Never verified
Files copied, never opened. Interrupted transfers leave items with correct names and sizes and truncated contents. The listing looks complete until someone tries to use it.
A backup answers “do the files still exist?” Disaster recovery answers “how long until we are trading again, and what do we lose in the meantime?” Most organisations have addressed the first and assume it settles the second.
We are a recovery lab rather than a backup provider, so this covers the half nobody plans for: what you do when the restore fails, and how data comes back off the hardware that took it down.
Unglamorous, and they turn a vague intention into something testable.
Recovery Point Objective is how much data you can afford to lose, expressed as time. A nightly backup gives you an RPO of up to 24 hours — a failure at 4pm loses everything since the previous night. If that is unacceptable, nightly backups are not sufficient, regardless of how reliable they are.
Recovery Time Objective is how long you can afford to be down. This is the one people have genuinely never calculated. Restoring several terabytes from cloud storage over a business broadband connection can take days — the backup is perfect and the business is still stopped.
Both numbers are decisions rather than technical facts, and they should be made by whoever carries the cost of being down rather than by whoever manages the storage.
Every one of these has arrived here attached to a business that believed it was covered.
Files copied, never opened. Interrupted transfers leave items with correct names and sizes and truncated contents. The listing looks complete until someone tries to use it.
A NAS in the same building, reachable from the infected machine. Ransomware follows mapped drives and network shares deliberately, and a power event takes both.
The job failed, the alert went to a mailbox nobody reads, and nothing has run since. Discovered at exactly the wrong moment.
Documents covered, databases and mail stores not — because those are locked while running and the job skipped them silently.
Old advice, still correct, and each part addresses a specific failure.
The original plus two backups. Two copies means one failure away from none, and backup media fails at the same rate as everything else.
Not two folders on the same NAS. Different hardware, ideally different technology, so a single fault or firmware bug cannot take both.
Physically elsewhere, or in a service the local network cannot reach with normal credentials. This is the part that survives fire, theft and ransomware.
Storage that cannot be altered or deleted for a set period. It is the only arrangement that reliably survives an attacker with your administrator credentials.
The single most valuable hour available to any business reading this.
Pick a real file from a month ago and restore it. Time how long it takes, including finding it. Then pick something large — a database, a mail store, a project folder — and do the same.
What that hour usually reveals: nobody knows the credentials, the restore is slower than anyone assumed, the job stopped covering a critical share when it was moved, or the person who set it up has left. All four are cheap to discover on a Tuesday and expensive to discover during an incident.
And where a failure has already happened, image the affected system before restoring over it. Auditors, insurers and the ICO may need to see the state as it was, and a restore removes that permanently. Business recovery in Manchester is from £500 +VAT after a free 48-hour diagnostic.
A backup is a copy of your data. Disaster recovery is a plan for resuming operations — which includes the copy, but also how long the restore takes, who performs it, and what the business does in the meantime.
Recovery Point Objective is how much data you can afford to lose, expressed as time — a nightly backup means up to 24 hours. Recovery Time Objective is how long you can afford to be down, which is the one most businesses have never calculated.
Not on its own. A single NAS on the same network is one copy in another box, exposed to the same power event, the same ransomware and the same fire or theft. It becomes a backup when there is a second copy somewhere it cannot reach.
Restore from it. Pick a real file from a month ago, then something large like a database or mail store, and time the whole process. That hour reveals missing credentials, unexpected duration and jobs that quietly stopped covering things.
Three copies of your data, on two different media or systems, with one off site. Each part addresses a specific failure — and adding one immutable copy is the only arrangement that reliably survives an attacker holding your admin credentials.
Image the affected system first. Restoring over the original destroys the state auditors, insurers or the ICO may need to see — and it costs nothing to preserve. You can always restore afterwards; you cannot un-restore.