Backups and Business Continuity: What to Require from Your IT Provider

Backups and business continuity are not the same thing. A backup answers the question “is our data stored somewhere?”, while business continuity answers a far more important one: “how quickly will we be working again after an incident, and how much data will we lose?”. A company that wants real protection needs both: reliable backups following the 3-2-1 rule, and a documented, regularly tested recovery plan with clearly defined RPO and RTO targets.

In practice, the most common problem is not that backups are missing — it is that nobody has ever tried to restore from them. A backup whose restore has never been tested is merely an assumption that everything is fine. Companies typically discover that something is wrong at the worst possible moment — after a hardware failure, a human error, or an attack.

This article explains how backups differ from continuity, what RPO and RTO mean, what specific commitments to require from your IT provider, and which mistakes come to light too late.

Why backups alone do not guarantee business continuity

A backup is a duplicate of your data from which recovery is theoretically possible. Business continuity is the full set of arrangements that ensure the company actually returns to work after an incident: what gets restored first, who is responsible, where systems are brought back up if the primary infrastructure is unavailable, and how long all of this takes.

Imagine a server has failed and the backups exist. Do you know how many hours it will take before your accounting system is running again? Who will restore it if the responsible person is on holiday? On what hardware will it be restored and brought back up if the server itself is broken? Do you even have such hardware — and if not, how quickly and from where will you get it? If there are no answers to these questions, you have backups but no continuity plan. That is why your IT support contract should explicitly cover not only backup creation but also recovery commitments.

The 3-2-1 rule in plain terms

The classic rule that has proven itself best in practice:

  • 3 copies — the original data plus at least two backup copies;
  • 2 different media or environments — for example, a local backup server and cloud storage, so that the failure of a single technology cannot destroy everything;
  • 1 copy off-site — physically separated from the primary infrastructure: in another data center or in the cloud, so that a fire, theft, or a ransomware attack at the office cannot reach it.

A further modern requirement: at least one copy must be immutable or disconnected from the primary network, so that an attacker who has obtained administrator rights in the main network cannot encrypt or delete it.

RPO and RTO: how much data you can lose and how long you can stand still

Two metrics every executive should know:

  • RPO (Recovery Point Objective) — how much data you can afford to lose. If backups run once a day, in the worst case you lose up to a full day of work. That means the lost data has to be sourced from somewhere and re-entered by hand. If that is unacceptable, backups must run more frequently.
  • RTO (Recovery Time Objective) — how long you can afford to be down: how long it takes until the backups are restored and people can work again. It is the time from the incident to the moment your systems are running again. The shorter the RTO, the more expensive and sophisticated the solutions required to achieve it.

These targets can and should differ between systems — there is no point in applying the same requirements to an archive as to your sales platform. A sample line of reasoning:

Example system The RPO question The RTO question
Sales or production management system Can we afford to lose several hours of orders? What does every hour of downtime cost us?
Accounting and documents Is losing a day of entries acceptable? Can we wait until the next business day?
Email and collaboration tools How much correspondence can we lose? How long can the company operate without email?
Archives and legacy documentation Are less frequent backups sufficient? Can recovery take longer?

The answers to these questions must come from the business, not from the IT department — the IT provider’s job is to propose a technical solution that delivers the agreed targets. We explain how these metrics connect to service level commitments on our page about what SLA your company needs.

What to require from your IT provider

If an external partner is responsible for your backups, agree on and put the following in writing:

  1. Regular restore testing. Not just a promise that backups are running, but a commitment that recovery is periodically tested and the results are reported. Only a successful test restore proves that a backup works.
  2. Off-site copies. At least one copy must sit outside your primary infrastructure and be either disconnected (off-line) or immutable — in another data center or in the cloud.
  3. Encryption. Backups must be encrypted both at rest and in transit — they contain the company’s most sensitive data.
  4. A documented recovery plan. Who restores what and in what order, where credentials are stored, and what RPO and RTO have been agreed for each system.
  5. Regular reporting. Whether all backup jobs succeeded, whether errors occurred, and when the last restore test was performed. Continuous automated monitoring of the kind used in our systems support and monitoring services means a failed backup is spotted the same day — not after an incident.

Typical mistakes that surface too late

  • Backups stored on the same server or in the same room. When a disk array fails, a fire breaks out or an attacker encrypts the data, the original and the backup perish together.
  • Restores that have never been tested. The most common mistake of all: the backup job reports success, but actual recovery turns out to be impossible — corrupted files, missing databases, forgotten passwords. More than a few companies also have no alternative hardware to restore onto and resume work on once the current equipment has failed.
  • Unencrypted backups. A stolen or lost backup medium becomes a data breach with all its legal consequences.
  • Not everything is backed up. New servers, new systems, and employee laptops are left out of the backup plan because nobody thought to add them.
  • Backups accessible with the same administrator credentials. An attacker who takes over an administrator account deletes the backups first.

The ransomware context: backups as the last line of defense

During a ransomware attack, attackers deliberately hunt for backups and try to destroy or encrypt them, leaving the company no option but to pay. Backup architecture must therefore be designed on the assumption that the primary network is already compromised: off-site, immutable copies protected by separate credentials, with a clear recovery scenario.

Backups are the last line of defense, but not the only one — we cover preventive measures on our IT security services page, and if the directive applies to your organization, see our overview of NIS2 requirements. It is worth knowing that business continuity and backups are among the risk management measures NIS2 explicitly names.

The role of the cloud

The cloud naturally solves the one-copy-off-site requirement: data is stored in a physically remote, professionally managed infrastructure. Altic IT builds client solutions on the Microsoft Azure cloud or in a trusted Baltic Tier III data center — in both cases, backups end up in an environment with professional physical and logical protection that an office server room typically lacks.

Cloud storage also scales flexibly as data grows and allows backup jobs and monitoring to be automated. You will find the available models on our cloud services page, and if you are considering retiring your server room altogether, see our comparison of an office server room versus a data center or the cloud.

Why Altic IT

We design and manage backup and business continuity solutions as an ISO-certified IT services company — with documented processes, automated monitoring, and regular client reporting.

  • 180+ clients served, ~350 managed servers, and ~3,500 managed computers and mobile devices;
  • ISO 27001 (information security) and ISO 20000 (IT service management) certifications;
  • professional liability and cyber risk insurance of EUR 2 million;
  • cloud solutions on Microsoft Azure or in a Baltic Tier III data center (Delska);
  • continuous automated monitoring of IT systems and regular reporting;
  • within the first 3 months, client incident volumes drop by up to 5 times, and the vast majority of our clients come through referrals.

Frequently asked questions

  • How often should backups be made?

    As often as needed to keep data loss within acceptable limits — that is exactly what the RPO metric defines. Critical systems are backed up frequently, slow-changing archives less often. There is no single answer for every company: the frequency is set by assessing how important each system is to the business.

  • How do we know whether our backups actually work?

    The only reliable way is a test restore: a system or set of files is actually recovered from the backup and verified to work. Such tests must run regularly and their results must be recorded in reports. If your provider cannot show evidence of the last successful restore test, treat the reliability of your backups as unknown.

  • Is the built-in protection in Microsoft 365 enough?

    The cloud provider guarantees that the infrastructure runs, but protecting the data itself against deletion, errors, or ransomware remains the client’s responsibility. That is why a separate, additional backup strategy — with its own retention periods and restore capabilities, independent of M365 — is recommended for cloud environment data as well.

  • How does a backup differ from a business continuity plan?

    Backups are only one component of a continuity plan. The plan additionally defines who restores systems and in what order, where they are brought back up, how quickly they must be running, and how the company operates during recovery. Backups without a plan usually mean a long and chaotic recovery.

  • Do backups protect against ransomware?

    Only when they are designed correctly: off-site, encrypted, disconnected (off-line) or immutable, inaccessible with the primary administrator credentials, and regularly tested. Attackers deliberately target backups, so their mere existence does not guarantee there will be anything left to restore from after an attack.

Verify the reliability of your backups

Do not wait for an incident to find out whether your backups work. Altic IT specialists will assess your backup strategy and recovery capabilities and provide concrete recommendations. Call +370 5 2032018 or reach us via the contacts page — we will discuss your situation and arrange an assessment.

Contact Altic IT

IT paslaugos verslui - Altic.lt
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Read more information about our Privacy policy