
Almost every business we assess is backing something up. Far fewer know what's excluded, how long a full restore would actually take, or whether the last test was ever performed. That gap is where the disaster happens.
We'll tell you what's actually covered, what isn't, and what a real restore would take.
We won't sell your data or send you marketing you didn't ask for.
Every backup design comes down to these two answers. Set them deliberately with the business, and the technical decisions follow. Skip the conversation and you'll discover your real numbers during an outage.
How much data you can afford to lose, measured in time. If you back up nightly, your RPO is up to 24 hours — everything since the last snapshot is gone.
If we lost everything since the last backup, what would that cost us?
How long you can operate without the system before the impact becomes serious. This is the number most businesses have never measured, and it's usually longer than assumed.
How long can we run without this before it's a crisis rather than an inconvenience?
The exclusions are where backups fail. Cloud platforms, SaaS applications, and machine data are the three most commonly left out of scope.
Mail, OneDrive, SharePoint, Teams, and Drive. Microsoft protects its infrastructure, not your data from your own users.
Hyper-V and VMware, backed up at the host level so an entire machine can be restored or spun up rather than rebuilt.
SQL Server and Oracle with application-aware backups, so what you restore is transactionally consistent rather than a crash copy.
CRM, accounting, and line-of-business platforms. Your vendor's terms usually make your data your responsibility.
On-premises servers and, where it matters, workstations — including the machine configurations that are painful to recreate.
CNC programs, PLC configurations, and device settings — the data that isn't in a database and isn't in anyone's backup scope.
Three copies, on two different media, with one offsite. It's an old rule and it still holds — but ransomware added a requirement, because modern attacks specifically hunt for and encrypt backups before triggering.
So one copy has to be immutable: written once, unable to be altered or deleted even by an administrator account. That single property is what turns a ransomware event from a negotiation into a restore.
These aren't hypothetical. They're what the free review turns up, in rough order of frequency.
The server is backed up. Microsoft 365 isn't, because people assume Microsoft handles it — and Microsoft's terms say otherwise.
Jobs report success for years. Nobody discovers the backup is unusable until the day it's needed, which is the worst possible time to find out.
Backup stored on the same site, same network, sometimes the same server. Ransomware and fire both treat that as one target.
Modern ransomware hunts backups first. If an admin account can delete them, so can an attacker holding that account.
A compromise sitting undetected for 60 days is useless to recover from if you only keep 30 days of backups.
Restoring 8TB over a business internet connection takes days, not the hours everyone assumed when the plan was written.
A green status in a dashboard means the job ran, not that the data is usable. The only proof is restoring it — which is why we test rather than report.
Backups are checked for integrity and recoverability as they're written, not just marked complete.
Individual files and mailboxes restored to confirm granular recovery works and to keep the process familiar.
A complete server or VM restored into an isolated environment and booted to confirm it actually runs.
A tabletop or live failover exercise with your team, measuring actual recovery time against your stated RTO.
For health information, public sector records, and many client contracts, the physical location of the copy matters as much as its existence. Canadian data centres are available where residency is required, and we document the arrangement so you can evidence it.
Whether residency is legally required for your specific data is a determination for your privacy officer or counsel — we build to whatever they conclude rather than substituting our own reading.
Microsoft protects its own infrastructure and offers limited retention, but that isn't a backup of your data in the sense you need. It won't help you after a malicious deletion, a compromised account emptying a mailbox, or a requirement to restore a folder as it stood eight months ago. Microsoft's own shared responsibility model puts your data on your side of the line.
Continuous automated verification, a monthly file-level restore, a quarterly full system restore, and an annual disaster simulation. The quarterly full restore is the one most businesses skip and the one that most often reveals a problem.
The backup copy is written once and cannot be altered or deleted for a defined retention period — not by us, not by you, not by an attacker holding your administrator credentials. It's the single most important change to backup design in the last decade, because modern ransomware specifically targets backups before encrypting production.
Yes, Canadian data centres are available and we'll document the arrangement so you can evidence residency. Whether it's actually required for your data is a call for your privacy officer or counsel — we build to their determination rather than assuming.
That depends on data volume, your connection, and whether recovery is local or from offsite — which is exactly why it should be measured rather than estimated. As a rule, large volumes restored over a business internet connection take longer than people expect, which is why a local appliance is usually part of the design.
Yes, and it's free. We're looking at scope, immutability, retention, and whether restores have been tested — not trying to find fault. If your current arrangement is sound we'll tell you so, and you'll have documentation confirming it.
Backup is copies of data. Disaster recovery is the plan and infrastructure to resume operating — which may mean standby systems, documented procedures, and defined roles. You can have excellent backups and still be down for a week without a recovery plan.
The free review tells you what's covered, what's excluded, and how long a real restore would take. Findings are yours whether or not you work with us.