Skip to content

Service

Backup, disaster recovery and business continuity

Almost every business we assess has backups running. Far fewer have restored one. The difference between those two states is the entire service: tested restores on a schedule, retention that matches your obligations, and a recovery window somebody has actually agreed to rather than assumed.

Restore testing

Daily

on covered systems

A backup nobody has restored is an assumption. Test results are reported monthly.

What gets protected, and how fast it comes back

Recovery targets are set per data type rather than globally, because protecting a file share to the same standard as a transactional database wastes money in one direction and creates risk in the other.

Backup frequency and typical recovery time by data type
Data typeTypical frequencyNote
Files and foldersMinutesEvery 4 hoursMost common request, least dramatic
Microsoft 365 dataUnder an hourDailyNot covered by Microsoft beyond a short retention window
Servers and virtual machinesHoursHourly to dailyImage level, so the whole machine comes back
Line of business databasesHoursDepends on transaction volumeNeeds application aware backup, not a file copy
Full site failoverHours to a dayContinuous replicationOnly where downtime cost justifies the standby cost

Planning for this region specifically

Generic disaster recovery templates assume a generic disaster. The Puget Sound has four risks worth designing around, and the first one changes where your recovery copy should live.

  • Cascadia subduction zone seismic risk, which makes a recovery site inside the same corridor a poor plan
  • Winter windstorm and ice related power loss, routinely multi day in outlying parts of Pierce County
  • Wildfire smoke events that make offices unusable while systems remain perfectly healthy
  • Single carrier fibre routes serving parts of the Kent Valley and the Port area

A recovery copy held in a data centre 20 miles away satisfies most compliance checklists and fails the specific scenario this region is most exposed to. Geographic separation should mean a different seismic zone, not a different building.

The plan is the deliverable

Backup software is a commodity. What is not commodity is a written document naming who declares an incident, who contacts staff, in what order systems come back, and what the business does manually in the meantime.

That last point is the one most often missing. If order entry is down for six hours, somebody needs to know whether orders get taken on paper and how they are reconciled afterwards. That is a business decision made calmly in advance, not a technical one made under pressure.

The plan is reviewed annually and after any material change to the environment, because a recovery plan describing systems you retired two years ago is worse than none at all.

Common questions

Answered before you ask.

We already have backups. Why is this a service?

Because running a backup and being able to restore from it are different things, and only the second one matters. The common failure is a backup job that has been reporting success for months while silently excluding the one database that runs the business, or an image that cannot be mounted because nobody ever tried. The service is the testing, the retention design and the recovery plan, not the software.

What are RTO and RPO?

Recovery time objective is how long you can be down. Recovery point objective is how much data you can afford to lose, measured backwards from the failure. Both are business decisions rather than technical ones, and they drive the cost directly. An hour of tolerance costs far more to deliver than a day of tolerance, so the useful exercise is agreeing what each department genuinely needs rather than defaulting to as fast as possible everywhere.

Does Microsoft back up our Microsoft 365 data?

Not in the way most businesses assume. Microsoft protects its own infrastructure and provides a short retention window for deleted items, which handles accidental deletion noticed quickly. It does not protect you from a deletion discovered months later, from a compromised account destroying mailbox contents, or from a retention policy configured wrongly. Third party backup for Microsoft 365 is standard practice and is included here.

What does immutable mean and why does it matter?

An immutable backup cannot be altered or deleted for a set period, even by an administrator account. It matters because modern ransomware specifically hunts for backup systems and encrypts or deletes them before triggering, on the reasonable assumption that a business with working backups will not pay. Immutability is what keeps the recovery path available once an attacker already has administrative credentials.

Let us try to restore something.

The assessment includes an attempted restore from your existing backup. It is the single most useful hour in the whole process and almost nobody has done it.

CallFree assessment