Business Continuity — Managed Backup
Managed backup services for New York businesses.
Immutable copies of the data your business runs on — watched daily, restore-tested on a schedule, and documented so an insurer or auditor can verify it. Not a product license and an unread status email.
What “managed” means when we say it
Most backup failures are operational, not technical: a job that started failing after a storage change and kept failing quietly, a new server that never made it into the policy, retention trimmed to save space the year before the lawsuit. The software rarely lies — it reports the failure to a mailbox nobody reads.
Managed backup means Stedholm owns that loop end to end. We design the coverage, monitor every job daily, investigate failures the day they occur, run the restore tests, and write the reports. When something falls out of coverage, finding it is our job, not your bad luck.
Immutable means immutable
An immutable copy cannot be modified or deleted before its retention clock expires — not by ransomware, not by a stolen administrator credential, not by us. Since destroying backups is a standard early move in an intrusion, we treat immutability plus separated credentials — MFA on the backup console, isolated from your primary identity system — as the baseline, not the premium tier.
We hold to 3-2-1 discipline: three copies, on two kinds of storage, with at least one immutable or offline. Firms under NYDFS Part 500 will recognize the regulatory language here — backups “adequately protected from unauthorized alterations or destruction” — as exactly this control.
Microsoft 365 is in scope
Retention policies and recycle bins are not backup; they are conveniences with expiration dates, and they will not survive an attacker with admin rights. We back up Exchange, OneDrive, SharePoint, and Teams data independently of the tenant — see Microsoft 365 services for the platform side.
What’s included
Server, VM, and endpoint backup
Image-level and file-level coverage matched to each system’s recovery tier, not a single default policy.
Microsoft 365 backup
Exchange, OneDrive, SharePoint, and Teams data copied out of the tenant on an independent schedule.
Immutable and offsite copies
At least one copy that cannot be altered or deleted inside its retention window, held apart from your production credentials.
Daily job monitoring
Failed jobs investigated by an engineer the day they fail — not filed in a mailbox for the quarterly review.
Scheduled restore testing
File-level and full-system tests on a published calendar, timed and recorded.
Retention mapped to obligations
Hold periods set from your regulatory and contractual requirements, not vendor defaults.
Evidence reporting
Restore results and coverage reports written to answer insurers, auditors, and client security questionnaires.
How restore testing runs
Testing is the product. Everything before it is preparation.
Tier the systems
With you, we sort systems by how fast they must come back — the same tiers that drive RTO and RPO targets set test frequency and depth.
Publish the schedule
Each tier gets a testing calendar you can see. Restores happen because the calendar says so, not when someone remembers.
Restore for real
Files, mailboxes, and full systems restored into an isolated environment, timed against the expectations we set together.
Record and report
What restored, how long it took, what failed, and what changed because of it — dated, and kept where you can produce it on demand.
Evidence your insurer actually asks for
Cyber-insurance applications have become specific: do you keep offline or immutable backups, is the backup console behind MFA, have you tested restores recently. Those answers can function as warranties — answering “yes” from optimism rather than operations is how claims turn into disputes.
We run the controls those questions describe and keep the dated evidence, so renewal answers come from reports rather than memory. The same artifacts serve NYDFS certification support, HIPAA contingency-plan documentation, and the FTC Safeguards file your Qualified Individual maintains.
Good fit if
Backup status is a green icon nobody clicks
Microsoft 365 data has no backup beyond retention settings
An insurance questionnaire asked about immutable copies and you paused
Nobody can say when a restore was last tested
You operate under NYDFS, HIPAA, or FTC Safeguards obligations
Common questions
Can you manage the backup product we already own?
Often, yes — if it can meet the bar: immutable copies, monitorable jobs, Microsoft 365 coverage, and restore testing we can actually execute. If it cannot, we will tell you exactly what is missing and you decide whether to change it. The assessment settles this before anything is signed.
How fast can you restore us?
It depends on data volume, target hardware, and connectivity — which is why we time real test restores instead of quoting a number. After the first test cycle you have measured recovery times per system, documented, which is worth more than any figure a sales page could print.
Is backup enough, or do we need disaster recovery too?
Backup answers the data question. Disaster recovery answers the operations question — where people work, in what order systems return, who calls whom. Small firms sometimes start with backup alone; regulated firms generally need both. The business continuity page lays out the split.
Know your backups restore — before you need them to.
An assessment shows what is covered, what is not, and when anything was last actually tested.