Backups that run where you work
Servers, workstations, virtual machines, and Microsoft 365. On-premises, cloud, or both. If it holds data your business needs on Monday, it gets a retention policy and someone’s name against it.
Most businesses have backups. Far fewer have proof those backups restore. A backup that has never been restored is a hypothesis, not a safety net. We design backup and disaster recovery for small and mid-sized businesses, run the restores on a schedule, and send you the results whether they went well or not.
Ask a business owner whether they're backed up and almost everyone says yes. Something is running. There's a console somewhere. Green checkmarks appear.
Ask when someone last restored a server from that backup and watched it boot, and the answer changes.
That gap has now been measured. In Veeam's Data Trust and Resilience Report 2026, a survey of more than 900 IT, security, and risk leaders, 90% said they were confident in their ability to recover from a cyber incident. Among organizations that were actually hit by ransomware, fewer than one in three fully recovered their data. Confidence and proof turned out to be two different things.
The uncomfortable part is that nobody in that 90% thought they were wrong. They had backups. The backups reported success. The problem surfaced on the one day it couldn't be fixed.
Servers, workstations, virtual machines, and Microsoft 365. On-premises, cloud, or both. If it holds data your business needs on Monday, it gets a retention policy and someone’s name against it.
At least one copy that cannot be altered or deleted, including by an administrator account an attacker has taken over. This is the specific control that decides whether a ransomware incident is an outage or a negotiation.
We restore from your backups on a recurring schedule and document the result. Not a checksum. An actual restore, verified, with the time it took written down.
How much data you can afford to lose, and how long you can afford to be down. Those two numbers drive every design decision, and most businesses have never been asked either question.
Documented order of operations, dependencies, credentials location, and who calls whom. Kept offline, because the plan stored on the encrypted file server is not a plan.
Failed jobs get chased the day they fail. You get a monthly summary in plain language, including the restore test result.
Every figure in this section comes from a published, dated, third-party report. None of it is our own measurement, and we've noted the source for each so you can check it.
Sophos’s State of Ransomware 2026, based on 2,158 organizations across 17 countries that were hit in the previous twelve months, found 56% of attacks succeeded in encrypting data — up from 50% the year before.
In the same report, only 34% of organizations with 100 to 250 employees stopped an attack before encryption or extortion. At organizations of 3,001 to 5,000 employees, 46% did. The gap is twelve points, and it is widening.
Backup-based recovery rose to 66% of encrypted-data cases in 2026, up twelve percentage points in a year. Forty-eight percent of encrypted victims paid the ransom. The organizations that recovered from backup were the ones that had a choice.
Average recovery cost across the Sophos 2026 sample was $1.7 million per incident, up 11% year over year — and that figure excludes any ransom paid.
Sophos’s dedicated research on backup compromise (2024 survey data) found 94% of organizations hit by ransomware said attackers attempted to compromise their backups during the attack. Where those attempts succeeded, median ransom demands were roughly double and total recovery costs ran about eight times higher. Backups are not incidental to a ransomware attack. They are a target inside it.
Sources: Sophos, State of Ransomware 2026 (2,158 respondents, 17 countries); Sophos, The Impact of Compromised Backups on Ransomware Outcomes (2024 survey data); Veeam, Data Trust and Resilience Report 2026 (900+ respondents). Figures from published third-party research, current as of July 2026.
This is the single most common gap we find, and it isn't a criticism of Microsoft. It's how the service is designed and documented.
Microsoft replicates your data across data centers so the service stays available. Replication is not backup. A file that gets deleted replicates as deleted. A file that gets encrypted by ransomware syncing through OneDrive replicates as encrypted.
What you get natively is a short recovery window, not an archive:
The SharePoint figure is Microsoft's own published documentation, not a vendor claim. After the 93-day window closes, the data is gone, including for Microsoft support.
That window is fine for the intern who deleted a folder on Tuesday. It is not fine for a finance-department mailbox nobody opened for four months, a former employee's OneDrive that turns out to have held the only copy of something, or a compliance request that reaches back a year.
Reference: Microsoft Learn — Microsoft 365 SharePoint data deletion . Exchange Online figures are tenant defaults and can be changed per tenant.
Inventory of servers, endpoints, cloud workloads, and SaaS data. What’s protected, what isn’t, and what everyone assumed was covered. This is usually the part that surprises people.
RPO is how far back you’d be restoring from, meaning how much work gets redone. RTO is how long you’re down. Both are business decisions with cost attached, not IT decisions. We ask; you decide.
Three copies of the data, on two types of media, one off-site, one immutable, and zero errors on the last verified restore.
We run scheduled restores and record what came back and how long it took. If a restore fails, that is a finding to fix now, on a normal Tuesday, rather than a discovery to make during an incident.
Recovery order, dependencies, contacts, credentials location. Printed and stored where an encrypted network can’t reach it.
Step 3 is the working version of federal guidance: CISA's #StopRansomware Guide recommends offline, encrypted backups with regular testing of availability and integrity.
ERP, practice management, accounting, a file server everyone maps a drive to. These are the systems where an outage stops billable work.
The move was probably correct. The assumption that came with it usually isn’t.
HIPAA, CMMC, PCI, cyber insurance applications, and client security questionnaires all ask about backup and tested recovery. Several now ask for the date of your last restore test. Having an answer is the difference between a renewal and a re-underwrite.
A drive failure, a deleted folder, a phishing incident that could have gone worse. The scare is the cheapest information you will ever get about your recovery posture.
Backup and recovery is where key-person risk becomes company risk.
Worth saying plainly, because the industry usually doesn't.
Backup is the last layer, not the first. It determines what a bad day costs, not whether you have one. Sophos’s 2026 data found malicious email and phishing together accounted for half of all ransomware incidents, and 79% of attacks started with an identity-based approach — which is where prevention lives.
If an attacker copied your data before encrypting it, restoring clean systems doesn’t unpublish anything. A clean restore removes their leverage over your operations. It does not remove their leverage over your reputation. Those are separate problems and we won’t pretend otherwise.
Restoring a file takes minutes. Restoring a server takes hours. Restoring an environment after a full compromise takes longer than that, because the systems have to be verified clean before they go back on the network. Anyone quoting you a recovery time before they’ve seen your environment is guessing.
Everything between your last good backup and the incident is gone. That interval is your RPO. It is a number you choose and pay for, and the honest conversation is about how much it’s worth, not about pretending it’s zero.
We’ll tell you what we measured, on your equipment, after we’ve run it.
Yes, and this is the most common misunderstanding we correct. Microsoft and Google protect the platform’s availability. Your data inside it is your responsibility, with a native recovery window measured in weeks, not years.
On a defined schedule agreed up front, with the result documented either way. If you’re asking because your current provider doesn’t, that’s the answer to your real question.
It tries. Sophos found 94% of ransomware victims said attackers attempted to compromise their backups during the attack (2024 survey data). This is why at least one copy has to be immutable, meaning it can’t be deleted or altered even by a compromised administrator account.
It depends on what failed and what you’re restoring. We won’t quote a number before we’ve inventoried your environment and run a real restore. After that, we’ll give you a measured figure rather than a marketing one.
Backup is the copy. Disaster recovery is the plan, the order of operations, and the tested ability to bring a business back. Plenty of companies buy the first and assume they got the second.
Often not. Owning a backup product and having tested recovery are different things, and the gap is usually process rather than software. We’ll tell you if what you have is fine.
Yes.
It scales with how much data you have, how far back you need to go, and how fast you need to be back. The RTO and RPO conversation happens before the pricing conversation, because it’s what sets the price.
Backups decide what the bad day costs. Endpoint security decides how often you have one.
Malicious email and phishing accounted for half of all ransomware incidents in Sophos’s 2026 data.
Detecting an intrusion before encryption starts is what keeps a backup from being needed at all.
Tenant configuration, retention policy, and admin access control are where Microsoft 365 data is either protected or quietly exposed.
What we deliver remotely vs. what needs someone on-site, in one place.
We'll inventory what's being protected, check whether any copy is immutable, review your Microsoft 365 retention settings, and pull a real restore so you can see how long it takes. You get the findings whether they're good or bad. Plain findings, no pressure.
Trusted by dozens of businesses