Backup & Disaster Recovery
Know you can recover your systems and data after ransomware, failure or disaster — because backups are protected from attack and recovery has been tested.
Is this for you?
You might need this if…
You have backups, but nobody has tested a full restore of a critical system recently.
Ransomware is on the board’s agenda, and you are not sure whether attackers could delete or encrypt your backups too.
Microsoft 365, other SaaS services or cloud workloads may not be covered by your current backup.
NIS2, DORA or customer requirements ask you to show documented continuity and recovery capabilities.
What we deliver
What it covers
Backup strategy and managed backup
We define what to back up, how often and for how long based on business requirements, then implement and run backup across on-premises, cloud and SaaS. You know exactly what is protected, with regular reports to prove it.
Immutable, ransomware-resistant backups
We set up backups that cannot be changed or deleted, isolated from your production environment and administrator accounts. Even if attackers take control of your network, a clean copy remains.
Disaster recovery planning and DR-as-a-service
We set recovery targets with the business, design the recovery solution and document the runbooks. With DR-as-a-service, critical systems can be recovered to a cloud or secondary site without building and running your own.
Business continuity and recovery testing
We plan and run regular recovery tests and continuity exercises, from single-system restores to full scenarios. Gaps are found in a test rather than during a real incident.
Our approach
How we work
01
Assess
Critical systems, data, dependencies and current backup coverage are mapped, and recovery targets are agreed with system owners.
02
Design
A backup and recovery architecture covering on-premises, cloud and SaaS, with immutability and isolation built in.
03
Implement
Backup and DR solutions are deployed or reconfigured, with runbooks written for each critical system.
04
Test
Restores and recovery scenarios are tested regularly, and results are used to improve the plan.
Best practices
What we bring to every engagement
Recovery targets come from the business
Recovery time and recovery point objectives are agreed with system owners, not set by IT alone.
Follow the 3-2-1-1-0 rule
Three copies, on two types of media, one off-site, one immutable or offline, and zero errors in verified restores.
Separate backup from production identity
Backup systems use separate accounts, multi-factor authentication and restricted access, so a compromised domain cannot reach them.
SaaS data is your responsibility too
SaaS providers keep the service running, but protecting your data against deletion or attack is largely up to you.
A backup isn’t proven until it is restored
Regular, documented restore tests are the only reliable evidence that recovery works.
Recover clean, not just fast
After ransomware, restore points are scanned and verified so the attacker does not come back with the data.
Outcomes
What you get
- Agreed recovery targets for each critical system
- A backup design covering on-premises, cloud and SaaS
- Immutable, isolated backup copies
- A disaster recovery plan with documented runbooks
- Test reports showing measured recovery times
- Evidence for NIS2, DORA, ISO 27001 and customer audits
AI-powered
Unleash the power of AI
We offer the possibility of using AI throughout this work: ready-to-use AI tools, or a customised version built for your organisation that can run inside your own infrastructure. In backup and recovery, AI detects unusual changes in backup data that may signal ransomware encryption and helps identify the last clean restore point. It can also keep recovery runbooks up to date as your environment changes.
Starter offer
Backup & Recovery Assessment
A fixed-scope, four-week assessment that checks whether you can really recover, including a controlled restore test, and gives you a prioritised improvement plan.
Week 1
Map
Inventory of critical systems, data, backup tools and current recovery targets, with interviews with system owners.
Week 2
Assess
Backup coverage, immutability, access controls and DR capability checked against business requirements and ransomware threats.
Week 3
Test
A controlled restore of selected critical systems to measure real recovery times.
Week 4
Report
Findings, gaps and a prioritised improvement plan presented to IT and management.
You receive
- Recovery targets for your critical systems
- A gap analysis of backup coverage and ransomware resilience
- Measured results from a controlled restore test
- A prioritised improvement roadmap
FAQ
Frequently asked questions
How long does it take to improve our backup and DR?
The assessment typically takes about four weeks. Quick fixes such as enabling immutability or covering missing systems can often follow within weeks, while a full DR solution usually takes a few months depending on scope.
Isn’t Microsoft 365 already backed up by Microsoft?
Microsoft keeps the service available and offers retention features, but these are not the same as an independent backup you control. Many organisations add a separate backup to protect against accidental deletion, malicious insiders and ransomware.
Will recovery testing disrupt production?
No. Restore tests are run in isolated environments or agreed windows, so production systems are not affected. Each test is planned in advance with the system owners.
Can you work with our existing backup tools?
Yes. We often start from the tools and suppliers you already have and improve how they are configured. Altechy is your single point of contact and brings backup and recovery specialists from our partner network when new tooling or a managed service makes sense.
Related services
Incident Response & Cyber Recovery Security Strategy, Risk & Compliance Data Centre & Hybrid Infrastructure Microsoft 365 & Collaboration Managed IT Operations Cloud, Network & Data Security
Let’s make sure you can recover
Book a free 60-minute idea session. We explore your challenges and opportunities with you, and suggest where to start — with no obligation.