Resources
The reference we wish existed when we were the ones on call.
Plain definitions, the questions worth asking about your own estate, and comparisons that admit where the alternative wins. No gated whitepapers, no form in front of any of it.
Self-assessment
Six questions about your current backups.
Ask these of whatever you run today, including if that's us. Any answer that starts with 'I think' is the one worth chasing.
When did you last complete a full restore, end to end, and how long did it take?
If the answer isn't a date and a number, you have backups but no recovery capability. This is the single question that separates the two.
Could an attacker with domain admin delete your backups?
If backup storage is reachable with production credentials, the answer is yes, and the backup is part of the blast radius rather than the way out of it.
Is Microsoft 365 backed up, or do you assume Microsoft does it?
Microsoft protects the platform. The data in it is yours to protect — their shared responsibility model says so explicitly.
Who else can run a restore if the person who built this is unavailable?
Bus factor is a recovery risk, not an HR one. Incidents rarely wait for the right person to be reachable.
Would you know within an hour if backups silently stopped running?
A failing job usually alerts. A job that stopped running often stops alerting too, which is why gaps get discovered during the incident.
Can you produce evidence of recovery capability for an auditor or insurer?
Increasingly this is contractual. A restore report with a measured RTO answers it; a screenshot of a green dashboard does not.
Glossary
The vocabulary, without the vendor gloss.
- RPORecovery point objective
- How much data you are willing to lose, measured in time. An RPO of one hour means a restore point exists at least every hour, so the worst case is losing an hour of work. It is a business decision expressed as a technical setting, and it is bounded by bandwidth: a workload changing faster than your link can ship will not meet it, whatever the schedule says.
- RTORecovery time objective
- How long you are willing to be down. This is the number most estates cannot answer honestly, because it has never been measured under real conditions. A restore that has never been timed does not have an RTO — it has a hope.
- 3-2-1-1-0The backup rule, current version
- Three copies of the data, on two different media, with one off-site, one immutable or air-gapped, and zero errors on restore verification. The last two digits are the modern additions: immutability answers ransomware, and the zero answers the far more common failure of a backup that ran successfully every night and could not be restored.
- ImmutabilityWrite once, delete never — until retention expires
- Storage-enforced retention, usually via object lock. It matters because the standard ransomware playbook encrypts backups first, using the credentials that reached the file server. Permissions cannot protect against an attacker who has the permissions. Storage that physically refuses the delete can.
- Incremental foreverOne full backup, then only changes
- After the first full, only changed blocks are read and stored, with restore points synthesised from them. It reduces backup windows and storage dramatically. The tradeoff is that the chain matters, which is why verification is not optional.
- Application-consistentThe database was told a backup was happening
- A guest agent quiesces writes and flushes buffers so the snapshot lands at a coherent moment. Without it, backups are crash-consistent — equivalent to pulling the power. Most filesystems survive that; databases often do not.
- CBTChanged block tracking
- The hypervisor records which blocks changed since the last snapshot, so an incremental reads deltas instead of scanning disks. It is the difference between a backup window measured in minutes and one measured in hours.
- Air gapNo network path from production to the backup
- Historically a tape in a safe. In practice today it means backup storage with no route from a production domain, plus immutability — because an attacker who cannot reach the storage and could not delete it anyway has run out of moves.
Comparisons
Against the alternatives, including where they win.
Documentation
How the product works, by workload.
Find out whether your backups actually restore.
Connect one hypervisor, set one policy, and let a scheduled drill try to bring it back. If it doesn't, you'll know in a day rather than during an incident.
No credit card · 14-day trial · Migration assistance included