Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Backup and disaster recovery

Cloud backup and disaster recovery for SMBs in Quebec

Hardware failure, human error, theft or ransomware: on the day of the incident, the only question that matters is whether you can restore. OKTO Solutions sets up, monitors and verifies the backup of your servers, your workstations and your Microsoft 365 data, then documents a business continuity plan with you and tests it.

A small business cloud backup follows the 3-2-1 rule: three copies of the data, on two kinds of media, with one of them off site and immutable. A disaster recovery plan says what gets restarted, in what order, and who decides. Without a real restore test, neither one counts for much.

Two separate things

Backup or disaster recovery: what is the difference?

People mix the two up constantly, and it costs them on the worst possible day. Backup creates copies of your data and keeps them safe. Disaster recovery describes who does what, in what order, to get the business running again. A company with excellent copies and no plan spends the first day arguing about what to restart while the phone rings. A company with a beautiful plan and unusable copies goes nowhere at all. This service covers both, because one without the other leaves half the problem untouched. It applies to any organization whose servers, files, accounting or email are needed to get through the day, and to any organization whose customer, insurer or prime contractor is asking for proof of continuity.

  • Backup protects the dataOff-site copies, encrypted in transit and at rest, immutable so ransomware can neither encrypt them nor wipe them.
  • The recovery plan protects the businessRestart order, owners, the phone numbers you will need, the calls somebody has to make. Written down, tested, and known to the people involved.
  • Monitoring holds it all upJobs are checked every day, and a failure becomes an intervention instead of a line in a log nobody reads.

The baseline

The 3-2-1 rule, explained plainly

Three copies, two kinds of media, one off site. It is old, it is well known, and it still covers the vast majority of loss scenarios: hardware failure, accidental deletion, theft, fire and ransomware.

3

Three copies of the data

The original plus two copies. Two copies on the same server do not count as two: if that server burns, you have zero. The idea is simple: never depend on a single place.

2

Two kinds of media

A local disk and cloud storage, for instance. Media do not fail the same way or at the same time. Putting all three copies on the same disk model is a bet on a single manufacturing defect.

1

One copy off site

Outside the building, off the network, and, with us, always immutable. This is the copy that survives fire, theft and above all ransomware, because nothing can change it before its retention ends.

The part the rule leaves out, and the part we add every time: the off-site copy has to be immutable. Modern ransomware hunts for the backups before it encrypts anything else, and it uses your own administrator accounts to erase them. A copy that no account can delete before its retention period ends is what leaves you a way out without paying a ransom.

The real test

Why a backup that was never tested does not count

A backup nobody has ever restored is not a backup, it is an intention. We regularly find jobs that have been green for two years while protecting a drive that no longer exists, virtual machine backups taken while the database was open, retention set to seven days by a provider who left long ago, and full sets that cannot be rebuilt because an encryption key is missing and nobody wrote it down. None of that shows up in a success report. It shows up the day somebody tries to restore, and that day it is late. This is also where quiet backups die: the failure notice lands in a mailbox nobody watches, and six months go by.

The first thing we ask a new client. Has a restore ever been done for real, and when. The answer tells us more about the true state of the protection than any dashboard screenshot.

RPO and RTO are set system by system. The file server, the accounting system and the mailboxes do not carry the same value for the business, and bringing them back does not carry the same urgency. The discussion happens with management before the copy frequency and the type of restore are chosen, because every hour of tolerance removed has a cost.

RPO and RTO

How much can you lose, and how long can you stay down?

Two acronyms, two very concrete questions, and the only decisions on this page that do not belong to the technicians. RPO is the data loss you accept: if the last copy was taken overnight, you lose the day’s work. RTO is how long you accept being down before your team can work again. Both objectives come from your business reality, not from a provider’s template. A manufacturer who bills by production and a professional office that enters its billable time on Friday do not give the same answers. We set them system by system, then design the backup strategy that meets them.

  • RPO, the loss you can live withHow much work you accept redoing. Set by how often the copies are taken.
  • RTO, the downtime you can live withHow long the business can limp along. Set by the type of restore and by the plan.
PlanMaximum data loss (RPO)Target time to restore service (RTO)
Base24 hours1 business day
Standard24 hours8 business hours
Complet4 hours on critical systems4 hours

These are target objectives, spelled out in the contract and then adjusted with you system by system. They are not a guarantee, except in the Complet plan, where they are contractual. The three levels are laid out on our managed IT plans page.

The scope

What exactly gets backed up?

Servers, workstations and Microsoft 365 do not carry the same value or the same urgency. We establish with you what has to be protected, how often and for how long, then apply the 3-2-1 rule across the whole thing.

Physical and virtual servers

Automated backup of the full image, not just the files. That is what lets a server be rebuilt whole instead of reinstalled in the middle of an emergency.

Workstations and laptops

Not every document lives on the server. A stolen laptop or a dead drive should not take three months of work with it.

Microsoft 365

Exchange, SharePoint, OneDrive and Teams backed up separately by a third party, with a retention period you choose and item-level restore.

The costliest misunderstanding: sync is not backup

Plenty of small companies believe they are protected because their files sit in OneDrive or in a synchronized share. Synchronization faithfully reproduces whatever happens to your files, including their encryption by ransomware and their deletion by mistake. The bad state spreads to every copy, often within minutes. That is a mirror, not a backup. A backup keeps earlier versions, out of reach of whatever is happening on the workstation, and lets you go back to yesterday morning instead of to the moment of the damage.

Same logic for Microsoft 365: the platform guarantees its own availability, not the preservation of your data. See also our Microsoft 365 support, which covers hardening of shares and mail rules.

  • Off-site copies, encrypted in transit and at rest
  • Immutable copies that ransomware can neither encrypt nor erase
  • Daily monitoring of the jobs, with a failure picked up as an alert
  • Verified backup with a restore test twice a year from the Standard plan on
  • Retention and versioning configured to match your obligations
  • Restore of files, mailboxes, servers or complete workstations
  • A documented disaster recovery plan that gets revised
  • Support during a real incident, from the first decision to service restored
  • Monthly report on the state of the backups

How it runs

How does a restore test work?

Twice a year, we restore for real. Not one small file picked because it is small: a full set, the one the business would depend on at nine o’clock on a bad Tuesday. The test takes a few hours, it never touches your production environment, and it produces a written result that you keep.

  1. We pick a realistic scenarioThe file server, the accounting database, a complete mailbox. The scenario changes from one test to the next so the same thing is not always the thing being proven.
  1. We restore into an isolated environmentNo risk to production, and no chance of bringing a still-infected system back online. It is the same precaution used on the day of a real incident.
  2. We check that it really opensThe application starts, the database mounts, the mailbox opens, the files are not corrupted. A restore that finishes without an error is not a successful restore until somebody has opened the contents.
  3. We put a stopwatch on itThe real time is compared against the target RTO. A gap becomes something to fix, not a footnote.
  4. We update the recovery planWhatever the test surfaced goes into the plan: restart order, a forgotten dependency, a missing key, a contact to change. The plan is also revised whenever your environment changes in a meaningful way.

Comparison

Managed backup, do-it-yourself backup, or plain synchronization

Three ways a small business protects its data. Two of them let the ransomware scenario walk right through.

CriterionBackup managed by OKTODo-it-yourself backupCloud synchronization
Off-site copyAlways, and encryptedDepends on how disciplined one person isYes, but it is a mirror, not a backup
Immutable copyIncluded, ransomware cannot erase itRarely in placeNo, an encrypted file syncs as encrypted
Failure monitoringChecked daily, alert and ticketAn email nobody readsNo concept of a backup failure
Restore testVerified, tested twice a year from the Standard plan onAlmost never doneCannot be tested as a complete set
Microsoft 365Third-party backup of Exchange, SharePoint, OneDrive and TeamsOften forgottenRecycle bin and retention limited in time
Recovery planDocumented, tested and revisedIn somebody’s headDoes not exist
Accidental deletionRestore by version and by dateDepends on the retention that was configuredThe deletion spreads to every copy
Proof for an insurerMonthly report and dated documentationAssembled by handNone

A backup nobody has ever restored is not a backup, it is an intention.

Antonio Pazzi, founder of OKTO Solutions

Data protection does not hold itself up. It assumes workstations kept current by our managed IT services, managed cybersecurity that stops ransomware before it reaches the copies, and infrastructure designed with recovery in mind, which is what our cloud and Azure service covers. Retention and destruction of data also touch your obligations: see our page on Law 25 compliance for SMBs. Our office is in Trois-Rivières and the service is available across Quebec, including companies in the Mauricie and in Boucherville and the South Shore.

Questions and answers

Common questions about backup and recovery

How often are backups taken?
Backups run daily in all three plans. In the Complet plan, critical systems are backed up several times a day. From the Standard plan on, a restore test is performed twice a year. The exact frequency for each data set then comes from what your business can absorb as a loss: a production database and an archive folder do not have the same needs.
Do you actually test the backups?
Yes. A backup that will not restore is worth nothing. The Standard plan includes verified backup with a restore test twice a year, and the result of that test is used to update the recovery plan. Jobs are also checked every day, and a failure opens a ticket instead of staying a line in a log.
Is Microsoft 365 not already backed up by Microsoft?
No, not in the sense of a business backup. Microsoft guarantees the availability of its platform and offers a recycle bin with retention that is limited in time. Keeping your data and being able to restore it stays your responsibility. That is why Exchange, SharePoint, OneDrive and Teams are backed up separately, with a retention period you choose.
What is the 3-2-1 rule?
Three copies of your data, on two different kinds of media, with one of them kept off site. It has been the accepted baseline for a long time, and it covers the vast majority of loss scenarios: hardware failure, accidental deletion, theft, fire and ransomware. We add immutability on the off-site copy, because ransomware goes after the backups first.
What is the difference between a backup and a recovery plan?
The backup protects the data. The recovery plan protects the business. It states which systems restart first, who decides, who executes, who tells the customers and the employees, and roughly how long each step should take. Having one without the other leaves half the problem untouched.
What is an immutable backup?
A copy that no software, no administrator account and no attacker can alter or delete before its retention period ends. That is what separates a business backup from a folder copied somewhere else. Ransomware tries to destroy the backups first: an immutable copy is what is still standing afterwards.
How long does a restore take?
It depends on what is being restored. From what we see, a file or a mailbox comes back within a few hours, and a full server inside one business day. Those are orders of magnitude, not a commitment: the volume of data, the type of restore and your internet link all move the number. We estimate these times with you when the objectives are set, then compare them against the result of the test.

Have your current backups checked

We look at what is backed up today, what is not, and whether a restore has ever been tested. You leave with the list of blind spots, no strings attached.