
Data protection and disaster recovery
Backups only count if a restore has been proven — so we prove it, on a schedule.
- Practice area
- Security and resilience
- Primary platform
- Veeam
- Usually sponsored by
- IT managers
- Delivered from
- Accra, Ghana
Recovery objectives agreed per system, engineered, and then proven by scheduled restore tests.
Veeam-backed backup for workloads and Microsoft 365, with recovery that has been tested rather than assumed.
Why organisations ask for this work
These are the situations that lead to this conversation. If more than one is familiar, there is usually a case worth examining before anything is bought.
Backups that have never been restored
Jobs report success, but no one has proven the data comes back in a usable state.
The last copy is reachable from production
Backup repositories sit on the same network an attacker would already have compromised.
Microsoft 365 assumed to be covered
Native retention is mistaken for organisational backup, leaving deletion and ransomware gaps.
What this service covers
Almost every organisation has backups. Considerably fewer have restores. The distinction becomes painfully clear during an incident, when a job has been silently failing for weeks, retention was shorter than anyone believed, or the backup repository sits on the same network the ransomware just encrypted.
We design data protection backwards from recovery. What must be running again within an hour, and what can wait until tomorrow? How much data loss is genuinely tolerable for each system? Those answers — recovery time and recovery point objectives — determine the architecture, not the other way round.
Microsoft 365 deserves specific attention. Microsoft guarantees the availability of its service, not the recoverability of your organisation's content after deletion, malicious action, or a retention gap. Native controls help; they are not equivalent to a backup you control and can restore from independently.

Workload backup
Physical servers, virtual machines, and business-critical applications protected to a documented policy.
Microsoft 365 protection
Exchange Online, SharePoint, OneDrive, and Teams data retained beyond native recycle bin windows.
Disaster recovery design
Recovery objectives agreed per system, then engineered — including secondary site or cloud failover where warranted.
Ransomware-resilient architecture
Immutable and air-gapped copies so an attacker who reaches production cannot destroy your last good copy.
Restore testing
Scheduled recovery drills with documented results, because an untested backup is an assumption.
Retention and compliance policy
Retention aligned to obligations and appetite, without unbounded storage growth.
What you receive, and what changes
Every engagement produces written artefacts. They are listed here so the scope is agreed before work starts rather than interpreted afterwards.
Artefacts you receive
- Recovery objectives register covering every protected system
- Backup architecture design and implementation
- Immutability and offsite copy configuration
- Restore test schedule with evidence of successful recovery
- Monthly protection reporting with failure follow-up
Outcomes to expect
- Documented, agreed recovery objectives instead of vague expectations
- A last good copy an attacker cannot reach
- Restore capability proven on a schedule, not discovered during a crisis
- Backup failures noticed and fixed within days, not months
How delivery runs
Each phase has a defined entry and exit point, so you always know what is being decided, by whom, and what happens next.
Define objectives
Recovery time and recovery point targets agreed per system with business owners.
Design protection
Repositories, schedules, retention, immutability, and offsite copies specified to meet those targets.
Implement and verify
Deployment followed by an initial restore test to prove the design end-to-end.
Operate and drill
Ongoing monitoring, failure remediation, and periodic recovery drills with written outcomes.
The technology this service touches
Platform choice follows the workload. These are the products most often involved in this practice area, and the vendor relationships behind them.
- Veeam
- Microsoft 365
- Azure
- VMware
Accredited means AAG Cloud Connect holds that vendor’s partner mark. Capability means we design, deliver, and support the platform without holding a formal partner designation for it. Both are stated plainly so nothing is implied by a logo.
Microsoft
Accredited partnerCloud platforms
The centre of our practice. We hold the Cloud Solution Provider relationship, so subscriptions, licensing advice, and first-line escalation sit with us.
VMware
Accredited partnerInfrastructure
Virtualisation for hybrid estates, including consolidation of ageing physical infrastructure onto supportable platforms.
Veeam
Delivery capabilityBackup and recovery
The backbone of our data protection work across on-premises, cloud, and Microsoft 365 workloads.
Who this service is for
Work of this kind is normally sponsored by one of a small number of roles, each of whom is measured on something different.
- IT managers
- Risk and compliance leads
- Finance directors
CIOs and IT managers
You need architecture that your team can actually run, vendors consolidated, and a partner who escalates instead of deflecting.
CFOs and finance leaders
You need licence spend that reconciles, renewals without surprises, and a cost model you can defend in a budget review.
Risk and compliance leads
You need identity controls, retention policies, and recovery evidence that stand up to an audit.
Quarterly
restore testing
An untested backup is an assumption
Recovery time and recovery point objectives are agreed with business owners per system, then the architecture is designed to meet them — including immutable copies that cannot be altered within their retention window even with compromised administrative credentials. Critical systems are restore-tested at least quarterly, with written results.
This describes an engagement pattern typical of this service. It is not an account of a named client, and no figures here are drawn from a specific organisation.
Frequently asked
The questions organisations genuinely ask before committing budget to this work.
Microsoft protects the availability of the service and provides limited native retention. It does not provide a full organisational backup: accidental and malicious deletion, retention gaps, and ransomware scenarios still require a backup you control independently.
Recovery point objective is how much data you can afford to lose, measured in time. Recovery time objective is how quickly a system must be usable again. Both are business decisions with cost implications, which is why we agree them with owners rather than assuming.
Critical systems at least quarterly, and after any significant infrastructure change. A full disaster recovery drill annually is a reasonable minimum for most mid-sized organisations.
It does not stop the attack, but it protects your ability to recover from it. Immutable copies cannot be altered or deleted within their retention window, even with compromised administrative credentials.
Yes. Hybrid protection — on-premises workloads with cloud or secondary-site copies — is one of the most common designs we deliver.
Related services
These practice areas are commonly delivered alongside this one, because the gaps between them are where problems tend to appear.
Cybersecurity and compliance
Measurably reduced exposure, starting with identity — where most incidents actually begin.
View serviceInfrastructure and hardware
Platforms sized against measured workload, procured through authorised channels, with a refresh plan agreed up front.
View serviceManaged services and support
A named owner for your environment, with published severity-based response targets and a monthly review that drives change.
View service
Talk to us about Backup & DR
Send a short brief on where you are now with Backup & DR. You will get a considered response setting out what we would need to establish next, rather than a generic brochure.
Your enquiry will be tagged Backup & DR so it reaches the right specialist first time.
