Cybersecurity

Data backup and a disaster recovery plan for small businesses in Nice

A backup protects your business on three conditions: that it is offline or offsite, that it really covers all your data — email and business software included — and that a restore has already been tested. The disaster recovery plan adds the question of time: how quickly do you start up again, and how much work are you prepared to lose? MZ Informatique puts both in place for small businesses in Nice and the Alpes-Maritimes.

Why does a permanently connected backup not protect you?

Because ransomware encrypts everything the machine can reach, backup included. An external disk left plugged in, a network share mounted permanently or a folder synchronised automatically all look to the attacker exactly like the rest of the data. It is one of the three weaknesses we find in very nearly every estate we audit on the Côte d'Azur: backups stored on the same network as the data.

A useful backup is offline or offsite, it is verified, and above all it has already been restored at least once. A backup that has never been restored is not a backup: it is an assumption.

How should a small business organise its backups?

Around one simple principle, known as the 3-2-1 rule: three copies of your data, on two different media, of which one copy is held offsite. In practice, for a firm with twenty workstations: the production data on the server or the machine, a fast local copy for everyday restores — a deleted file, an overwritten version — and an offsite copy, away from the premises and away from the network, for the major incidents: fire, theft, ransomware.

We always add two points that get forgotten: which data is actually backed up — mailboxes and online tools rarely are by default — and how many successive versions are kept, because data that has been corrupt for three weeks cannot be recovered from yesterday's single backup.

  • The data on the file server and on the workstations.
  • Mailboxes and online workspaces, rarely backed up by default.
  • The databases behind your business software, backed up cold or consistently.
  • The configuration of the network equipment, so you can rebuild quickly after an incident.

What is a disaster recovery plan?

It is the document that answers a single question: what do we do, in what order and how quickly, when the IT stops? It sets two values decided with you rather than imposed on you: the acceptable time before the service comes back, and how much work you are prepared to lose — an hour, half a day, a day. Those two figures determine everything else, budget included.

The plan then lists the applications in priority order — payroll is not as urgent as the till or as order management — the people to contact, the access needed and where the backups sit. It runs to a few readable pages, not to a binder nobody will open on the day.

A recovery plan without a test is only an intention. We replay a real restore at regular intervals and hand you the write-up: how long it took, what came back, what was missing.

What do we check during a restore test?

Four things, in this order. That the backup opens — unreadable media, or encryption whose key nobody holds, is not a textbook case. That the data is complete, including files that were open when the copy ran and the databases. That the application restarts once the data is back, which means having the configurations too. That the time observed matches the one stated in the recovery plan.

This test is part of the initial security audit: we do not simply look at the green light on the backup console. It is often at that moment that you discover what was not being backed up.

How much does offsite backup cost?

It is included in our monthly protection and monitoring fee, charged per workstation per month, alongside monitored anti-virus, updates and support. The initial set-up — reworking the existing backups, moving a copy offsite, the first restore test — falls under the initial remediation, costed on the quotation.

The volume of data and the number of servers move the figure, not the complexity of the solution. We favour standard mechanisms you could take elsewhere: no data is locked into a format that would make you dependent on us.

Frequently asked questions

Backup and recovery: what we get asked

Our data is in the cloud: is it backed up?

Not in the sense you mean. The large online services guarantee the availability of their infrastructure, not the recovery of a file you deleted six weeks ago, nor of a mailbox emptied by a compromised account. A third-party backup of your online workspaces is still needed: it is one of the first points we check.

How often should a restore be tested?

Once a year at the very least, and after every significant change: a new server, a change of business software, an email migration. We replay the test as part of the monitoring fee and hand you the write-up: how long it took, what came back, what was missing.

What is the difference between backup, recovery planning and high availability?

A backup keeps a copy of the data. The recovery plan organises the restart: what, in what order, how quickly. High availability aims at no interruption at all, through redundant equipment; it costs markedly more and is only justified for activities that cannot stop for an hour. For most small businesses, backup plus a recovery plan is enough.

Where are the offsite backups hosted?

The hosting location is agreed with you when the system is set up and written into your register of processing activities, along with the retention period chosen. We favour hosting inside the European Union and encryption whose key you hold.

When did you last run a restore?

The free audit includes a real restore test, on site in Nice, Sophia Antipolis, Cannes or Monaco. You will finally know what your backups are worth.