Backups you have actually tested
Almost every organization we assess has backups. A much smaller number have ever restored from them.
That gap is where the damage happens. Backups fail quietly. A job stops running after a server change and nobody notices for eight months. A database is technically backed up but not in a state you could actually recover. Everything is protected except the one file share that matters. The backup succeeds every night and writes to a drive that has been full since spring.
Nobody finds out until the day they need it, which is the worst possible day to find out.
What we do differently
We monitor every backup, every day. Not a dashboard somebody checks when they remember. We use dedicated backup monitoring so a failed or missed job raises an alert and gets worked. This is genuinely the most common gap we find in assessments, including at organizations already paying a provider for backup.
We test restores. A backup you have never restored from is a hope. We periodically restore to confirm the data comes back and comes back usable.
We design around how long you can actually be down. Before choosing tools, the real questions are how much data you can afford to lose and how long you can afford to be offline. Those two answers drive everything else, and they are usually different for your ERP than for your file shares.
We plan for the whole event, not just the files. Recovery is a sequence: what comes up first, who makes which call, how people work while systems are down, how you communicate. Data is one part.
Ransomware, without the theatrics
We are not going to put a countdown clock on this page. Here is the practical position.
Ransomware changed backup requirements in one specific way: attackers go after the backups first, because encrypted backups are what turns an incident into a payment. So the questions that matter are whether your backups are isolated from the systems they protect, whether an attacker with domain admin could reach and destroy them, and how quickly you could rebuild if they did.
Most backup setups we inherit were designed before that was the threat model. They handle a failed drive or a deleted folder well and a determined intruder badly.
What we work with
We are vendor-agnostic and match the design to the environment: on-premise, cloud, or hybrid, covering servers, workstations, Microsoft 365 and Google Workspace data, and line-of-business systems.
Worth flagging, because it surprises people: Microsoft 365 and Google Workspace do not back your data up for you in the way most people assume. They protect against their own infrastructure failing. They do not comprehensively protect you from a user deleting a mailbox, a retention policy expiring, or an attacker with valid credentials.
Getting started
If you are not sure what shape your current backups are in, that is the normal answer. A good first step is simply asking us to look at what you have.
Use the button above, or call (734) 929-1400. Or ask for a second opinion: twenty minutes, no obligation.
Related: IT and network support in Ann Arbor, and IT compliance services, since backup isolation is on almost every compliance questionnaire.
