Skip to content
Home / Services / Backup & Recovery
Backup, recovery & business continuity

Backups you've actually tested. Recovery you can prove.

A real backup strategy isn't a vendor invoice — it's a recovery you can demonstrate, on a Tuesday afternoon, to your board, in under your declared RTO. We'll get you there. With evidence.

  • Immutable, encrypted, geographically distributed copies
  • Quarterly tested recovery drills with signed reports
  • M365, Google Workspace, GitHub, Salesforce — covered
Outcomes our clients see
< 1 hr
RPO for critical workloads
< 4 hrs
RTO for critical workloads
0
data-loss events across clients in 2025
4 / yr
tested recovery drills, signed reports
Get a written assessment

30 minutes. No pressure. Yours to keep.

Why companies call us

If any of this sounds familiar, you're in the right place.

"I'm not 100% sure our backups even work."

The gap: A backup vendor exists, charges $X/month, and produces a green dashboard. Nobody has done a real restore.

What we do: Quarterly recovery drills. Real workloads, real timing, signed reports. Your board sees green for a reason.

"We don't back up SaaS."

The gap: M365, Google Workspace, GitHub, Salesforce, Notion — your SaaS providers don't back up your data the way you think. Read their fine print.

What we do: Independent third-party backups for every critical SaaS. Granular restore. Long retention. Yours, not theirs.

"If ransomware hit us today, I have no idea what would happen."

The gap: No documented RPO/RTO. No tested playbook. No isolated recovery environment.

What we do: 3-2-1-1-0 strategy with immutable copies. Documented playbooks. Clean-room recovery environment. Annual ransomware tabletop.

What's included

Every capability you need. None you don't.

We build a tailored scope against your environment. Here's the full menu — pick what fits, drop what doesn't.

3-2-1-1-0 strategy

3 copies, 2 media, 1 off-site, 1 immutable, 0 errors after testing. Industry gold standard, in production.

Immutable cloud backups

Object-lock + WORM storage. Even root credentials cannot delete. Ransomware survives 0 hours.

Cross-region replication

Geographically distributed copies, with documented failover steps and tested fallback.

SaaS backup

M365, Google Workspace, Salesforce, GitHub, GitLab, Box, Dropbox, Notion, Slack — daily, granular, restorable.

Endpoint backup

Optional, opinionated. We don't love it for most clients (cloud-first), but support it where it makes sense.

Database backup

Logical + physical, point-in-time restore, tested with synthetic data and full restores quarterly.

Disaster recovery

Tiered DR strategy: hot, warm, cold. Documented RPO/RTO, tested annually, evidence packaged for auditors.

Ransomware-ready playbooks

Pre-signed authority to act. Clean-room recovery environment. Communication trees. Insurance broker liaison.

Compliance-aligned retention

HIPAA, SOX, PCI, GDPR/CCPA retention rules baked in. Legal hold workflows. Audit trail.

What you'll have in 90 days

Real, measurable, signed-off.

Every deliverable is documented, version-controlled, and yours to keep — even if you ever leave.

  • Backup posture audit

    A complete inventory of what you back up, how, where, and whether it works.

  • RPO / RTO definition

    Clear, board-approved targets per workload, with the architecture to deliver them.

  • Immutability rollout

    Object-lock storage, role separation, deletion protection across all critical backups.

  • SaaS backup deployment

    M365, Google Workspace, GitHub, Salesforce, others as needed.

  • Quarterly recovery drill

    Real workload restored, real time measured, signed report shared with leadership.

  • Annual ransomware tabletop

    A 3-hour exercise with leadership, IT, legal, comms. Documented gaps + fixes.

  • Insurance broker handoff

    Evidence pack tailored for cyber insurance underwriting and renewals.

  • Retention & legal-hold playbook

    Documented retention by data class, with eDiscovery / legal-hold workflows.

How we work

A predictable process. No black boxes.

  1. 01

    Inventory

    List every workload, every SaaS, every database. Map current backup posture. Find the gaps.

  2. 02

    Architect

    Design 3-2-1-1-0 with immutability. Set RPO/RTO targets per workload. Validate with leadership.

  3. 03

    Test

    Run a real recovery drill on every critical system. Document the timing. Fix the gaps.

  4. 04

    Operate

    Continuous monitoring. Quarterly drills. Annual tabletop. Compounding confidence.

Common questions

Top questions about backup & recovery.

Don't see yours? Ask us anything — we answer real emails personally.

Don't Microsoft / Google back up our data?

Not the way you think. They protect against their failure, not yours. Accidentally deleted email, malicious admin, ransomware that propagates to your tenant — those are your problem, not theirs. Read the shared responsibility model.

How often do you test recovery?

Quarterly for every critical workload, with a signed report. Plus an annual end-to-end ransomware tabletop with leadership.

What's your declared RPO and RTO?

Workload-dependent. For critical production: <1 hour RPO, <4 hours RTO. For tier-2: <24 hours RPO, <24 hours RTO. We'll define yours together — and we'll meet them.

Do you partner with cyber insurance brokers?

Yes. We package evidence for underwriting and renewal. Several of our clients have seen lower premiums after we took over their backup posture.

What if we already use Veeam / Cohesity / Druva / Rubrik?

Great — we'll manage what you have. We're tool-agnostic for backup. We have opinions, but the right tool is the one that fits your workloads and budget.
Ready when you are

Let's see if backup & recovery is the right fit.

Book a 30-minute discovery call. We'll listen, ask better questions than the last guys, and write up a tailored proposal — only if it makes sense for you.