Fire, flood, theft, ransomware, a dead motherboard: what these events have in common is not their cause but their effect — your servers are gone overnight. A backup answers the question “do I still have my data?”. A recovery plan answers the one that actually costs money: “when does my team get back to work?”
Many companies learn the difference on the worst possible day. The backups existed, and they were sound — but between ordering a server, rebuilding it and moving several terabytes back onto it, days go by, not hours.
It answers: do I still have my data? That is necessary, and it is where most contracts stop. A perfect backup does not prevent a long outage.
It answers: how soon am I working again? That requires a bootable copy of your servers, ready to run somewhere else, immediately, without waiting for hardware.
It is measured in days of revenue, orders never entered, and wages paid to people who are waiting. Most companies have never put a figure on it — which is why the recovery plan keeps being postponed.
We publish no standard recovery time, because there is no such thing: it depends on your data volume and on how critical each server is. It is agreed with you, written into the contract, and tested.
Four mechanisms in Datto BCDR, and what each one changes on the day you need it.
Each snapshot is a complete, bootable recovery point rather than the last link in a chain of incrementals to rebuild. That is what allows an immediate restart — and it is also what breaks least often.
The system periodically boots your backups in isolation and captures the resulting screen. We do not tell you the backup is good: we show you the login screen.
Backups are scanned for signs of malicious encryption. The point is not to stop the attack; it is to know which date to roll back to in order to find a clean point.
Someone overwrote a folder? We restore the folder. A server is dead? We restore the whole server, on the same hardware or different hardware. One setup covers both.
Your backups leave your premises encrypted and are replicated to a data centre located in Germany, and therefore within the European Union. One copy stays with you, on the appliance: that is the one that allows a fast restart, while the remote copy covers the loss of the site itself.
It is the first question any cyber insurer and any auditor asks. We would rather answer it here than on request.
One honest caveat: Datto is a US vendor, even though the hosting we use is European. If your sector or your market requires French sovereign hosting, say so at the first conversation: we handle that case with a different architecture, and we will tell you plainly if we are not the right provider for that particular constraint.
That is your RTO. An hour for a practice booking appointments all day, half a day for a design office: there is no universal right answer, only yours.
That is your RPO. If the last backup ran overnight, an incident at 5 pm costs you a day of data entry. This is the parameter that sets how often snapshots are taken.
Those two answers determine the architecture and the budget. We ask them at the first meeting, before discussing hardware — and we write them into the contract, because a recovery commitment that exists nowhere commits no one.
We survey what you have, identify what would actually stop you, and price it. The survey is free and commits you to nothing.