Backup and Disaster Recovery
Don't lose data even during a ransomware attack. On-premise and cloud backup, immutable copies, tested recovery procedures. You know your RTO/RPO and know backup will work when needed - because you test it regularly.

What is backup and disaster recovery?
Backup and disaster recovery is a data protection strategy combining the 3-2-1 rule (3 copies, 2 media, 1 off-site), immutable backups resistant to ransomware, and regularly tested recovery procedures with defined RTO and RPO targets. nFlo implements and manages Veeam, Commvault, and IBM Spectrum Protect solutions, including DR drills that verify backup actually works before a real incident occurs.
60% of companies will never recover data from backup - because they never tested it
Backup and DR system with regular recovery testing
3-2-1 Strategy
3 copies, 2 media, 1 off-site - protection against every scenario
Immutable Backup
Copies that ransomware cannot encrypt
DR Testing
Regular tests to verify backup actually works
Ransomware Encrypted Production and Backup - 14 Days Downtime
A manufacturing company fell victim to ransomware. Production systems encrypted - and backup on the same NAS. Recovery from tapes that no one had tested for 2 years took 14 days. Losses: €1.9 million in revenue + €120K ransom they paid anyway.
Without proper backup and DR:
- Data loss during storage failure, ransomware, human error
- Long downtime because you don’t know how long recovery will take
- Backup on same storage as production - ransomware encrypts everything
- No certainty backup actually works - because you’ve never tested it
- Non-compliance with regulations (NIS2, GDPR) regarding data protection
Backup and DR for Cyber-Resilience
A backup is the last line of defense against ransomware — provided it is attack-resilient. We apply the 3-2-1 rule (extended to 3-2-1-1-0) with immutable and air-gapped copies protected by separate credentials.
The key is the ability to recover quickly and verifiably within a defined RTO/RPO. We test recovery regularly, so an attack is not a choice between downtime and paying the ransom.
From 3-2-1 Strategy to Regular DR Tests
We don’t just install a backup agent. We design a data protection strategy aligned with your RTO/RPO, implement the solution, test recovery, and train your team on incident response.
What you get:
- Business Impact Analysis - RTO and RPO determination for each system
- Backup strategy following 3-2-1 rule (3 copies, 2 media, 1 off-site)
- Backup platform implementation (Veeam, Commvault, IBM Spectrum Protect)
- Immutable backup configuration (ransomware protection)
- Cloud backup (AWS, Azure) for off-site copy
- Integration with Hyper-V, Proxmox, physical servers
- Application and database backup (SQL, Oracle, Exchange, SAP)
- Disaster recovery plan with specific procedures
- Recovery tests - verification that backup works
- Backup job monitoring and automatic alerts
- Documentation and team training
Who Is It For?
This service is for you if:
- You’re not sure your backup will actually work
- Backup is on the same storage as production data
- You don’t know your RTO and RPO - don’t know how long recovery will take
- You must meet NIS2, GDPR, ISO 27001 backup requirements
- You want ransomware protection through immutable copies
- You need backup for virtualization, cloud (AWS, Azure, M365)
3-2-1-1-0 Backup Strategy
Extension of Classic 3-2-1 Rule
We recommend the 3-2-1-1-0 strategy as protection against modern threats:
- 3 data copies (production + 2 backups)
- 2 different media types (disk + cloud or tape)
- 1 off-site copy (in different location)
- 1 immutable copy (air-gap or object lock)
- 0 verification errors (test your recovery!)
Backup Platforms
Veeam Backup & Replication
Most popular platform for virtual environments:
- VM backup and replication
- Instant VM Recovery (RTO in minutes)
- Backup to cloud (AWS, Azure, Wasabi)
- Immutable backup (S3 Object Lock, hardened repository)
- Backup for Microsoft 365 (Exchange, SharePoint, OneDrive, Teams)
- Veeam Data Cloud for Entra ID - Microsoft identity backup
- Veeam ONE for monitoring
Commvault Complete Backup & Recovery
Enterprise data protection:
- VM, physical, cloud, SaaS backup
- Metallic SaaS - backup as a service
- HyperScale X - scale-out backup appliance
- Ransomware detection and recovery
- Long-term retention and compliance
IBM Spectrum Protect
Backup and archiving for large environments:
- Source-side deduplication
- Backup to tape libraries
- Safeguarded Copy - immutable backup
- Integration with IBM storage
Related Glossary Terms
Learn more about key concepts related to this service:
Contact your account manager
Discuss Backup and Disaster Recovery with your dedicated account manager.

How we work
Our proven service delivery process.
BIA
Business Impact Analysis - RTO/RPO determination
Design
Backup and disaster recovery strategy
Implement
Veeam/Commvault deployment, configuration
Test
Recovery test - RTO/RPO verification
Monitor
Continuous monitoring, alerts, regular tests
Benefits for your business
What you gain by choosing this service.
Data Loss Protection
Data safe even during ransomware or hardware failure
Fast Recovery
Return to operations in hours instead of days
Regulatory Compliance
Meet NIS2, GDPR, ISO 27001 requirements
Lower Premiums
Insurers value tested backup
Related Articles
Expand your knowledge with our resources.
CVE-2026-11374: In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus,...
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, le...
Read more →CVE-2026-12205: Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private...
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever c...
Read more →CVE-2025-1740: Improper restriction of authentication attempts in Akinsoft MyRezzta
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass, Password Recovery Exploitation, Brute Force. This issue affects MyRezzta: fr...
Read more →Frequently Asked Questions
Common questions about Backup and Disaster Recovery.
What is the 3-2-1 backup strategy?
The 3-2-1 strategy is the golden rule of backup: 3 copies of data, on 2 different media (e.g. disk + tape), with 1 copy off-site (in a different location or cloud). It protects against single device failure, site failure and ransomware attacks.
What is immutable backup and why is it important?
Immutable backup is a backup copy that cannot be modified or deleted for a specified period of time. It is crucial for ransomware protection - even if attackers take control of systems, they cannot encrypt or delete immutable copies.
What is the difference between RTO and RPO?
RPO (Recovery Point Objective) is the maximum acceptable data loss - e.g. RPO 1h means you can lose max 1h of data. RTO (Recovery Time Objective) is the time needed to restore systems - e.g. RTO 4h means you must be back up and running within 4h.
How often should backup and disaster recovery be tested?
We recommend: backup tests (single file recovery) monthly, DR tests (full system recovery) quarterly, full DR exercises (failure simulation) once or twice a year. ISO 27001 and NIS2 require regular testing.
How much does backup and disaster recovery implementation cost?
Cost depends on data volume, required RTO/RPO and chosen technology. A backup project for a mid-size company (10-50 TB) typically costs 30,000-100,000 PLN. This includes licenses, implementation and training. We also offer a subscription model (BaaS).