Backup & Disaster Recovery
Part of Technology Stabilization & Standardization, alongside Managed IT Services, Cloud IT Services, Microsoft 365 Management, and Co-Managed IT.
TTS Cyber backs up servers, workstations, laptops, Microsoft 365, other cloud apps and network device settings, and does the restore when something breaks. Below is how a backup differs from disaster recovery, what Exchange Online mail and SharePoint keep by default, and what to ask any provider.
What does TTS Cyber back up, and who does the restore?
TTS Cyber backs up servers, workstations and laptops, Microsoft 365 (mail, OneDrive, SharePoint and Teams), other cloud apps such as Google Workspace and Salesforce, and network device settings. Backups are encrypted, and a copy is kept off site or in the cloud. Backups are kept about 30 days on average, and can be kept longer on request.
When something breaks, TTS Cyber does the restore. Test restores run on a monthly schedule. In a test restore, backed-up data is restored to check that it works. TTS Cyber also writes and keeps a disaster recovery plan for you and runs a recovery drill with you. A drill is a practice run.
You can buy this service on its own or together with managed IT.
What is the difference between a backup and disaster recovery?
NIST (the National Institute of Standards and Technology) defines a backup as a copy of files and programs made to help recovery. It defines a disaster recovery plan as a written plan for recovering information systems at an alternate facility, meaning another site. The plan applies after a major hardware or software failure or the destruction of facilities. So the backup is the copy, and the plan is a separate document. NIST writes for federal information systems, but these terms are widely used outside government.
CISA (the Cybersecurity and Infrastructure Security Agency) gives small businesses voluntary guidance to write down the steps staff would use to recover systems from backups. It says recovery without backups can take weeks or months and may be impossible.
NIST also defines two recovery targets. The recovery time objective (RTO) is the longest a system can stay unavailable before the impact becomes unacceptable. The recovery point objective (RPO) is the point in time before an outage that data can be recovered to, given the most recent backup.
Is Microsoft 365 already backed up?
Microsoft’s pages give set windows for getting deleted items back, and its shared responsibility page says you own your data and are responsible for protecting it. That page is illustrative guidance. It does not change any agreement with Microsoft and does not state a Microsoft 365 backup policy.
The defaults for mail and SharePoint:
- In Exchange Online (mail), most items removed from Deleted Items stay in the Recoverable Items folder for 14 days by default. An admin can raise that to at most 30 days. Microsoft calls this folder deletion protection, not a backup.
- In SharePoint, deleted items stay in the recycle bin for 93 days by default.
Microsoft also sells a backup product for SharePoint sites, OneDrive accounts and Exchange mailboxes, with a recovery window of 3 months, 6 months, 1 year or 2 years. For SharePoint and OneDrive, Microsoft says its own resiliency copies, which it keeps so the service stays available, are described separately from recovery you control.
TTS Cyber backs up Microsoft 365.
Can ransomware delete your backups?
Many ransomware variants try to. The joint #StopRansomware Guide, from CISA, the FBI, the NSA and MS-ISAC (the Multi-State Information Sharing and Analysis Center), says they look for backups they can reach and delete or encrypt them, so restoring becomes impossible unless a ransom is paid.
The guide advises keeping offline, encrypted backups of critical data. It is voluntary guidance.
Ask any provider, including TTS Cyber, whether any copy is offline or out of reach of your network.
How can you tell a backup will restore?
The direct check is a test restore. NIST and CISA both say to test backups.
CISA’s voluntary small-business guidance says to test so you can restore data both fully and partially and can restore data as it was at least seven days ago. NIST’s backup safeguard says to test that backup information is reliable and intact, and to restore selected system functions from a sample to see whether they work as intended. NIST writes that safeguard for federal information systems, and it is a voluntary reference for other organizations.
The service includes test restores on a monthly schedule. Whatever provider you use, ask what each test restore covers.
What’s included
- Backup of servers, workstations and laptops
- Microsoft 365 backup: mail, OneDrive, SharePoint and Teams
- Backup of other cloud apps, such as Google Workspace and Salesforce
- Backup of network device settings
- Encrypted backups with a copy kept off site or in the cloud
- Backups kept about 30 days on average, and longer on request
- Test restores on a monthly schedule
- A written disaster recovery plan, kept by TTS Cyber
- A recovery drill with you
- Restores done by TTS Cyber when something breaks
What it’s for
- Test restores on a monthly schedule check that backed-up data can be restored.
- The disaster recovery plan is written and kept for you.
- You can buy backup and recovery without also buying managed IT.
Frequently Asked Questions
How long does TTS Cyber keep backups?
TTS Cyber keeps backups about 30 days on average, and can keep them longer on request. Because 30 days is an average, ask TTS Cyber how long your own backups would be kept. If you may need copies from further back, tell TTS Cyber early.
Does HIPAA apply to my organization’s backups?
The Health Insurance Portability and Accountability Act (HIPAA) Security Rule applies only to certain organizations, so ask an advisor whether it reaches you. Where it applies, it requires a contingency plan for emergencies that damage systems holding electronic protected health information. The contingency plan has three required parts: a data backup plan, a disaster recovery plan and an emergency mode operation plan. The rule sets no restore time. TTS Cyber is not a law firm, and this is general information, not legal advice.
What will my cyber insurance application ask about backups?
It depends on the insurer. One insurer’s ransomware application asks how often critical information is backed up, where copies are held, such as off site or offline, and whether backups have protections such as encryption. It also asks how often a full recovery is tested and whether the recovery time objective for critical systems was validated in the last 12 months. Other insurers ask different questions.
Is the 3-2-1 backup rule enough?
Not by itself. CISA’s small-business guidance names the rule: 3 copies of important files, on 2 different types of storage media, with 1 copy stored off site, away from your business location. That covers copies, media and location only. The same page adds physical security, encryption and offline copies. It is voluntary guidance.
Can I buy Backup & Disaster Recovery without managed IT?
Yes. TTS Cyber offers Backup & Disaster Recovery on its own or together with managed IT. The first section above describes what TTS Cyber backs up and who does the restore. If you already have an IT provider, you can compare what you get today with that description.
Related services
Managed IT Services
TTS Cyber runs your everyday IT: monitoring, a helpdesk for your staff, and setting up and shutting off accounts as people join and leave. It is built around how your business works.
Cloud IT Services
Keep your important data safe and reach it from anywhere, with email server management and security built in. The goal is cloud computing that lowers your costs and upkeep.
Microsoft 365 Management
TTS Cyber manages Microsoft 365 users, licenses, laptops and phones, sets up sign-in and email protection, and handles backup. Offered only with managed IT.
Further reading
From our blog
Industries