top of page

Managed Backup and Disaster Recovery: What It Is and What to Ask

Nav
2 days ago
4 min read

Managed backup and disaster recovery (BDR) is a service where a provider backs up your servers, PCs, and cloud data like Microsoft 365, monitors every backup job, keeps copies offsite and out of ransomware's reach, tests restores on a schedule, and gets you running again after an outage, attack, or hardware failure. Backup is the copy. Disaster recovery is the plan and the speed to use it.


managed backup and disaster recovery

Everybody has backups. Very few people have restores. The difference shows up at the worst possible moment, usually when someone opens the backup console for the first time in a year and discovers the last successful job ran in March.


TL;DR: Managed BDR means someone else watches your backups, keeps an offline copy ransomware can't touch, and tests that restores actually work. Back up Microsoft 365 or Google Workspace too, because the cloud provider's job isn't your data recovery. Keep the backups in your name.


Technician managing servers as part of managed backup services

What Managed Backup and Disaster Recovery Includes


  • Image-level backups of servers and key PCs, so a whole machine can be rebuilt, not just its files

  • File-level backups for quick "I deleted the wrong folder" restores

  • Cloud app backups for Microsoft 365 or Google Workspace email, OneDrive, SharePoint, and Teams

  • Offsite and immutable copies that can't be changed or deleted by an attacker

  • Daily monitoring of every job, with someone fixing failures

  • Restore testing on a schedule, with written results

  • A disaster recovery plan that says what gets restored first, by whom, and how fast


Done well, it's part of server administration and 24/7 network operations center monitoring, not a separate thing someone remembers once a quarter.


Cyber attack sign showing why offline backups matter for disaster recovery

Ransomware Goes After Your Backups First


Modern ransomware doesn't just encrypt your files. It looks for your backups and deletes them, so you have no choice but to pay.


CISA's #StopRansomware Guide is direct about it: "Maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups in a disaster recovery scenario." It explains why: "many ransomware variants attempt to find and subsequently delete or encrypt accessible backups to make restoration impossible unless the ransom is paid."


CISA also recommends keeping "golden images" of critical systems, which are preconfigured templates that let you rebuild a server quickly. That's the difference between recovering in hours and recovering in weeks.


I learned how much speed matters on a 3am call: a virus was spreading across a client's network and the job was to contain it before the first person logged in. Containment is step one. Clean, tested backups are what let everyone actually get back to work.


Code on a screen representing Microsoft 365 cloud data that needs its own managed backup

Your Microsoft 365 Data Needs a Backup Too


This one surprises people. Microsoft keeps its services running. Getting your specific data back after a mistake, a malicious deletion, or a compromised account is a different job.


Microsoft's own Services Agreement puts it this way: "We recommend that you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services." That line is from Microsoft's consumer terms, but the principle holds for business tenants too: recycle bins and retention windows are not a backup strategy.


A third-party Microsoft 365 backup covers mailboxes, OneDrive, SharePoint, and Teams, with restore points you control.


Keys and a USB drive representing owning your own backups

Your Backups Should Be in Your Name


Here's my one strong opinion. No provider should ever hold your data hostage.


Your backup accounts, encryption keys, and storage should be registered to your company, with your own administrator access. If you leave your IT provider, your backups should leave with you, not disappear on the last day of the contract. Ask any provider, including us: "If we cancel, do we keep our backups?" If the answer takes more than five seconds, that's your answer.


Small cloud-based business deciding on disaster recovery solutions

When You Don't Need Us for This


  • You're fully in the cloud with a handful of users. Buy a reputable Microsoft 365 or Google Workspace backup tool, turn on MFA, and check the backup report monthly.

  • You have an IT person who already tests restores quarterly. Keep them. Maybe add an immutable offsite copy.


Where managed backup and disaster recovery pays off: on-site servers, line-of-business databases, compliance requirements, or any business where a week of downtime would hurt.


Business owner thinking through common backup and disaster recovery questions

Straight Answers About Backup and Disaster Recovery


What is managed backup?


Managed backup is a service where a provider runs, monitors, and fixes your backups for you, including cloud and offsite copies, and tests that data can be restored.


Are backup and disaster recovery the same thing?


No. Backup is a copy of your data. Disaster recovery is the plan, tools, and process for getting systems running again using those copies.


What is the 3-2-1 backup rule?


Keep three copies of your data, on two different types of storage, with one copy offsite. Many providers now add an immutable or offline copy for ransomware protection.


How often should backups be tested?


At least quarterly for full restores of critical systems, with automated checks on every backup job daily.


Does Microsoft 365 back up my data?


Microsoft keeps its service available and offers retention features, but it recommends customers back up their own content. A third-party backup gives you restore points you control.


Business owner calling NSOCIT about managed backup and disaster recovery

Still Stuck? Give Us a Call


If you're not sure when your last backup actually worked, give us a call at 410-703-3857 or send us a note. We protect businesses across the DMV, including Annapolis, with managed IT services on one flat monthly rate.


We'll test your restore before you need it. It's much less exciting that way, which is exactly the point.


Comments


bottom of page