Abstract dark navy and purple graphic representing backup vs disaster recovery
| |

Why Backup Is Not Disaster Recovery: Building Recovery That Works

Most businesses we work with have backups. Most of them would struggle to recover from a serious incident. The gap between having a backup and being able to recover is where businesses fail when it matters most.

Backup is a copy. Recovery is a plan.

A backup is a copy of your data stored somewhere else. That is necessary, but it is the easy part. Recovery is the process of getting your business running again after something destroys or encrypts your primary systems. It involves decisions about what to restore first, how to restore it, where to restore it to, and how long each step takes. If nobody has thought through those decisions before the incident, the recovery will be slow, chaotic, and expensive.

The questions that matter

Recovery time objective: how long can you be down before the business is seriously damaged? For some businesses it is hours. For others it is days. The number drives everything else, because it determines what kind of backup and recovery setup you need.

Recovery point objective: how much data can you afford to lose? If you back up every 24 hours, you can lose up to a day of work. If that is acceptable, fine. If it is not, you need more frequent backups or continuous replication.

Tested restore: when did you last actually restore from a backup and confirm it worked? Not run a report that says the backup completed. Actually restored files to a test server, opened them, and confirmed they were intact. If the answer is “we have not tested it,” you have a backup, not a recovery capability.

Immutable backups

Ransomware specifically targets backups. The first thing an attacker does after gaining access is try to delete or encrypt your backups so you have no choice but to pay. If your backups are on a network share that a compromised account can reach, they are not safe.

Immutable backups cannot be altered or deleted, even by an admin account. They are written once and locked. The only way to remove them is to wait for the retention period to expire. This is the single most important thing you can do to protect against ransomware.

The tool is not the plan

We use Acronis Cyber Protect as our backup and recovery platform. It combines backup, disaster recovery, endpoint protection, and vulnerability assessment in one stack, which means one console, one agent, and one set of policies. We deliver it with our partners at MRB Secure, who bring decades of backup and recovery experience to the table. Acronis is our choice because it works — it handles immutable backups, tested restores, and rapid recovery in one platform.

Some of our clients come to us already running Veeam or Commvault, and those are solid platforms too. Where we can, we work with what you have and make it better. Where a fresh start makes sense, we recommend Acronis. Either way, the plan around the tool is what makes recovery work: defined RTO and RPO, tested restores, immutable backups, and a documented recovery process.

If you want to know whether your backup would actually work in a crisis, contact us. We will tell you what we find.

The recovery drill

The single most valuable thing any business can do for its backup strategy is run a recovery drill. Pick a system. Pick a point in time. Restore it to a test environment. Open the files. Confirm they work. Time the whole process. That gives you two things: proof that the backup works, and a baseline for how long recovery takes.

We run these drills for our managed services clients quarterly. The first drill usually surfaces problems — corrupted backups, missing data, permissions that do not restore correctly, systems that take longer to recover than the RTO allows. Better to find those problems in a drill than during an incident.

The South African context

South African businesses face specific recovery challenges. Load shedding means backups might run during power cuts, producing incomplete or corrupted copies. Internet bandwidth for cloud restores can be slow, making full-system recovery from a cloud backup impractical within the RTO. Local skills are scarce, so the person who understands the backup system might not be available at 2am on a Sunday.

These are the things we design around. Local backup appliances for fast restore, cloud copies for offsite protection, immutable storage for ransomware resistance, and a managed service so someone is always available to run the recovery. The technology is the same anywhere in the world. The design has to account for local conditions.

What a proper recovery plan looks like

A proper recovery plan is a document that someone can follow at 2am without thinking. It lists the systems in recovery priority order, the steps to restore each one, the location of the backups, the credentials needed, and the contact numbers for the people who need to be involved. It is tested, updated, and kept somewhere accessible — not on the system that just went down.

If you do not have one of those, you have backups. You do not have recovery.

See what hackers can see about your business

Get your free security scan

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *