Data Protection & Continuity
Managed Backup
Automated, encrypted, immutable backup across servers, endpoints, virtual machines, databases and cloud workloads, monitored daily and restore-tested on a fixed cadence.
Every workload, one console, tested restores
- Ransomware-resistant copies
- ImmutableRansomware-resistant copies
- Job verification
- DailyJob verification
- Documented restore tests
- QuarterlyDocumented restore tests
Backup fails quietly. Jobs stop running after a server is rebuilt, a new virtual machine never gets added to the schedule, retention silently ages out the copy you needed, and nobody notices until the day somebody asks for a file from four months ago. The failure is almost never the software; it is the absence of anyone whose job it is to look.
Managed Backup puts that responsibility with us. We protect every workload you own under one policy set, verify each job every morning, chase the failures, and prove the whole thing works by performing scheduled test restores and giving you the written evidence.
Copies are encrypted before they leave your network and at least one is held immutable, meaning it cannot be altered or deleted by anyone, including an attacker holding your administrator credentials, until its retention period expires. That single property is what separates a backup that survives a ransomware event from one that does not.
What is included
- Physical servers, virtual machines, workstations and laptops
- Microsoft SQL Server, Oracle, MySQL and PostgreSQL databases
- Microsoft 365, Google Workspace and major SaaS platforms
- AES-256 encryption in transit and at rest, with customer-held keys available
- Immutable storage that cannot be deleted before its retention expires
- Daily job verification with failures chased by our team, not just logged
- Scheduled test restores with written evidence for auditors
- Granular recovery of a single file, mailbox item, database table or whole machine
What you get out of it
- A restore time you can commit to in writing
- Backups that survive an attacker with domain administrator rights
- Audit evidence produced as a by-product, not a fire drill
- No more silent backup failures discovered at the worst moment
How we design a backup policy
We start from the business, not the technology. For each system we ask two questions: how much data can you afford to lose, and how long can you afford to be without it. Those answers become the recovery point objective and recovery time objective, and everything else follows from them.
A system with a four-hour recovery point objective needs a fundamentally different design from one that can tolerate a day. Rather than applying one schedule to everything and hoping, we tier your estate so that the money goes where the risk actually is.
The 3-2-1-1-0 rule, applied properly
The classic guidance is three copies of your data, on two different media, with one off-site. Modern practice adds two more digits: one copy immutable or air-gapped, and zero errors on verification.
That final zero is the one most organisations skip. A backup job that reports success has only proven it wrote data somewhere. Verification proves that data can be read back and is internally consistent, which is a materially different claim.
Where this fits
You have backups but have never tested a restore
The most common situation we walk into. We inventory what is actually protected, find the gaps, and perform a real restore so you learn what recovery looks like before you need it.
You are preparing for an audit or cyber-insurance renewal
Insurers and auditors increasingly ask for proof of immutable backup and tested recovery. We produce that evidence on a schedule so the questionnaire is a formality.
You are running mixed on-premises and cloud workloads
One policy set covering physical servers, virtual machines and SaaS data, so nothing sits outside the protection boundary because it belongs to a different team.
Frequently asked questions
- How quickly can we recover a whole server?
- It depends on data volume and whether recovery is local or from cloud storage. Local recovery of a typical file server is usually measured in hours; a full cloud restore of a large dataset can take longer, which is exactly why we agree and document the target up front rather than discovering it during an incident.
- Can ransomware encrypt our backups?
- That is precisely what immutable storage prevents. Once written, an immutable copy cannot be modified or deleted by any credential until its retention period expires. Attackers routinely target backup repositories first, so this is not a theoretical protection.
- Do we keep control of our encryption keys?
- Yes, if you want it. Customer-managed keys mean nobody, including us and the storage provider, can read your data. The trade-off is that losing the key means losing the data, so we document key custody carefully before enabling it.
- What happens when a backup job fails?
- Our team sees the failure the same day, investigates the cause and either fixes it or escalates to you with a recommendation. You receive a monthly report showing job success rates and any recurring issues we are working through.
Ready to move on Managed Backup?
We will scope it against your actual environment, not a generic package, and give you a fixed price before any work starts.
