Davidson’s IT Agency | Business Continuity & Disaster Recovery
BCDR systems armed · RTO < 15 min · RPO < 5 min · 3-2-1-1-0 backup strategy
BCDR systems armed
Business Continuity & Disaster Recovery

When everything fails.
We don’t.

Data loss and prolonged downtime can end a business. We build automated, tested, and immutable recovery systems that bring you back online in minutes, not days.

Immutable backups Air-gapped vaults Automated failover Tested restore drills Ransomware-proof by design
Recovery Time Objective
< 15MIN
Time to get back online
Recovery Point Objective
< 5MIN
Maximum data loss tolerated

What is one hour of downtime worth to you?

Most businesses underestimate it. And most businesses find out the hard way. Move the sliders to see what it would cost you.

Every second you are offline, money walks out the door.

It is not just the technology that stops. Your team cannot work, orders do not process, customer requests go unanswered, and your reputation takes a hit that is difficult to repair.

This is exactly why BCDR is a necessary investment, not an optional one.

Employees affected 25
Avg. revenue / cost per employee / hour €85
Hours of downtime per incident 8
Estimated financial exposure Severe
€0
Low exposure Catastrophic

Three layers of protection.

Not software on a shelf. A resilient architecture designed around your specific operations.

Cloud & Local Backups

Never lose a file again. We automate your backups so your data is always double-secured, tested, and ready to restore.

Hover for detail
Implementation
  • 3-2-1 backup strategy
  • Hybrid local + cloud storage
  • AES-256 encryption at rest
  • Daily automated restore drills

Ransomware Defense

Modern attackers target your backups first. We build invisible, immutable vaults that ransomware cannot reach or encrypt.

Hover for detail
Implementation
  • WORM write-once-read-many storage
  • Air-gapped physical network
  • Immutable by design
  • Anomaly detection algorithms

High Availability Failover

If a server crashes, a standby system takes over instantly. Your team barely notices anything happened.

Hover for detail
Implementation
  • Active virtual machine replicas
  • Near zero RTO on failover
  • Automated DNS rerouting
  • Seamless hardware handover
Four recovery pillars

What actually keeps you online when everything else fails.

Not one piece of software, not one copy of your data, but four coordinated disciplines that survive fire, theft, ransomware and hardware death.

01 / MULTIPLE COPIES
LOCAL CLOUD + OFFSITE 3-2-1-1-0 · MULTIPLE COPIES
Redundant backups

Three copies, two mediums, one offsite. Losing one is survivable, losing all three at once is nearly impossible. Why it matters: a single backup is not a backup, it is a wish.

02 / UNREACHABLE
WORM · IMMUTABLE · RANSOMWARE-PROOF
Immutable vaults

Write-once storage and an air-gapped network path. Ransomware can encrypt your business, but not the vault it cannot see. Why it matters: modern ransomware hunts backups first, before it locks you.

03 / INSTANT TAKEOVER
PRIMARY STANDBY AUTOMATED FAILOVER · RTO < 15 MIN
High availability

Live replicas and automated DNS rerouting. If the primary dies, the standby takes over before your team even notices. Why it matters: every minute of downtime now costs more than a year of infrastructure.

04 / PROVEN, NOT PROMISED
RESTORE DRILL CALENDAR QUARTERLY FULL RESTORE · DOCUMENTED
Continuous testing

Quarterly full restore drills against real data, documented per location and per system. Every drill signed off, every gap closed. Why it matters: an untested backup is not a recovery plan, it is a hope.

Recovery layers

Data, System and Site, three layers, one recovery.

A resilient BCDR program is not one control. It is three coordinated layers, each designed to survive the failure of the one below it.

Data layer

Data layer

The base. Backups, encryption, immutability and offsite replication. Every other layer depends on this one being honest and tested.

  • 3-2-1-1-0 backup policy
  • AES-256 at rest, TLS in transit
  • WORM immutable vaults
  • Air-gapped offline copy
  • Daily automated restore validation
System layer

System layer

The muscle. Live replicas, automated failover and rerouting so that services survive the loss of the physical machine they once ran on.

  • Active VM replicas, near-zero RPO
  • Automated DNS takeover
  • Cloud or on-prem standby hosts
  • Health checks every 30 seconds
  • Documented response runbooks
Site layer

Site layer

The insurance policy. A secondary site, or a cloud region, capable of running your business if your primary location becomes unreachable.

  • Secondary office or cloud region
  • Replicated identity and access
  • Spare hardware staged and tested
  • Network path diversity per site
  • Annual site failover rehearsal
If a layer falls Site goes dark · data survives Server dies · replica takes over Backup is attacked · air gap holds
What continues Data is intact Services stay live Business keeps running

One coordinated recovery fabric · Data, system and site verified together

Recovery ecosystem

Best-of-breed partners. One accountable team.

No single vendor covers every layer of recovery. We coordinate storage, cloud and hardware specialists so the recovery plan holds at every layer.

Immutable storage & WORM partners

Hardware and cloud providers that guarantee write-once storage, so a compromised admin account cannot erase history. Selected per environment, not per kickback.

Cloud region & DR site providers

Microsoft Azure, AWS and European sovereign cloud providers with regional failover and air-gapped isolation. Chosen for geographic distance from your primary site, not for price alone.

Server & hardware recovery specialists

Staged spare hardware, on-call replacement SLAs and forensic recovery for the physical layer. Because most outages start with a thing that has a power supply.

One coordinated recovery plan · Storage + cloud + hardware · No single point of failure

Case study

What Code Spaces teaches us about backups.

In 2014, a mid-market hosting provider called Code Spaces was put out of business by a single attacker, not because their data was valuable, but because they did not have a single copy that the attacker could not reach.

Real-world shutdown · 2014

A company erased in under 12 hours.

Code Spaces was a small but successful source-code hosting provider. In June 2014, an attacker gained control of their AWS account and demanded a ransom. When they refused to pay, the attacker used the same admin panel to delete every EC2 instance, every EBS volume, every S3 bucket and every backup snapshot inside the AWS account. Because the backups lived in the same account as the production data, the attacker deleted them in the same breath.

How the shutdown unfolded
  • Admin panel compromised. An attacker obtained control of the AWS management console used by Code Spaces staff.
  • Ransom demand. The attacker left a note demanding a payment to hand back control of the account.
  • Refusal, and retaliation. The company tried to regain control. The attacker began to systematically delete production data and backups.
  • Snapshot purge. Within hours, every backup snapshot in the AWS account was gone. Because backups lived beside production, they were not a last line of defence, they were the same line.
  • No recovery path. Code Spaces had no offline, immutable or out-of-account copy. There was nothing to restore from. The company ceased operations permanently and its customers were left to rebuild from whatever they had locally.

The lesson is not about the attacker. It is about architecture. If your backups sit in the same account, the same network or the same admin surface as your production data, they are not backups. They are a second copy of the same problem.

Backups in the same account are not backups

If an attacker has admin rights on your production, they have admin rights on your backups, unless the backups cannot be reached by that account. Immutability and account separation are the difference between losing data and losing a company.

Delete is the new encrypt

Modern attackers do not need to encrypt anything. They can simply delete your data, or the keys to it, and demand a ransom. The defence is the same, an offline, immutable copy they cannot touch.

Restore drills catch the fatal assumption

Every step in a recovery plan can look correct on paper and still fail on contact with reality. Drilling a real restore from a real backup is how you find out before you need to.

Out-of-band recovery matters

If the only path to your recovery is the same admin panel that was just compromised, you have no path. Out-of-band access, separate credentials and offline media are how you get back when production is under hostile control.

Two ways to protect

Backup-only, or full recovery program.

Both reduce risk. Only one is designed to keep the business running while it happens. The choice is which failure mode you are willing to accept.

Backup-only

Data is protected. The business is not.

Automated backups land in a vault every hour. If a server dies, someone will eventually find the backup, restore it, and bring the service back online. Eventually.

  • ✓Data is copied to a safe location
  • ✓Ransomware cannot always reach the copy
  • ✓Recovery is possible, given enough time
  • !Business stops while recovery runs
RTO realisticHours to days
RPO realistic1 to 24 hours
FailoverManual
DrillsRarely tested
Full BCDR program

Data is protected, and the business keeps running.

Immutable backups, live replicas, tested failover and rehearsed drills. When something fails, the recovery is already happening before anyone needs to pick up the phone.

  • ✓Immutable, air-gapped and multi-region backups
  • ✓Automated failover with near-zero data loss
  • ✓Secondary site or cloud region always on
  • ✓Quarterly restore drills with signed evidence
RTO targetUnder 15 minutes
RPO targetUnder 5 minutes
FailoverAutomated
DrillsQuarterly, documented
Extended recovery services

More than backups.

The full stack around BCDR, from crisis communication to compliance evidence, so your recovery plan is business-ready, not just data-ready.

Immutable vault architecture

Ransomware-proof by design, not by hope.

We do not trust antivirus, we do not trust perimeter firewalls, and we do not trust admin accounts. We assume your production environment will be breached, and design the vault so that even a full takeover cannot reach it. The vault is where the business survives, so it is where we spend the architectural effort.

Air-gapped copies

Physically unreachable. Logically untouchable.

Once a day, a copy of your data lands on media that is not connected to the network. Not patched into the same switch, not in the same account. It survives everything the production environment does not.

Air-gap schedule
Daily
Automated failover

Recovery that starts itself.

Health checks every thirty seconds. The moment the primary is unreachable, the standby takes over. No one needs to be paged to start the recovery.

Health check interval
30s
Recovery drills

Proven, not promised.

Every quarter we restore from real backups, in front of real stakeholders, and document the exact time it took. The result is not a claim, it is a signed rehearsal.

Drill cadence
Quarterly
Crisis communications

Your team is told before your customers complain.

When a real incident happens, calm beats chaos. We document exactly who gets told, in what order, in what words, so that staff, clients and regulators hear it from you before they hear it from somewhere else. The plan is written, signed and rehearsed.

Comms plan on file
Signed
Escalation paths
Documented
Compliance evidence

ISO 22301 ready, on request.

Every drill logged, every RTO recorded, every gap closed. Evidence ready for ISO 22301, NIS2 and your cyber insurance underwriter. Reports are provided on request, or as an option inside the managing service.

Evidence pack
On request
Engagement tiers

Pick the depth that fits your risk.

The tiers below are examples. Within each one, scope, RTO, RPO and drills are adapted to your operations, industry and existing infrastructure.

01 Small / single site

Essential backup

A focused backup and restore package for a single office. Covers the data, but not the running business. Ideal as a first step.

  • ScopeSingle office · servers · cloud apps baseline
  • BackupDaily · offsite · encrypted
  • DrillsTwice yearly restore test
  • ReportingOn request, restore log
Lead time1 to 2 weeks
03 Regulated / critical

Mission-critical

For finance, healthcare, critical infrastructure and anything where downtime is regulated. Full BCDR plus continuous drills, IR retainer and regulator-ready evidence.

  • ScopeEverything in Business continuity + OT · supply chain
  • DrillsContinuous · monthly failover rehearsal
  • StandardsISO 22301 · NIS2 · DORA · sector-specific
  • ReportingOn request, regulator-ready pack
Lead timeProgram-based

Examples only · Every scope is tailored · Managing and reporting available on request

The business case

Why BCDR is not a cost centre.

It is the difference between a bad week and a closed business. Here is what each side of that line looks like in practice.

When you have it

The incident happens. The business does not stop.

A server dies at 02:14. A user clicks a phishing link at 09:47. A warehouse floods on a Saturday. In every case, the same thing happens, the failover runs, the vault is sealed, the team is paged, and by the time clients log in on Monday, nothing looks wrong. The bad day was real, but the business never felt it.

  • ✓Failover in seconds, not hours
  • ✓Data loss measured in seconds, not days
  • ✓Insurers recognise the controls and price accordingly
  • ✓Clients never see the incident
DowntimeMinutes
Data lossNear-zero
When you don’t

The incident happens. The business ends.

A backup that has never been tested. A vault an attacker can reach. A failover nobody ever rehearsed. Every one of these looks like a plan, right up until the moment it does not work. By then the decision is no longer yours to make.

  • !Backups that were never tested do not restore
  • !Ransomware finds the backup before it locks production
  • !Clients leave and contracts end before the recovery completes
  • !60% of small businesses close within 6 months of a major incident
DowntimeDays to weeks
Data lossPermanent

Industry figures only · Actual impact depends on your sector, size and existing controls

From first audit to signed recovery plan.

A short, evidenced, engineering-first process. Every system documented, every failover proven.

01

Assess & map

We map every system, every dependency and every single point of failure. Every RTO and RPO agreed against the business, not against IT.

02

Design & build

Immutable vaults, air-gapped copies, live replicas, secondary site, and the automated failover policy. Every change reviewed and version-controlled.

03

Test & drill

We restore real data, in front of real stakeholders, and time the recovery to the second. Every gap becomes a documented fix. Every drill signed off.

04

Monitor & maintain

Continuous health checks, alert paths, quarterly re-drills and evidence packs on request. The plan stays current, because your business changes.

Run the crisis simulator.

Watch our BCDR protocol in action against two of the most common failure scenarios. Press Play to trigger the drill.

DAVIDSONS_BCDR_V2
STANDBY
ELAPSED 00:00
Scenario
Incident timeline
Infrastructure state
CLOUD VAULT WS-01 WS-02 WS-03 PRIMARY SERVER STANDBY REPLICA
System state
OPERATIONAL
Data at risk
0%
Active replicas
2 of 2
RTO remaining
15 min

Do not leave your business to chance.

Book a free BCDR audit. We will map your current exposure, identify every single point of failure, and show you exactly what it would take to survive a real incident.

Price available upon request