCSC and the ICO both describe it. The modern addition is that the offsite copy must be immutable or offline, because ransomware targets backups it can reach.
Our server backs up to a NAS in the office. Is that enough?
No. A NAS on the same network is reachable by the same ransomware and lost in the same fire or flood. It is useful as the fast local copy; the offsite, immutable copy is the one you recover a business from.
What is an immutable backup?
A backup that cannot be changed or deleted for a set period, even by an administrator. It stops an attacker who has your credentials from destroying the backups before encrypting the live data, which is now the standard first move.
How long would it take to recover a server?
That is the recovery time objective, and we agree it per server. With a standby image in the cloud, a critical server can be running again in hours; a file-level restore to rebuilt hardware takes longer. The quarterly test tells you the real number, not the brochure one.
Do we still need this if everything is in Microsoft 365?
You need Microsoft 365 backup, which is a separate service at £3 per user. This page is for servers, line-of-business applications, NAS devices and laptops that hold data outside OneDrive. Many businesses have both.
Where is the data stored?
In UK data centres, in an account separate from your Microsoft tenant and your servers, encrypted in transit and at rest, behind two-factor authentication, with retention locks.
Will our insurer accept it?
Cyber insurers ask whether backups are offsite, immutable or offline, separate from production credentials, and tested. This service answers yes to all four, and the quarterly test record is the evidence.
Sources
- 1.Offline backups in an online world (NCSC)
- 2.Backing up your data (NCSC small organisations guide)
- 3.Mitigating malware and ransomware attacks (NCSC)
- 4.A guide to data security (ICO)
- 5.Recovery point objective and recovery time objective (NIST glossary)
- 6.N-able Cove Data Protection server backup
- 7.Acronis Cyber Protect