Symptom
Last successful full restore test cannot be dated
- Root cause
- Restore testing is not scheduled or tracked as an operational task
- Business risk
- Recovery assumptions are unverified until the real incident
Managed IT · Backup & Disaster Recovery
Managed backup and disaster recovery is the operation of data protection and recovery infrastructure to defined Recovery Point and Recovery Time Objectives, including immutable copies and regular restore testing. Evolvice designs, operates and tests recovery capability so a ransomware event or outage becomes a controlled procedure rather than a crisis.
Overview
Most enterprises can point to a backup schedule but cannot state, with evidence, how long a full restore actually takes or whether the backups themselves are safe from the same attack that took production down. Backup jobs completing successfully is not the same as recovery being possible. We operate backup and DR as a tested capability, not a checkbox.
Diagnostic
Patterns we repeatedly find when auditing an existing backup and DR setup.
Symptom
Symptom
Symptom
Symptom
Resilience
Backup software reporting "job successful" only confirms that data was written somewhere. It does not confirm that the data is complete, uncorrupted, isolated from the production attack surface, or restorable within a time the business can survive.
Our DR practice is built around measured RPO and RTO per system tier, immutable copies, and scheduled restore exercises with recorded evidence.
Definition
RPO is the maximum acceptable amount of data loss measured in time before an incident, and RTO is the maximum acceptable duration to restore a system to operation after an incident, both defined per system based on business impact.
Delivery model
A repeatable five-step engagement we run for every environment we take over.
Inventory of systems and data stores, tiered by business criticality, with RPO/RTO targets agreed per tier with system owners.
Deployment of air-gapped or immutable backup copies isolated from production identity, following a 3-2-1-1 pattern where warranted.
Scheduled, evidenced restore tests per tier — file-level, application-level and full-environment — with results logged against RTO targets.
Documented, role-assigned failover procedures rehearsed on a fixed cadence, including communication and decision-authority steps.
Quarterly review of RPO/RTO adequacy as systems and data volumes change, with backup architecture adjusted before capacity or coverage gaps appear.
Compliance
How our delivery model maps to the four reference frameworks German enterprises are audited against.
| Control | ISO 27001 | NIS2 | BSI-Grundschutz | GDPR |
|---|---|---|---|---|
| Backup & Data Recovery | A.8.13 | Art. 21(2)(c) | CON.3 | Art. 32(1)(c) |
| Business Continuity Management | A.5.29 / A.5.30 | Art. 21(2)(c) | DER.4 | Art. 32(1)(b) |
| Ransomware / Malware Resilience | A.8.7 | Art. 21(2)(e) | OPS.1.1.5 | Art. 32(1)(b) |
| Incident Handling & Recovery Reporting | A.5.24 | Art. 23 | DER.2.1 | Art. 33 |
| Testing & Exercise of Continuity Plans | A.5.30 | Art. 21(2)(c) | DER.4.A9 | Art. 32(1)(d) |
Questions & Answers
Definitions, delivery detail and commercial answers in one place — written to be quotable by search and AI answer engines, and readable by your team.
Backup is the process of copying data so it can be restored after loss or corruption. Disaster recovery is the broader capability of restoring entire systems, applications and infrastructure to operation after a disruptive event, of which backup is one component.
In the cluster
Service desk, devices, endpoints and IT operations run to agreed SLAs for your whole workforce.
Part of our Managed IT & End-User Support practiceWe start with a 30-minute diagnostic of your current delivery — at no cost and with no sales pitch. You leave with a written summary of findings either way.