Solution
Backup and recovery
A successful job proves neither integrity, isolation nor recovery time. I separate the credentials, isolate the copy, restore in front of you with the duration measured, then have management decide the acceptable downtime and data loss for each service.
On the day it matters
A duration you know rather than hope for
After the first timed restore you know how long each system takes to come back. Management then decides whether that figure is acceptable or calls for investment.
Extortion has less leverage
Isolated copies and rehearsed restores give the organisation an exit other than the criminals' promise. They resolve neither data theft, business interruption nor the duty to notify.
Retention you can defend
Scope and duration are tied to a recovery need, an obligation or an explicit decision. The cost becomes legible.
Recovery objectives are decided, not assumed
Every service carries a downtime and a data loss management has accepted. The recovery architecture, from a plain restore to a standby site, follows those figures rather than the other way round.
In practice
- Credential separation: the backup store refuses the accounts that administer production, so one stolen password doesn’t open both
- An isolated or immutable copy for a defined period, chosen for the threat, then tested against administrative deletion, expiry and capacity
- For each hosted service, the native retention, restore and export mechanisms tested; an additional backup only where they fall short
- A restore genuinely performed in front of you, system by system, with the measured duration written down
- Recovery objectives per service: accepted downtime and data loss, then the architecture that holds them, from a plain restore to a standby site
- A recovery rehearsal: one service failed over to the standby and brought back, with timings, gaps and decisions recorded
- A test cadence based on criticality, change and risk, with a procedure your team runs
Systems involved
- Proxmox Backup Server, restic, Veeam and the backup tools in place
- Object storage with locking, S3 Object Lock for instance, and ZFS
- Microsoft 365, Google Workspace and the retention features of hosted services
- PostgreSQL, SQL Server and the databases to restore
- Swiss hosts and Swiss cloud regions for the off-site copy
Service lineServers and hosting →
The systems to bring back
The same work, against each sector’s own constraints. Every card opens the full sector.
Banking and insurance
Recovery objectives decided per service
Claims handling, pricing and accounting each receive a downtime and a data loss management has accepted. A timed restore and then a failover rehearsal prove the architecture holds them.
Energy and utilities
The data platform restored within a known time
Measurement history and forecasts cannot be recreated from the meters. The isolated copy and the timed restore give management a known downtime before the incident, not during it.
Healthcare and life sciences
Records restored without exposing the data
The isolated copy of records and research data uses credentials separate from production, and I restore in front of you, in an isolated environment, with the duration measured.
Logistics and supply chain
Flow tracking restored before the next wave
Shipment tracking, partner exchanges and invoicing each carry an accepted downtime. The timed restore says whether the warehouse reopens in the morning.
Manufacturing
Shop-floor data and the ERP restored within a decided time
Machine history, the ERP and the documentation receive copies isolated from production and a timed restore. The shop floor knows the delay before the outage, not during it.
Retail and e-commerce
Sales and stock restored before opening
The central till, the stock and the accounts each carry a downtime management has accepted. The timed restore says whether the shops open on time after an incident.
How it runs
Inventory
You choose what has to survive, for how long, and the acceptable downtime per service. Drawing up the list is how the data still outside any backup gets found.
Separation
Credentials, the immutable or isolated copy and the off-site copy get designed together, then their configuration is tested.
Restore
A real restore, onto a side environment, timed. That’s the moment the backup stops being a hypothesis.
Rehearsal
One service fails over to the standby and returns, with roles, timings and decisions recorded. Your team then owns the test calendar.
To go deeper

Five threats to a Swiss organisation, and the control that blocks each one
Documented Swiss incidents point back to the same controls: exposed services, identity, payments, suppliers and recovery. The order still needs to fit the organisation's risk.

Backups: the restore test nobody runs
Rolle, 2021: the data of 5,393 residents on the darknet. A backup strategy becomes credible when recovery is tested against RTO, RPO and business impact.
Test the fit: Backup and recovery
Describe the context, constraints and decision you need to make. The first conversation qualifies scope, boundaries and the next useful step.
Describe the situation