Area 07 · Operations and infrastructure

Backup and restore

A backup console reporting “success” every night proves very little on its own. What counts is whether, at nine on Monday with the server encrypted, your accountant can open Friday's books and your shop can start taking orders again. So we work the opposite way round from most providers: first we settle how long each system may be down and how much work can be lost, then we design the backups, and finally we genuinely restore and time the result. All of it remotely, tests included.

3-2-1
three copies, two media types, one kept off site
Record
of every test restore, dated and timed
Spain or EU
home of the off-site copy
Plan
for recovery, written before anything goes wrong

Two numbers before picking any tool

For every system we agree the RTO, how long it can be unavailable, and the RPO, how much recent work may be lost. Below are rough figures for an SME of ten to fifty people.

ERP and invoicing

Four hours down, one hour of data. A nightly copy of a3ERP or Sage 200 falls short on the final day for filing VAT. The database needs its transaction log captured several times a day.

Shared folders and SharePoint

Twenty-four hours for both. Most companies are fine with one daily copy after closing time, plus snapshots through the day to catch slips.

Microsoft 365 email

Four hours down, one hour of data. A mailbox emptied by a departing employee, or a contract deleted two months ago, can only be retrieved from an independent tenant backup.

Online shop

One hour down, minutes of data. With orders arriving from Amazon.es and payments via Redsys and Bizum, restoring from a backup is far too slow. You need a standby environment ready to go and database replication.

Laptops

Twenty-four hours for both. Achievable only when documents sit in OneDrive or SharePoint with their own backup, rather than on one particular machine's desktop.

Your backup server should not trust its own domain. If the backup console signs in with the same Active Directory accounts as everyone else, whoever steals an admin password can wipe the backups before encrypting anything. That is why we separate backup credentials, turn on two-factor sign-in and keep at least one destination that not even an administrator can empty.

How we work

Four steps, all via remote access to your servers and Microsoft 365. Any competent provider handles the first three; the fourth, restoring and timing, is the one hardly anybody does and the only one that proves anything.

01

Finding the data

We trace where everything is stored. Something almost always sits outside the backups: quotes on a laptop desktop, the clinic software's database on another drive, or building plans in someone's personal Dropbox.

02

Agreeing targets

Together we give each system an acceptable downtime and data loss. Those figures drive the budget, not the reverse.

03

Configure and monitor

Schedule, retention, encryption and off-site copy. An alert fires when a job fails and also when the expected report simply never shows up.

04

Restore for real

At the agreed frequency we recover selected data into an isolated environment and time it. The outcome goes into a dated record you can hand to an auditor or insurer.

Common questions

Because having backups and being able to restore are two different things. Reviews turn up all sorts: a NAS still copying drive D: although the ERP moved to drive E: two years ago, a USB disk that filled up in March and has stored nothing new since, or encrypted backups whose password only the previous technician knew. A few hours of remote work tell you whether your current setup would get you out of trouble and what needs to change.

They are your last line of defence, provided they survive the attack. Modern ransomware does not just encrypt; it first spends days locating the NAS and backup server so it can erase them and force payment. A deletion-locked copy at an external provider, plus a recently tested restore, lets you resume work without negotiating with anyone. If the worst happens, bear in mind that INCIBE runs a free cybersecurity helpline for businesses and the public.

A sensible starting point is daily copies for thirty days, weekly ones for three months and monthly ones for a year. Accounting records need far longer, since Spain's Commercial Code requires them to be kept for six years, and clinical records must be held for at least five years after each discharge under Ley 41/2002. Your advisers confirm those periods, and we turn them into retention rules.

Yes. GDPR explicitly mentions the ability to restore availability of personal data promptly, the ENS contains specific backup measures and NIS2 requires business continuity management. Dated restore records are tangible evidence for an auditor or the AEPD. Whether NIS2 applies to your company is something your legal adviser should confirm.

The NAS or server reports the fault and we see it before you do. We tell you which disk model to buy and which bay holds the dead one, marked on a photo. The physical swap is done by someone on your team with our guidance over video, or by your usual technician. After that, we follow the RAID rebuild and data checks remotely to the end. Apply does not travel to site or sell disks.

We check whether your backups actually restore

We review your current setup remotely, attempt a real restore and tell you plainly whether it would save you on the day of an incident.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.