For businesses
Backup you have tested, recovery you have timed
Every backup product reports green until the day it matters. We audit what is genuinely protected, rebuild it so ransomware cannot delete it, agree recovery objectives with your leadership, and then prove them with a real restore and a real stopwatch.
- Independent audit of what is actually protected
- Immutable repositories isolated from production Active Directory
- Microsoft 365 protection — the gap most organizations have
- Recovery objectives agreed with leadership and costed
- Live recovery testing with measured RTO and RPO
- Runbooks for planned failover, unplanned failover, and failback
What we deliver
Find out what is actually protected
Almost every environment we audit has workloads nobody realized were unprotected, and retention that does not match what anyone believes.
- Coverage discovery — protected versus unprotected workloads, and the gaps
- Retention review against your actual legal and operational requirements
- Immutability review: whether it is configured, or merely assumed
- Microsoft 365 protection review, which is far more often missing than not
- Written findings with a prioritized remediation roadmap
Backup that survives an attack
Ransomware operators delete backups first. Whether yours survive is a design decision made long before the incident.
- Immutable backup repositories that cannot be deleted within the retention window
- Hardened Linux repositories isolated from your production Active Directory
- Object storage with S3 Object Lock for genuinely air-gapped retention
- Alignment to the 3-2-1-1-0 model, verified against what is configured
- Backup infrastructure credentials separated from production administration
A disaster recovery plan that exists
Recovery objectives agreed with your leadership, engineered toward, and written into a runbook someone can follow at 3am.
- Recovery point and recovery time objectives agreed per system and costed
- Replication design across sites or into Azure with Azure Site Recovery
- Recovery plan sequencing — boot order, dependencies, and pre- and post-scripts
- Runbooks covering planned failover, unplanned failover, and failback
- Roles, contacts, and decision authority named before an incident, not during
Proof, on a schedule
The only meaningful test of a backup is a restore. We run them and give you the numbers.
- Live recovery testing per platform, validating that data is usable and intact
- Observed recovery time and recovery point measured against your stated targets
- Full disaster recovery failover exercises with documented results
- Gap analysis between the objectives you agreed and what the test achieved
- Annual test and report cycle producing evidence for auditors and insurers
Platforms we work in
Named platforms, not categories — so you can tell at a glance whether we already know your environment.
- Backup platforms
-
- Veeam Backup & Replication
- Veeam Agent
- NetBackup
- Carbonite
- ManageEngine
- Immutability
-
- Hardened Linux repository
- S3 Object Lock
- Immutable snapshots
- Air-gapped copies
- Replication
-
- Azure Site Recovery
- Storage Replica
- Veeam Replication
- Storage
-
- NetApp
- HPE Nimble
- HPE MSA
- Amazon S3
- Azure Blob
- Workloads
-
- VMware
- Hyper-V
- Proxmox
- Microsoft 365
- AWS
- Physical servers
- Linux
How it runs
From first call to sign-off
Every engagement is governed by a written statement of work naming deliverables, assumptions, and who is responsible for what.
-
Audit current state
What is protected, what is not, what retention actually is, and whether immutability exists in configuration or only in the sales brochure.
-
Agree the objectives
Recovery point and recovery time targets set with your leadership, per system, and costed — because "no downtime" and the budget rarely coexist.
-
Design and build
Repository architecture, immutability, and replication engineered to the agreed objectives, with the backup estate isolated from production identity.
-
Test, document, repeat
Failover tested and timed, runbooks written, then an agreed retest cycle so the evidence stays current for auditors and insurers.
Questions
What people ask
Backup you have tested, recovery you have timed — questions
Our backups run every night and report success. Is that not enough?
A successful job means data was written. It does not tell you whether it can be read back, how long a restore takes, whether the retention matches your obligations, or whether an attacker with domain administrator rights could delete it all in ten minutes. Those are four different questions, and the last one is why immutability matters.
Is Microsoft 365 backed up by Microsoft?
Not in the way most people assume. Microsoft guarantees service availability and provides limited retention and recycle-bin recovery. Long-term retention, point-in-time recovery after a deletion is discovered months later, and protection against a malicious insider are your responsibility. This is one of the most common genuine gaps we find.
What does a DR test actually involve?
We execute a recovery for each in-scope platform, confirm the restored data or workload is usable and intact, and measure how long it took and how much data was lost against your stated targets. You receive a written report with results, the gap between observed and target objectives, and prioritized remediation. Testing is arranged against isolated or non-production targets so production is unaffected.
How much should this cost?
It depends entirely on the recovery objectives you choose, which is why we set them before designing anything. Recovering in a day costs a fraction of recovering in an hour. Our job is to make that trade-off explicit and priced so your leadership makes an informed decision, rather than discovering the answer during an outage.
Can you audit backups we bought from someone else?
Yes, and an independent audit is often the point. We assess whatever is in place — Veeam, NetApp snapshots, Carbonite, Microsoft 365 backup tools, native cloud snapshots — and report on coverage, retention, immutability, and tested recoverability without regard to who sold it.
When did you last restore something on purpose?
If the answer is not in the last twelve months, a scoped recovery audit will tell you what you would actually get back — and how long it would take.

