ServicesBackup & Recovery
Backup & Recovery

Backups you can actually restore.

Three-tier backup architecture: local NAS for speed, off-site for resilience, immutable cloud copy for ransomware resistance. Quarterly restore tests confirm every backup works before you need it.

The three tiers

The 3-2-1 rule. Actually followed.

3 copies, 2 media types, 1 off-site. Most MSPs describe this. We implement it, monitor it, and prove it works quarterly.

Tier 1 — Local NAS backup

Daily incremental to on-premises storage. Sub-hour RPO for critical systems. Fast restore for the common case: accidental deletion, failed update, corrupted file.

Tier 2 — Off-site replication

Nightly encrypted replication to an off-site target geographically separate from your office — AWS S3 for new builds, or your existing off-site infrastructure if you have one. AES-256 at rest, TLS 1.2+ in transit, versioned, with credentials rotated on a schedule. 30-day retention minimum, configurable longer. Survives a full-site loss — fire, theft, flood, or hardware failure.

Tier 3 — Immutable cloud copy — regulated-data engagements

AWS S3 Object Lock in compliance mode on a separate bucket. Ransomware cannot encrypt or delete it — even with your credentials, even with ours. Write-once, read-many for the full retention window. Air-gapped from your on-prem environment by IAM policy and account boundary. Deployed for clients with cyber-insurance EDR-and-immutable-backup requirements, HIPAA exposure, or contractual data-protection obligations.

Quarterly restore testing

We perform actual restores from each backup tier every quarter and document the result. You see the results in your monthly report. No "it should work" — it either did or it didn't.

24/7 backup monitoring

Failed backup jobs alert immediately — not at month-end review. We know your backup broke before you do, and we fix it before you'd ever need it.

Microsoft 365 backup — available add-on

Veeam Backup for Microsoft 365 covers Exchange Online, SharePoint, OneDrive, and Teams independently of Microsoft's native retention. Recoverable after accidental deletion, retention-policy expiry, or account compromise. Per-seat pricing — added when you need it.

Documented RTO & RPO

Your recovery time objective and recovery point objective written into your runbook. You know exactly how long recovery takes and how much data is at risk before disaster strikes.

Ransomware recovery plan

Written playbook: who calls who, which systems come back first, how long until you're operational. Tested, not assumed.

Why it matters

An untested backup is a hope, not a plan.

60% of small businesses that lose their data close within 6 months. The failure almost never happens because backups weren't running — it happens because nobody checked whether they could restore from them.

Every quarter we do a real restore: pull the backup, mount it in a test environment, verify the data. You get a signed-off report. That's the difference between backup as a checkbox and backup as an actual safety net.

Get your backup audited
0

unrecoverable data loss events across all clients since Rainier IT was founded.

Technology
Proxmox Backup Server ZFS restic AWS S3 S3 Object Lock AWS KMS (SSE-KMS) Veeam Backup for M365 zstd compression
Frequently asked

Common questions about backup & recovery.

The questions to ask any backup vendor — including us — before a real outage forces them.

What does the 3-2-1 backup rule actually mean?

Three copies of your data, on two different media types, with one copy off-site. That's the rule. Most shops we audit have one copy (the production data), call the backup software's local snapshot the second copy (it's not — same disk, same room, same fire), and have nothing off-site. The architecture we deploy is: Tier 1 local NAS for fast recovery (sub-hour RPO) and Tier 2 nightly encrypted off-site replication on every engagement, plus Tier 3 immutable cloud copy with AWS S3 Object Lock in compliance mode for clients with regulated-data or cyber-insurance requirements.

Doesn't Microsoft 365 back itself up?

No — and Microsoft is explicit about this in the shared-responsibility model. M365 protects against infrastructure failure on their side. It does not protect against a user (or attacker) deleting mail, a SharePoint site getting wiped, OneDrive being encrypted by ransomware, or a former employee's data being permanently lost after their license is reclaimed. Those are your responsibility. We add Veeam Backup for Microsoft 365 (Exchange Online, SharePoint, OneDrive, Teams) as the standard add-on for any M365 client.

What is S3 Object Lock and why does it matter for ransomware?

S3 Object Lock in compliance mode is AWS's WORM (write-once, read-many) feature: once a backup object is written, it cannot be modified or deleted by anyone — including the AWS root account, including someone with our credentials — until the retention clock expires. That's the property ransomware operators have learned to defeat by stealing backup credentials and deleting the backups before they encrypt production. Object Lock makes that attack mechanically impossible. It's the standard we deploy as Tier 3 for any client whose cyber-insurance carrier or regulator asks about immutable backup.

How often do you test that the backups actually restore?

Quarterly, documented in your monthly health report. The test isn't "did the backup job complete" — every backup tool reports green when nothing useful was captured. The test is: pick a real file, a real database, or a real VM, restore it to an isolated environment, verify integrity, and time the restore. The architecture is built so that the moment of need is never the first time the chain runs end-to-end — it's tested every quarter, on schedule, with the results in your monthly report.

What are RTO and RPO and what should mine be?

RPO (Recovery Point Objective) is how much data you can afford to lose — the gap between the last backup and the failure. RTO (Recovery Time Objective) is how long you can afford to be down. For a typical small business, our targets are RPO under 1 hour for production data and RTO under 4 hours for a full environment restore. Mission-critical workloads can be tighter (RPO 15 min, RTO 1 hour) by adding warm replication. Both numbers are documented per-workload in your runbook so "how bad is this" has an answer the day of the incident.

If we get hit by ransomware, how fast can you have us back up?

For a normal small-business environment with the full 3-tier backup architecture deployed, a typical recovery target is: 1–2 hours to contain and isolate (Huntress automation does most of this), 2–4 hours to restore the immutable Tier-3 copy to clean infrastructure, and 4–8 hours to validate and bring users back online — so back inside one business day. The tail (forensics, insurance reporting, full root-cause writeup) takes longer. The key variable is whether the backup is actually clean and untouched — which is the entire reason we deploy an immutable Object Lock tier on any engagement where ransomware survival matters.

When did you last successfully restore from your backup?

If you're not sure, that's the answer. Free backup audit — we'll check what you have and tell you whether it would actually work.

Get the free audit