Backup & Disaster Recovery
Backup and disaster recovery implementation.
We don't resell it — we build it.
We assess what's backed up today, design recovery objectives with you, configure the platform you choose, and prove restores actually work with documented runbooks. Labor-only: no backup software, storage or appliance resale, and no margin in either direction.
Backup and disaster recovery implementation means proving your organization can get its data back, not just that a job runs green. That means assessing what's backed up today and where those copies actually live, designing recovery objectives with the business rather than assuming them, configuring the platform you choose, and testing restores until there's a documented runbook your own team can run.
Pro IT NW is labor-only. We implement and configure the systems we engineer — Veeam, Cohesity, Rubrik, Commvault, Datto, Acronis, Druva and Wasabi — and Microsoft 365 Backup as a Microsoft-native option for SharePoint, OneDrive and Exchange Online. We don't resell backup software, storage or appliances, and we take no margin on any of them.
Reviewed by the team at Pro IT NW — Seattle, delivered USA-wide.
Service detail
Assessed, designed, then configured — in that order
A restore test that has never run is not a backup, it's an assumption. The assessment and the recovery objectives decide what gets built; the platform configuration is what follows from them.
Assess and design
- ›What's backed up today, where the copies live, and whether that was a decision or an accident
- ›Whether restores have actually been tested, and when the last test happened
- ›What the business says it needs back, and how fast — recovery objectives set WITH you, not assumed for you
- ›Copy count, copy location and copy isolation — so one compromised credential can't reach every copy
- ›Identity and access design for the backup console itself: who can see it, who can change retention, who can delete
Implement and configure
- ›Configuration of the platform you choose — Veeam, Cohesity, Rubrik, Commvault, Datto, Acronis, Druva or Wasabi
- ›Microsoft 365 Backup setup for SharePoint, OneDrive and Exchange Online, where that's the right fit
- ›Retention and recovery-window policy set to match the objectives agreed in design, not left at a platform default
- ›Restore workflow build-out: same-location, alternate-location and granular item recovery, exercised before go-live
- ›Documented runbooks: what gets restored, how, by whom, and how the result is verified
- ›Restore testing on a repeating schedule, with the result written down each time
Why backup projects go sideways
- ›A backup job runs green for months and nobody has ever restored from it
- ›Every copy lives in one place, reachable by the same credentials as the primary data
- ›The backup console shares admin credentials with everything else in the tenant — a single compromise reaches both
- ›Recovery objectives were never written down, so 'fast enough' is a different number for everyone in the room
- ›Retention was set once at the platform default and never revisited against what the business actually needs back
- ›Restore testing happens for the first time during a real incident
Microsoft-native option
Microsoft 365 Backup
Microsoft 365 Backup is a Microsoft-native product for SharePoint sites, OneDrive accounts and Exchange mailboxes, separate from the retention and versioning already built into Microsoft 365. Per Microsoft's own documentation, the recovery window is configurable per backup policy — 3 months, 6 months, 1 year or 2 years, with existing policies defaulting to 1 year — and recovery points run as frequently as every 10 minutes, with additional weekly snapshots for SharePoint and OneDrive extending coverage further back. Backup storage uses an append-only model Microsoft describes as immutable except for deletion, restores are billed at no additional charge, and protected data is billed at $0.15 per GB per month. It's one option among several for Microsoft 365 data — we implement it where it fits, and we're equally willing to say it doesn't and configure a third-party platform instead. We take no margin either way.
Restore testing
Restore testing and documented runbooks
CIS Critical Security Control 11 (Data Recovery), Safeguard 11.5, sets the standard: "Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets." Regulated organizations often carry a related requirement, with no set testing interval — for HIPAA covered entities and business associates, 45 CFR 164.308(a)(7)(ii) requires a Data backup plan (Required), a Disaster recovery plan (Required) with "procedures to restore any loss of data," an Emergency mode operation plan (Required), and Testing and revision procedures (Addressable) for the contingency plan itself.
We build the restore test into the implementation rather than leaving it as a future task: what gets restored, to where, how the result is verified against a known-good state, and how often the test repeats — written down as a runbook your own admins can run without us on the call. We help implement and test the controls these standards describe; we don't certify compliance, and this page is not a claim that any configuration makes you HIPAA compliant.
Access
Protecting the backup system itself
A backup console is a management plane with broad reach by design — it can typically touch every system it protects. The same reasoning that makes RMM tooling worth treating as Tier 0 infrastructure applies to a backup console: if it shares credentials with the rest of the tenant, or if the same account that runs backups can also delete them, a single compromise can reach both the primary data and the copies meant to recover it. Identity and access design for the console — who can see it, who can change retention, who can delete a backup — is part of the implementation, not an afterthought scoped in later.
Procurement
We don't resell backup software or storage
We don't resell hardware or software. When a project needs procurement, we recommend the right products for your environment, work with the vendor of your choice on quoting, and handle install, configuration, and integration. No margin in either direction.
FAQ
Common questions about backup and disaster recovery implementation.
Do you sell backup licenses or storage?
No. Pro IT NW is labor-only — we don't resell hardware or software, and that includes backup platforms, cloud storage capacity and backup appliances. When a project needs procurement, we recommend the right products for your environment, work with the vendor of your choice on quoting, and handle install, configuration and integration. No margin in either direction, so nothing about our recommendation depends on which product or how much storage you buy.
Which backup product do you recommend?
It depends on your environment, not on a standing recommendation. We implement and configure the systems we engineer — Veeam, Cohesity, Rubrik, Commvault, Datto, Acronis, Druva and Wasabi among them — plus Microsoft 365 Backup as a Microsoft-native option for SharePoint, OneDrive and Exchange Online. We're vendor-neutral and take no margin on any of them, so we won't tell you one is universally best; what we will do is scope your data footprint, recovery objectives and budget and tell you which platform fits, and why, before anything is purchased.
Do you run our backups day to day?
Not as a default. This page describes implementation: assessing what's backed up today, designing recovery objectives and copy strategy with you, configuring the platform, and proving restores work with documented runbooks. Ongoing day-to-day operation — monitoring jobs, triaging failures, rotating credentials on the console — is a separate conversation we can have under /services/managed-it-support/, which is itself offered selectively, post-go-live, to clients whose environment we already know. We won't promise monitoring hours or response times here; that's a scoped discussion once the platform is in and tested.
What is Microsoft 365 Backup, and how is it different from what Microsoft 365 already does?
Microsoft 365 Backup is a Microsoft-native product — separate from the retention and versioning built into SharePoint, OneDrive and Exchange — that backs up all or selected SharePoint sites, OneDrive accounts and Exchange mailboxes, with recovery points and a rollback or granular-item restore workflow. Per Microsoft's own documentation, the recovery window is configurable per backup policy at 3 months, 6 months, 1 year or 2 years (existing policies default to 1 year), backup storage uses an append-only model that Microsoft describes as immutable except for deletion, and billing is $0.15 per GB per month for protected data with restores themselves free. It's one option among several for Microsoft 365 data — we'll tell you honestly whether it fits your recovery objectives compared to a third-party SaaS backup platform, since we take no margin either way.
How do you know a backup will actually restore?
By testing it, not by trusting the job-succeeded checkmark in the console. CIS Critical Security Control 11 (Data Recovery), Safeguard 11.5, states the standard plainly: "Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets." As part of implementation we build the restore test into a documented runbook — what gets restored, where, how the result is verified against a known-good state, and how often the test repeats — so your organization has a working answer to "does this actually come back" before an incident forces you to find out.
Does HIPAA require us to have backups and a disaster recovery plan?
Yes, if you're a HIPAA covered entity or business associate. 45 CFR 164.308(a)(7) requires a Contingency plan standard with several implementation specifications: a Data backup plan (Required) to "create and maintain retrievable exact copies of electronic protected health information," a Disaster recovery plan (Required) with "procedures to restore any loss of data," an Emergency mode operation plan (Required), and Testing and revision procedures (Addressable) for periodic testing and revision of contingency plans. We help implement and test the controls that requirement describes — backup, recovery procedures, and documented restore tests — but we are not a HIPAA compliance authority and this page is not a claim that any specific configuration makes you compliant. That determination is yours, informed by your own counsel or compliance advisor.
Which backup and disaster recovery platforms do you implement?
Veeam, Cohesity, Rubrik, Commvault, Datto, Acronis, Druva and Wasabi, plus Microsoft 365 Backup as a Microsoft-native option for SharePoint, OneDrive and Exchange Online. We implement and configure these systems; we don't resell licensing or storage capacity for any of them, and we're not naming a preferred vendor here — which platform fits depends on your data footprint, recovery objectives and existing Microsoft investment.
Related
Related work
- → Managed IT support — where ongoing operation of a backup platform is discussed, once the project that established it is done.
- → Your provider's RMM is Tier 0 — the same access-design reasoning applied to remote management tooling.
- → Why we carry no partner badges — what we are enrolled in, what we are not, and why labor-only changes the advice you get.
Related reading
What's backed up today, and has it been restored?
Tell us what you're protecting now, where the copies live, and what the business says it needs back. We'll come back with scope and a fixed-fee range.