Backup & Disaster Recovery
Backup & Disaster Recovery · Capability

Recovery rehearsals

Scheduled restore tests with timed results — because a backup that has never been restored is a hope, not a plan.

A backup job that completes successfully every night proves the software ran, not that the data it captured will actually come back usable when you need it. Corrupted source files, missed folders, expired credentials on a connected service, or a restore process nobody has actually walked through under pressure — all of these hide behind a green tick until the day a real restore is required, which is the worst possible time to discover them.

We run scheduled restore tests on a defined cadence and record how long each one takes against your agreed recovery targets, so the RTO and RPO figures in your DR plan are numbers we've actually measured, not numbers we've assumed. A rehearsal that misses its target is a fixable problem found on a Tuesday afternoon; the same gap found during a real outage is a fixable problem found while your business is offline. That difference is the entire point of testing before you need it.

Part of Backup & Disaster Recovery

Hardware fails, ransomware happens, people delete things. What separates an incident from a crisis is whether your data comes back — quickly, completely and provably. We build backup and disaster recovery on Acronis Cyber Protect, with recovery capacity on Replic8's primary and secondary Gaborone data centres, and we rehearse the restore so the first real test isn't the day you need it.

Also part of Backup & Disaster Recovery
Questions we hear about Backup & Disaster Recovery
Aren't backup and disaster recovery the same thing?

No — and the difference is measured in days of downtime. Backup answers "can we get the files back?"; disaster recovery answers "how fast is the business running again?". A company with perfect backups but no rehearsed recovery plan can still be down for a week waiting on hardware and guesswork. Backup is a component of DR, never a substitute.

What do RTO and RPO actually mean?

RPO is how much data you can afford to lose, counted backwards from the incident — it decides backup frequency. RTO is how long you can afford to be down, counted forwards — it decides the recovery architecture. There is no universal number: a nightly backup means up to a full day of invoices re-keyed. If that is unacceptable, the targets tighten and the design changes.

Microsoft 365 is in the cloud — isn't it already backed up?

No. Microsoft guarantees the service stays up; your data remains your responsibility — their own service agreement recommends third-party backup. Replication is not backup: a deleted or ransomware-encrypted file replicates as deleted or encrypted, and retention windows lapse. Independent Microsoft 365 backup is one of the cheapest risks to close.

How often should we test that backups actually restore?

Monthly spot restores, quarterly full-system restores, and at least one full disaster-recovery rehearsal a year — more for critical systems. Ransomware raises the bar: the test must prove your immutable copies survive and restore into a clean environment. A backup that has never been restored is a hope, not a plan — so we rehearse on schedule and keep the evidence.

Can we recover from ransomware without paying?

Yes — if immutable, off-site backup copies exist, your recovery point is recent enough, and the restore has been rehearsed in isolation. Paying is no guarantee: decryptors fail and the data has often already been stolen. Recovery-readiness is also now a cyber-insurance precondition, so the same work protects you twice.

Platforms: Acronis Cyber Protect · Replic8 Cloud · Microsoft 365 · Azure