Protect Your Data. Reduce Downtime. Keep Your Business Running.

Your business depends on its data.

Customer records, emails, financial information, documents, applications and operational systems all need to be available when your people need them. But one accidental deletion, cyberattack, hardware failure or service outage can leave your organisation unable to work.

Cloud backup and disaster recovery services help protect your critical data and give your business a practical way to recover when something goes wrong.

At Stratiis, we provide managed cloud backup and disaster recovery solutions for businesses, charities and public-interest organisations across Scotland and the UK.

We do more than install backup software.

We help you identify what needs protected, decide how quickly it must be recovered, monitor whether backups are completing successfully and test whether your systems can actually be restored.

Speak to Stratiis about protecting your business data and building a practical disaster recovery plan.

What Is Cloud Backup?

Cloud backup creates secure copies of your business data and stores them in a separate cloud environment.

Depending on your requirements, this may include:

Microsoft 365 email and files

SharePoint and OneDrive data

Microsoft Teams data

Business servers

Virtual machines

Databases

Line-of-business applications

Desktop and laptop files

Cloud-hosted systems

Configuration and system data

Backups are normally created automatically according to a defined schedule. This reduces the risk of important data being missed because someone forgot to copy it manually.

A properly managed cloud backup solution should also provide monitoring, encryption, retention controls and clear recovery options.

The purpose is not simply to store another copy of your data. It is to make sure that your organisation can retrieve the right information when it is needed.

What Is Disaster Recovery?

Disaster recovery is the process your organisation follows to restore its IT systems, data and essential services after a serious disruption.

The disruption could be caused by:

  • Ransomware
  • A cyberattack
  • Hardware failure
  • Accidental deletion
  • Data corruption
  • Fire or flood
  • Power failure
  • Internet or network failure
  • Theft of equipment
  • A failed software update
  • A cloud service problem
  • Human error

A backup is one part of disaster recovery, but it is not the complete solution.

Disaster recovery also considers which systems must be restored first, who is responsible for making decisions, how employees will communicate and how the business will continue operating while recovery work takes place.

The UK National Cyber Security Centre advises organisations to plan for cyber incidents and ensure that recovery arrangements are effectively managed, rather than assuming recovery will happen automatically.

What Is the Difference Between Backup and Disaster Recovery?

Backup and disaster recovery are closely connected, but they solve different problems.

Backup protects your data.

It gives you another copy of files, emails, systems or databases that can be restored after deletion, corruption or loss.

Disaster recovery protects your ability to operate.

It defines how your technology and critical services will be restored following a major incident.

For example, a company may have a successful backup of its accounts database. However, if it has no replacement server, no access to the required application and no agreed recovery process, the business may still be unable to use that data.

A good recovery strategy brings the technology, data, people and processes together.

Why Do Businesses Need Cloud Backup?

Many organisations assume their information is safe because it is stored in the cloud.

Cloud platforms are generally resilient, but resilience of the platform is not the same as having a complete, independent backup and recovery strategy.

Microsoft explains that cloud customers remain responsible for protecting their data, identities, on-premises resources and the cloud components they control.

Without suitable backup protection, your organisation may struggle to recover from:

Accidental deletion

An employee may delete an email, document, folder or SharePoint site without realising it is still needed.

The deletion may not be discovered until weeks or months later, when built-in recovery options are limited or no longer available.

Ransomware

Ransomware can encrypt files, disrupt services and attempt to compromise connected backups.

The National Cyber Security Centre recommends maintaining multiple backups and separating them logically so that one compromised copy does not affect every recovery option.

Malicious activity

A disgruntled employee, compromised administrator account or external attacker could deliberately delete or alter business information.

Data corruption

Files, databases and applications can become corrupted because of software faults, failed updates, hardware problems or configuration errors.

Hardware failure

Servers, storage devices and other equipment can fail without warning. Replacing the equipment does not automatically restore the data or applications that were running on it.

Compliance and contractual requirements

Your organisation may need to retain certain information for legal, regulatory, insurance or contractual reasons.

Backup should form part of a wider information governance and retention strategy.

Business disruption

Even when data can eventually be recovered, a slow or poorly organised recovery can leave employees unable to work and customers unable to access services.

Does Microsoft 365 Include Backup?

Microsoft 365 includes a range of availability, retention, recycle-bin and recovery features.

However, these features should not automatically be treated as a complete backup strategy for every organisation.

Retention policies are primarily designed to support information governance and compliance. Recycle bins provide limited recovery options for deleted information. Neither replaces the need to understand your recovery requirements.

Microsoft now also provides Microsoft 365 Backup capabilities for services including Exchange Online, SharePoint and OneDrive. Microsoft describes the service as providing fast backup and restore within Microsoft 365 data boundaries.

The right approach depends on:

  • How long you need to retain information
  • How far back you may need to recover
  • Which Microsoft 365 services you use
  • How quickly information must be restored
  • Whether you need an independent copy
  • Your compliance obligations
  • Your budget
  • The level of management and reporting required

Stratiis can review your current Microsoft 365 environment and recommend an appropriate backup and recovery solution for Exchange Online, OneDrive, SharePoint and Teams.

What Should a Cloud Backup Solution Protect?

A backup strategy should be based on the information and systems your organisation needs to operate.

This often includes several different areas.

Microsoft 365

Microsoft 365 may contain a large proportion of your organisation’s operational information, including:

  • Exchange Online emails
  • Shared mailboxes
  • OneDrive files
  • SharePoint sites
  • Microsoft Teams data
  • Calendars and contacts

Your backup strategy should reflect how employees use Microsoft 365 and how long business information needs to be retained.

Business servers

Physical and virtual servers may host:

  • Shared drives
  • Finance systems
  • Customer databases
  • Document-management systems
  • Specialist applications
  • Active Directory services
  • Printing and operational systems

Server backups may need to protect the full system rather than individual files alone.

Cloud servers and virtual machines

Cloud-hosted servers still need appropriate protection.

The provider may protect the underlying infrastructure, but your organisation remains responsible for deciding how workloads, configurations and data should be backed up and recovered.

Databases

Databases often change throughout the working day.

The backup frequency should reflect how much information the organisation could realistically afford to lose.

Laptops and desktops

Where employees store information locally, endpoint backup may be required.

A better long-term approach may be to move business data into managed platforms such as SharePoint or OneDrive, but endpoint protection can still be appropriate for certain users and devices.

Specialist applications

Industry-specific systems may have their own backup requirements.

Stratiis can work with your software provider to understand how the application stores data and how it should be restored.

What Is the 3-2-1 Backup Rule?

The 3-2-1 backup rule is a widely used approach to reducing the risk of losing every copy of your data in the same incident.

It recommends keeping:

  • Three copies of your data
  • Two copies on different systems or forms of storage
  • One copy stored off-site

The National Cyber Security Centre describes the 3-2-1 approach as a common method for creating resilient backups and recommends keeping multiple copies that are logically separated.

Modern backup strategies may extend this principle by including immutable or offline copies.

An immutable backup cannot easily be changed or deleted during its protected retention period. This can make it harder for ransomware or a compromised administrator account to destroy your recovery data.

The most suitable design will depend on your systems, risk profile and recovery requirements.

Why Backup Monitoring Matters

A backup job showing as configured does not necessarily mean your data is protected.

Backups can fail because of:

  • Expired credentials
  • Storage limits
  • Network problems
  • Configuration changes
  • Software errors
  • Licensing issues
  • New users or systems being missed
  • Corrupted backup data
  • Security incidents
  • Failed application integrations

Without monitoring, a failed backup may go unnoticed until the business needs to recover something.

That is the worst possible time to discover a problem.

A managed cloud backup service should provide:

Automated monitoring

Failure alerts

Regular status reviews

Capacity monitoring

Backup reports

Investigation of failed jobs

Retention checks

Recovery testing

Clear escalation procedures

Stratiis monitors managed backup services and investigates problems so that failures are not simply left for the customer to discover.

Why Backups Must Be Tested

A backup is only useful if it can be restored.

Testing helps confirm that:

  • The backup contains the expected data
  • The information is not corrupted
  • The recovery process works
  • Access permissions can be restored
  • The required systems and software are available
  • The recovery time is realistic
  • Staff understand their responsibilities

The National Cyber Security Centre warns that malware may remain within backups and recommends scanning restored files and rebuilding software from trusted sources where appropriate.

Recovery testing should not be limited to restoring one test document.

For important systems, testing may need to simulate a wider incident, such as the loss of a server, a ransomware attack or the failure of a business application.

What Are RPO and RTO?

Two important terms used when planning backup and disaster recovery are Recovery Point Objective and Recovery Time Objective.

Recovery Point Objective

The Recovery Point Objective, or RPO, is the maximum amount of recent data your organisation could afford to lose.

For example, an RPO of four hours means the business must be able to recover data from no more than four hours before the incident.

A company entering hundreds of financial transactions each day may need a much shorter RPO than a business whose files change infrequently.

Recovery Time Objective

The Recovery Time Objective, or RTO, is the target time for restoring a system or service after an incident.

For example, an RTO of eight hours means the organisation aims to restore the service within eight hours of the disruption.

Not every system needs the same RTO.

Your email, finance system or customer database may need to be restored quickly, while an archive server may be able to wait.

Stratiis helps customers prioritise systems and set recovery objectives that are realistic, affordable and aligned with the needs of the business.

How Quickly Can a Business Recover?

Recovery time depends on several factors:

  • The cause of the incident
  • The amount of data involved
  • The systems being restored
  • The available internet connection
  • The type of backup solution
  • Whether replacement hardware is required
  • Whether the environment is safe to restore into
  • Whether user accounts or identities have been compromised
  • The agreed recovery priority
  • The availability of application suppliers
  • The quality of the disaster recovery plan

Restoring a deleted document may take minutes.

Recovering a full server environment after ransomware could take considerably longer because the organisation must first contain the threat, investigate the compromise and confirm that it is safe to reconnect restored systems.

Promises of instant recovery should therefore be treated carefully.

A responsible provider should define what can be recovered, in what order and under which assumptions.

What Should a Disaster Recovery Plan Include?

A useful disaster recovery plan should be practical enough to follow during a stressful incident.

It should include:

Critical systems

A clear record of the systems, applications and data the organisation relies on.

Recovery priorities

An agreed order for restoring services.

This should be based on business impact rather than which system is easiest to restore.

Recovery objectives

Defined Recovery Point Objectives and Recovery Time Objectives for important systems.

Roles and responsibilities

Named decision-makers, technical contacts, suppliers and escalation routes.

Communication arrangements

A method for communicating with employees, customers, suppliers and other stakeholders if normal systems are unavailable.

Technical recovery procedures

Documented instructions for restoring data, systems, applications and configurations.

Alternative working arrangements

Plans for employees to work from another location or use replacement systems while recovery takes place.

Cyber incident considerations

Procedures for containing an attack, protecting evidence and avoiding the restoration of compromised systems.

Supplier information

Contact details, account information and escalation processes for critical technology providers.

Testing schedule

An agreed timetable for reviewing and testing the plan.

Plan maintenance

A process for updating the plan when systems, people, suppliers or business requirements change.

Disaster Recovery and Business Continuity

Disaster recovery and business continuity are related, but they are not identical.

Disaster recovery concentrates mainly on restoring technology, systems and data.

Business continuity considers how the wider organisation will continue delivering essential products or services during disruption.

A complete business continuity plan may also cover:

  • Buildings
  • People
  • Communications
  • Supply chains
  • Key suppliers
  • Utilities
  • Transport
  • Manual working procedures
  • Customer communications
  • Regulatory reporting
  • Financial authority

Technology recovery should support the wider continuity plan.

For example, restoring a finance application will not help if no one can access the building, employees do not have working devices or the organisation has no way to contact customers.

UK government guidance describes business continuity management as a process for managing risks to the smooth running of an organisation and supporting the continuation of critical functions during disruption.

How Cloud Backup Helps Protect Against Ransomware

Cloud backup is an important part of ransomware resilience, but it must be designed correctly.

Attackers may attempt to:

  • Encrypt live business data
  • Delete backups
  • Compromise backup administrator accounts
  • Disable security tools
  • Corrupt systems before the attack is discovered
  • Steal data before encrypting it
  • Target connected cloud services

A ransomware-resilient backup strategy may include:

Separate backup credentials

Multi-factor authentication

Immutable backup storage

Offline or logically isolated copies

Restricted administrative access

Longer retention periods

Multiple recovery points

Monitoring for unusual activity

Recovery testing

Documented incident-response procedures

Backups should not be permanently accessible using the same accounts and permissions as the systems they protect.

Stratiis can review your backup environment as part of a wider cybersecurity and business resilience assessment.

What Are Immutable Backups?

Immutable backups are backup copies that cannot normally be edited, overwritten or deleted during a defined retention period.

This provides additional protection against:

  • Ransomware
  • Malicious deletion
  • Compromised administrator accounts
  • Accidental changes
  • Backup tampering

Immutability is not a complete security solution.

Administrator accounts still need strong protection, retention periods must be correctly configured and recovery procedures must be tested.

However, immutable storage can provide an important final recovery option when live systems and conventional backups have been compromised.

How Long Should Backups Be Retained?

There is no single retention period that is right for every organisation.

Retention should be based on:

  • Legal requirements
  • Regulatory obligations
  • Insurance conditions
  • Customer contracts
  • Internal policies
  • The type of data
  • How quickly errors are normally discovered
  • The cost of storage
  • The organisation’s risk appetite

A common backup schedule may include:

  • Daily recovery points
  • Weekly recovery points
  • Monthly recovery points
  • Annual or long-term archives

Keeping every backup forever is rarely practical or appropriate.

Organisations must also consider data protection principles and avoid retaining personal data longer than necessary without a valid reason.

Stratiis can help align backup retention with your operational, compliance and information-governance requirements.

Is Cloud Backup Secure?

Cloud backup can be highly secure when it is correctly designed and managed.

Important controls include:

  • Encryption in transit
  • Encryption at rest
  • Multi-factor authentication
  • Role-based access
  • Separate administrator accounts
  • Restricted permissions
  • Secure data centres
  • Audit logs
  • Retention controls
  • Immutable storage
  • Monitoring and alerts
  • Regular security reviews
  • Tested recovery procedures

Security also depends on how the service is administered.

A technically capable platform can still be weakened by shared passwords, excessive permissions, unprotected administrator accounts or poor monitoring.

Stratiis takes a managed approach so that the technology is supported by appropriate policies, access controls and oversight.

Who Needs Cloud Backup and Disaster Recovery?

Almost every organisation that relies on digital information should have a backup and recovery strategy.

This is particularly important for organisations that:

  • Cannot operate without access to IT
  • Hold confidential or personal data
  • Use Microsoft 365 extensively
  • Depend on specialist applications
  • Have regulatory or contractual obligations
  • Provide services to the public
  • Work across several locations
  • Have remote or hybrid employees
  • Need to demonstrate cyber resilience
  • Would suffer serious reputational damage following data loss

Stratiis supports organisations across a range of sectors, including:

Accountancy firms

Law firms

Charities

Housing associations

Construction companies

Engineering businesses

Manufacturers

Professional services firms

Healthcare-related organisations

Multi-site businesses

Each organisation has different recovery priorities. That is why backup and disaster recovery should be designed around the business rather than sold as a standard storage package.

What Is Included in a Managed Cloud Backup Service?

A managed cloud backup service from Stratiis may include:

Backup assessment

We review your systems, data locations and existing backup arrangements.

Solution design

We recommend an approach based on your risks, recovery requirements, retention needs and budget.

Implementation

We configure the backup platform, policies, schedules, security controls and protected workloads.

Microsoft 365 protection

We can protect business information held within Exchange Online, OneDrive, SharePoint and Microsoft Teams.

Server and virtual-machine backup

We can protect physical servers, virtual servers and supported cloud workloads.

Monitoring

Backup jobs are monitored so failures can be identified and investigated.

Reporting

You receive visibility of backup status, protected systems and any issues requiring attention.

Recovery support

Our team can help restore files, emails, systems or wider environments when required.

Recovery testing

We can carry out agreed test restores and help validate whether recovery objectives can be met.

Disaster recovery planning

We help document recovery priorities, responsibilities, dependencies and procedures.

Ongoing review

Backup requirements are reviewed as your systems, workforce and business change.

Our Cloud Backup and Disaster Recovery Process

1. Understand your organisation

We begin by understanding how your business operates, which systems are important and what would happen if they became unavailable.

2. Identify critical data and systems

We identify where important data is stored and check whether any systems, users or applications are currently unprotected.

3. Define recovery priorities

We agree which services must be recovered first and how quickly the business needs them back.

4. Design the solution

We recommend an appropriate combination of backup frequency, retention, security, storage and disaster recovery capabilities.

5. Implement and secure

We configure the solution, protect administrator access and separate backup services from the systems they protect.

6. Monitor and manage

We monitor backup performance, investigate failures and keep the configuration under review.

7. Test recovery

We test agreed restore scenarios to confirm that the data can be recovered and that procedures remain practical.

8. Review and improve

We update the strategy when systems, suppliers, applications or business requirements change.

How Much Does Cloud Backup and Disaster Recovery Cost?

The cost depends on what needs to be protected and how quickly it must be recovered.

Pricing may be affected by:

The number of Microsoft 365 users

The volume of data

The number of servers

The number of virtual machines

Backup frequency

Retention period

Immutable storage requirements

Disaster recovery infrastructure

Recovery time objectives

Recovery testing

Monitoring and support requirements

Compliance and reporting needs

A Microsoft 365 backup service may be priced per user or according to storage and consumption.

Server backup may be priced per device, workload or volume of protected data.

A full disaster recovery service will usually cost more than basic file backup because it is designed to restore complete systems and services rather than individual documents.

Stratiis provides clear recommendations based on the level of protection your organisation genuinely needs.

What Should You Look for in a Backup and Disaster Recovery Provider?

When comparing providers, ask the following questions:

  • What systems and data will be protected?
  • Are Microsoft 365 services included?
  • How frequently will backups run?
  • Where will backups be stored?
  • Are backups encrypted?
  • Are immutable or isolated copies available?
  • How long will data be retained?
  • Who monitors failed backup jobs?
  • How quickly will failures be investigated?
  • How often are restores tested?
  • What is the recovery process during ransomware?
  • Are recovery times guaranteed or only estimated?
  • What happens if replacement hardware is required?
  • Who will manage communication during an incident?
  • Can the provider help create a disaster recovery plan?
  • Will the provider review the service as the business changes?
  • What reporting will management receive?
  • What support is available during a serious incident?
  • Are all costs clearly explained?

A strong provider should be comfortable discussing recovery limitations as well as capabilities.

Why Choose Stratiis?

Stratiis provides managed IT, cloud, cybersecurity and communications services to organisations across Scotland and the UK.

Our approach connects backup with the wider technology environment.

That means we can consider:

Microsoft 365

Servers and cloud infrastructure

Cybersecurity

Identity and access management

Networking and connectivity

Endpoint management

Business continuity

Incident response

Rather than treating backup as an isolated product, we help ensure that it supports the way your organisation actually operates.

With offices serving Glasgow, Edinburgh and Inverness, Stratiis provides local expertise backed by a wider managed-services capability.

Cloud Backup and Disaster Recovery Checklist

Use this checklist to assess your current arrangements.

  • Do you know where all critical business data is stored?
  • Is Microsoft 365 data included in your backup strategy?
  • Are all important servers and applications protected?
  • Are backups created automatically?
  • Are backup failures actively monitored?
  • Are backups protected by multi-factor authentication?
  • Are backup administrator accounts separate from normal user accounts?
  • Do you maintain an off-site or isolated backup copy?
  • Do you use immutable backup storage where appropriate?
  • Do you know how long backups are retained?
  • Have you defined your Recovery Point Objectives?
  • Have you defined your Recovery Time Objectives?
  • Do you know which systems must be restored first?
  • Have you tested a data restore recently?
  • Have you tested a full system recovery?
  • Do you have a written disaster recovery plan?
  • Does the plan include supplier contact information?
  • Do employees know who makes decisions during an incident?
  • Is the plan reviewed when systems or staff change?
  • Does management receive regular backup and recovery reporting?

Any unanswered question may represent a potential weakness in your recovery strategy.

Frequently Asked Questions

What is cloud backup?

Cloud backup is the process of automatically copying business data to a secure cloud-based environment so that it can be restored following deletion, corruption, hardware failure or a cyber incident.

Is OneDrive a backup?

OneDrive provides cloud storage, synchronisation, version history and some recovery capabilities. However, synchronisation can also replicate unwanted changes or deletions. Whether OneDrive provides enough protection depends on your retention and recovery requirements.

Do we need to back up Microsoft 365?

Many organisations choose to add dedicated Microsoft 365 backup because they require longer retention, simpler recovery, independent protection or stronger reporting than built-in features alone provide.

What Microsoft 365 data can be backed up?

Depending on the solution, backups may include Exchange Online mailboxes, OneDrive accounts, SharePoint sites and Microsoft Teams data.

Will cloud backup protect us from ransomware?

Cloud backup can help your organisation recover from ransomware, particularly when backup copies are isolated, immutable and protected by separate credentials. It does not prevent ransomware and should be combined with wider cybersecurity controls.

How often should our data be backed up?

The correct frequency depends on how often data changes and how much recent information the organisation could afford to lose. Critical systems may require frequent backups, while less important data may only need daily protection.

What happens when a backup fails?

With a managed backup service, the failure should generate an alert for investigation. The provider should identify the cause, correct the problem and confirm when protection has resumed.

How often should backups be tested?

Important backups should be tested regularly. The frequency should reflect the importance of the system, the organisation’s risk profile and any compliance requirements.

Can you restore one deleted file?

Yes. Most backup solutions allow individual files, folders, emails or other items to be restored without recovering an entire system.

Can you recover a complete server?

Where a suitable image-based or virtual-machine backup has been configured, it may be possible to restore a complete server. Recovery time will depend on the platform, data volume, available infrastructure and nature of the incident.

What is an immutable backup?

An immutable backup is protected against alteration or deletion for a defined period. It can provide an additional defence when ransomware or compromised administrator accounts target normal backups.

What is disaster recovery as a service?

Disaster Recovery as a Service, sometimes shortened to DRaaS, provides cloud-based infrastructure and recovery capabilities that can be used when a business’s main systems become unavailable.

How is disaster recovery different from business continuity?

Disaster recovery focuses mainly on restoring IT systems and data. Business continuity covers the wider steps required to keep the organisation operating, including people, premises, suppliers and communications.

Can Stratiis help create our disaster recovery plan?

Yes. Stratiis can help identify critical systems, set recovery priorities, document responsibilities and create practical technology recovery procedures.

Can Stratiis test our existing backups?

Yes. We can review existing arrangements, check backup coverage and carry out agreed test restores to assess whether your data and systems can be recovered.

How quickly can Stratiis recover our systems?

Recovery time depends on the systems involved, the type of incident, the backup platform and the agreed recovery objectives. These expectations should be documented before an incident occurs.

Protect Your Business Before You Need to Recover It

The middle of a cyberattack, system failure or data-loss incident is not the right time to discover that your backups are incomplete.

Stratiis can review your current backup arrangements, identify gaps and help you build a practical recovery strategy.

Whether you need Microsoft 365 backup, server protection, immutable cloud storage or a complete disaster recovery plan, we will recommend a solution based on your organisation’s actual risks and priorities.

Speak to Stratiis About Cloud Backup and Disaster Recovery

Contact Stratiis to arrange a review of your current backup and recovery arrangements.

Call: 0141 348 7960
Email: sales@stratiis.com