Managed IT & Support

Backup and disaster recovery

A backup is only useful if you can restore from it when it matters. We design, run and test backup and disaster recovery, covering servers, cloud workloads and Microsoft 365, with recovery objectives agreed in business terms and restores tested on a schedule.

Who this service is for

A good fit if

  • You have backups but have never tested a full restore.
  • You do not know how long it would take to recover your key systems after a failure.
  • Ransomware is a concern and your backups are on the same network as your servers.
  • Microsoft 365 email and files are not backed up separately.
  • Insurers, auditors or customers are asking about your recovery capability.

Another approach may suit you better if

  • You only need to copy personal files to an external drive at home.
  • You need a full business continuity program covering facilities, staffing and communications. We cover the IT part and can work with a continuity consultant.
  • You are not prepared to fund recovery capacity in line with your objectives. Faster recovery costs more.

What this service is

Backup and disaster recovery make sure that when something goes wrong, such as a failed server, a deleted folder, a ransomware attack, a flood or a power outage, your organization can get its systems and data back within an acceptable time.

A backup is a copy of data. Disaster recovery is the tested ability to restore systems and get people working again. Many organizations have the first without the second. Our article on why a backup is not the same as a recovery plan explains the difference.

We provide backup and disaster recovery as a project and as part of managed IT services, where backups are monitored daily and restores are tested on a schedule.

Recovery platforms we work with

  • Veeam for backup and replication of virtual machines, physical servers, cloud workloads and Microsoft 365.
  • Altaro VM Backup (now part of Hornetsecurity) for straightforward virtual machine backup in smaller environments.
  • Acronis for combined backup and endpoint protection, including workstations and remote devices.
  • Zerto for continuous replication and fast recovery of critical virtual machines.

We also use native backup services in AWS, Azure and Google Cloud where they fit. The platform follows your recovery objectives, not the other way round.

How we design for recovery

  • Several copies in different places. A common rule of thumb is three copies of data, on two types of storage, with one off site. We also keep at least one copy that cannot be altered or deleted for a set period.
  • Protection from attackers. Ransomware often targets backups first. Backup systems use separate credentials, multi-factor authentication and isolated or immutable storage.
  • Everything that matters is covered. Servers, databases, cloud workloads, Microsoft 365 email and files, and configuration of key network equipment.
  • Canadian storage. Off-site and cloud copies can be kept in Canadian locations to support data residency. We document where every copy lives.

Backing up cloud applications

Moving to the cloud does not remove the need for backup. Services such as Microsoft 365 keep themselves running, but they are not designed to recover every deleted mailbox, overwritten file or compromised account, and retention settings eventually expire. We add independent backup for Microsoft 365 email, OneDrive, SharePoint and Teams, and for cloud servers and databases, stored separately from the service being protected. Restores can be as small as one email or as large as an entire site.

Testing and planning

We schedule test restores, from single files to whole systems, and record how long each took. The disaster recovery plan sets out who declares a disaster, who does what, the order in which systems are restored and how staff and customers are kept informed.

Privacy law is relevant too. Under PIPEDA, organizations must report breaches of security safeguards that create a real risk of significant harm, and ransomware incidents can fall into that category. Recovery planning should include your breach response process. We explain the technical side; this is not legal advice. For prevention and detection, see our cybersecurity services.

What is included

The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.

Typical deliverables

  • A review of current backups, coverage gaps and recovery capability.
  • Recovery point and recovery time objectives agreed for each key system.
  • A backup design with on-site and off-site copies, including immutable or isolated copies where suitable.
  • Backup of servers, virtual machines, cloud workloads and Microsoft 365.
  • Daily monitoring of backup jobs, with failures investigated and fixed.
  • Scheduled test restores, with results recorded.
  • A written disaster recovery plan with step-by-step recovery procedures and contacts.
  • Recovery support when an incident happens.

Not included unless agreed separately

  • Backup software licences, storage and cloud consumption charges, billed separately.
  • Recovery of data that was never included in the agreed backup scope.
  • Forensic investigation after a cyberattack, which is handled by specialists.
  • Facilities, staffing or communications planning beyond IT systems.

What we will need from you

Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.

  • Administrative access to servers, storage, cloud accounts and Microsoft 365.
  • Decisions from business owners on acceptable data loss and downtime for each system.
  • Network capacity for off-site backup traffic.
  • Time from key staff to take part in recovery tests.
Delivery

How the work is delivered

Each stage ends with something you can review before the next one starts.

  1. Review

    We inventory systems and data, check existing backups and identify gaps and single points of failure.

    Output: Backup and recovery review.

  2. Set objectives

    With your business owners, we agree how much data loss and downtime each system can tolerate.

    Output: Recovery objectives for each system.

  3. Design and deploy

    We implement the backup platform, off-site and ransomware-resistant copies, and monitoring.

    Output: Working backups and a monitoring report.

  4. Test and document

    We perform test restores, measure recovery times and write the disaster recovery plan.

    Output: Test results and a disaster recovery plan.

  5. Monitor and rehearse

    Backups are checked daily, and restores and recovery exercises are repeated on a schedule.

    Output: Regular test reports.

Testing and handover

  • Test restores prove that backups can actually be recovered, not just that jobs completed.
  • Measured recovery times are compared with the agreed objectives.
  • At least one backup copy is kept off site and protected from deletion or encryption by attackers.
  • Backup administrator accounts are separate and protected with multi-factor authentication.
  • The disaster recovery plan is stored where it can be reached even if your main systems are down.

What affects the cost

We do not publish package prices. Each estimate is based on an agreed scope, in Canadian dollars, with taxes shown separately. These are the things that move the number most:

  • The amount of data and the number of systems protected.
  • How much data loss and downtime each system can tolerate.
  • Retention periods required by your policies or regulators.
  • Where backups are stored, including Canadian locations for residency.
  • How often restores and recovery exercises are tested.

Questions buyers usually ask

Which backup platforms do you use?

We work with platforms such as Veeam, Altaro VM Backup (now part of Hornetsecurity), Acronis and Zerto, as well as native cloud backup services. The choice depends on your systems, recovery objectives and budget. Naming these vendors does not imply any partnership with them.

What are recovery point and recovery time objectives?

The recovery point objective is how much data, measured in time, you can afford to lose. The recovery time objective is how long a system can be unavailable. Agreeing both for each system drives the backup design and its cost.

Can backups protect us from ransomware?

Backups are a key part of ransomware recovery, but only if attackers cannot delete or encrypt them. We keep isolated or immutable copies, protect backup accounts and test restores. Backups do not prevent an attack, so we pair them with security controls.

Can our backups stay in Canada?

Yes, in most cases. Many backup platforms and cloud providers offer Canadian storage locations. We confirm where each copy is stored, including any provider support or replication processes, and document it.

Could you recover tomorrow?

Tell us what you back up today and which systems matter most. We will reply to arrange a conversation about your recovery readiness.