Услуга · Backup

Backup configuration

First we establish two numbers: how much work it is acceptable to lose and how long the organisation can withstand being stopped. Without those reference points choosing a scheme becomes guesswork.

Two numbers
calculated before we configure
Three copies
on two types of media
Read only
beyond ransomware's reach
Verification
to a calendar

What the work includes

We set up not only the backup itself but the verification routine. An archive nobody has ever restored is a hope, not a defence.

Discuss the scope

We work out the targets

What is critical, how much data you can afford to lose and how many hours you have to come back up.

We design the scheme

Three copies, two different media types, one of them definitely off-site.

We configure the jobs

Servers, databases, virtual machines, device configuration, mail.

We lock down the archives

Separate credentials and immutability enabled so ransomware cannot reach it.

We monitor

The alert about a failed job goes to a real person rather than a long-departed employee's mailbox.

We verify

A written routine: spot checks monthly, a full server restore once a quarter.

How it goes

A typical infrastructure is set up in a week or two including the first full run.

01

We review

What is backed up, what is not, where the archives sit and whether anyone has ever tried a restore.

02

We design

A design with the volumes, the retention periods and the window in which everything can complete.

03

We configure

Jobs, storage, permissions and alerts.

04

We restore

A test restore against a stopwatch. The number you get is the real recovery time.

Retention depth matters more than how often you back up. Ransomware sits in the network for weeks before it fires. If your archives live seven days and the malware triggers on the fourteenth, every copy you have is already ruined. A sensible minimum is a month of daily copies plus monthly snapshots going back a year.

Questions and answers

Databases exported the proper way, virtual machine images, the configuration of network gear and firewalls, the directory service, software licence keys. Device configuration is what people forget most often: the data is there, but only the engineer remembers how it was all set up.

Spot checks every month, and once a quarter restore a critical server in full with a stopwatch. The real time is almost always longer than expected, and it is better to learn that in a drill than on the day of an outage.

Only if the permissions are set correctly. If the account the backup runs under can delete objects, the malware will reach the remote archives too. What is required is write-only access plus immutability enabled on the storage.

We will set up your backups

Tell us what needs protecting and how much downtime you can survive. We will propose a scheme to fit those numbers.