Backup Is a Business Decision
Define recovery objectives in business terms and evaluate whether a backup approach can actually restore operations.
Presenting to others?
View this module as full-screen slides for meetings, classes, or group presentations.
Module 4 of 7
0 of 7 complete0%
Having backups is not the same as recovering
A backup is a copy. Recovery is the tested ability to return to normal.
Backup creates the copy. Recovery proves the organization can use that copy to resume operations within a timeframe it can absorb.
Plenty of organizations have backups and not a tested recovery plan — and most discover the difference during the incident itself, the worst possible time to find out.
02
Where recovery commonly fails
Backups may exist, but that doesn’t always mean you can recover when it matters most.
Backups not completing
The job stopped running weeks ago, and no one was alerted.
Scope gaps
Critical systems or data were never included in the backup set.
Reachable by the same incident
Backups on the same network can be encrypted or destroyed alongside everything else.
Never tested
Restore procedures were never practiced, so recovery takes far longer than expected.
Learn more: the verification gap and reachable backupsLearn more
An unverified backup is a hypothesis — a backup that cannot be restored provides confidence without protection, the most dangerous combination. Attackers typically locate and corrupt or encrypt backup copies before triggering visible disruption (as Module 2 shows in the attack sequence), which is why isolation and integrity verification matter as much as the backup itself.
03
The two numbers that define your exposure
Recovery objectives in plain language
The question
Recovery Time Objective (RTO)
How long can we be down?
Recovery Point Objective (RPO)
How much recent work can we afford to lose?
Measured in
Recovery Time Objective (RTO)
Hours or days of outage.
Recovery Point Objective (RPO)
Hours or days of data.
Driven by
Recovery Time Objective (RTO)
Speed of the restore method and who performs it.
Recovery Point Objective (RPO)
How frequently backups run.
If it is wrong
Recovery Time Objective (RTO)
The business stops longer than it can sustain.
Recovery Point Objective (RPO)
Work is permanently lost and must be recreated.
Answer both honestly and the technical requirements follow. An organization that can tolerate two days of downtime needs a materially different approach than one that cannot lose a morning.
Technical reference: how the numbers become requirementsTechnical reference
- RPO drives backup frequency
- A four-hour RPO means backups must run at least every four hours; a 24-hour RPO allows nightly backups. The tighter the number, the more frequent (and more resource-intensive) the schedule.
- RTO drives restore method
- A short RTO usually requires image-level or standby recovery rather than file-by-file restore, plus a documented runbook so the process does not depend on one person.
- 3-2-1 as a baseline
- Three copies of data, on two types of media, with one kept off-site or isolated — a common baseline that keeps a single event from destroying every copy.
Test before you need it
Recovery readiness
The worst time to find out a backup does not work is during the incident.
A basic recovery test
Confirm jobs are completing
Verify backup jobs ran successfully and review any failure alerts.
Restore a representative item
Recover a file or supported system from the most recent backup.
Confirm the result is usable
Open, access, and verify that the restored item is complete and intact.
Document and assign next actions
Record what was tested, note any gaps, and confirm who is responsible for follow-up.
05
Not all restores are equal
“Can you restore a file?” and “can you restore the business?” are different questions.
- 01
File and folder recovery
Restores individual files and folders — the most common day-to-day need.
- 02
Image-level recovery
Restores an entire system including OS, applications, and settings — not just files.
- 03
Documented recovery readiness
A written runbook plus validation that the full restore process actually works.
06
How BackupGuard deepens by tier
BackupGuard protects approved data on covered systems. All tiers include off-site cloud storage, routine remote file restores, and eligible Windows Server image backup. DEFENSE adds workstation images and quarterly eligible server restore testing; GUARDIAN adds recovery documentation. Customer-site storage is a separately priced add-on.
| Capability | BackupGuard COREFile and folder backup plus Windows Server images | BackupGuard DEFENSEWorkstation images and quarterly server testing | BackupGuard GUARDIANDocumented recovery planning and evidence |
|---|---|---|---|
| Automated, Encrypted Data BackupOne scheduled backup daily for approved sources, with encrypted off-site cloud storage. | Included | Included | Included |
| Self-Service Restore Options | Not included | Included | Included |
| Windows Server Image BackupIncluded in every eligible server tier; a full rebuild requires a separately approved scope unless expressly included. | Included | Included | Included |
| Priority Recovery Coordination | Technician-Assisted Recovery | Priority coordination | Priority coordination |
| Written Implementation & Recovery Runbook | Not included | Not included | Included |
BackupGuard CORE
File and folder backup plus Windows Server images
- Automated, Encrypted Data BackupIncluded
- Self-Service Restore OptionsNot included
- Windows Server Image BackupIncluded
- Priority Recovery CoordinationTechnician-Assisted Recovery
- Written Implementation & Recovery RunbookNot included
Showing 5 key capabilities. Activate to compare additional capabilities.
Recovery depends on approved backup scope, successful recovery points, system condition, and the selected tier. Full rebuilds and major application recovery require separate scope and pricing unless expressly included.
What to remember
Four ideas worth carrying forward
- A backup is a copy; recovery is the tested ability to resume operations in an acceptable timeframe.
- RTO answers how long you can be down; RPO answers how much recent work you can lose.
- File-level, image-level, and documented recovery readiness are meaningfully different capabilities.
- Monitoring and integrity verification are what separate a real recovery plan from a false sense of security.
Terms used in this module
Select a term to read its definition without leaving this page.
Finished this module?
Mark it complete to save your progress, or continue without marking it complete.