SERVICE
Backup & Business Continuity
Ransomware-proof backups and recovery plans that actually work.
Why Your Current Backup Isn't Enough
Most Singapore businesses have backups. They're usually just snapshots: daily copies of data stored somewhere. This protects against hardware failure. It doesn't protect against ransomware, which encrypts your backups as quickly as it encrypts your live data. A traditional backup is useless if the attacker has access to the same storage.
Ransomware attacks on Singapore businesses cost real money—not just in ransom demands, but in downtime, lost productivity, and reputational damage. Singapore logged 21M+ cyberattacks in 2024 (highest in Southeast Asia according to CSA). Ransomware is a top threat for medium and large businesses.
Real backup is different: immutable copies (can't be encrypted, modified or deleted even by an attacker), offsite (on a completely separate system accessible only with specific credentials), and tested regularly (so you know recovery actually works, not just theoretically).
Immutable & Offsite Backup Architecture
Immutable backups are write-once, never-modify-or-delete. An attacker with admin credentials still can't encrypt them. We implement this using backup appliances (Veeam, Commvault, Rubrik) that support immutable snapshots, combined with offsite replication. The onsite backup helps with quick recovery. The offsite immutable copy survives ransomware attacks, regional disasters, even the loss of your entire data centre.
Immutable doesn't mean slow. Modern backup appliances replicate immutable snapshots continuously—you can recover to within minutes of the attack, not days. We design backups that balance fast recovery (RTO) with cost, because offsite immutable copies are expensive and every organization has a budget.
Disaster Recovery Drills That Actually Matter
Having a disaster recovery plan that's never tested is fantasy. Untested plans fail when you need them. We run DR drills regularly: we actually fail over to your recovery site, restore your data, spin up applications, and verify they work. This isn't simulation—it's a real test using real recovery procedures.
We also vary the drill: sometimes you're recovering from ransomware (restore from immutable offsite backups only), sometimes from natural disaster (recover to cloud), sometimes from a data centre fire (activate your geographically separate backup). Each scenario tests different muscles.
After each drill, we document what worked and what needs improvement. Over time, your recovery becomes faster and more reliable because you've practised it.
RTO/RPO Engineering: Recovery Speed Where It Matters
RTO (Recovery Time Objective) is how quickly you need to be back running. RPO (Recovery Point Objective) is how much data loss you can tolerate. A bank might need an RTO measured in hours and an RPO measured in minutes. A small office might tolerate a full day of RTO and RPO.
Higher RPO and RTO is cheaper—you need fewer backup replicas, less offsite infrastructure, less testing. We help you define realistic targets based on your actual business impact, then design backup and recovery infrastructure that hits those targets.
We also engineer recovery for specific systems: your ERP might need a short RTO (critical for business), your email a longer one (annoying but survivable), your corporate website the longest (can run on cached content while you recover). One-size-fits-all recovery is wasteful.
Ransomware-Proof Backup Strategy
Ransomware attacks work by encrypting your data and demanding payment for a decryption key. Paying ransom is a terrible idea (funds criminal organizations, doesn't guarantee recovery, signals to attackers that you're an easy target). The only real defence is immutable backups—data the attacker cannot encrypt.
A ransomware-proof strategy has multiple layers: immutable backups (so you can recover without paying), segmentation (so ransomware can't spread from one system to your entire infrastructure), monitoring (so you catch attacks early), and incident response (so you know exactly what to do when ransomware hits). None of these alone is sufficient; together they make you an unattractive target.
We also advise on air-gapped backups—backup systems that are physically disconnected from your network, connected only long enough to receive new snapshots, then disconnected again. An attacker on your network cannot reach an air-gapped backup. This is the gold standard for critical data.
Business Continuity Planning & Documentation
Backup is one piece of business continuity. A complete BCP covers: critical business processes, their dependencies, recovery procedures for each system, alternate work locations if your office is unavailable, communication chains so everyone knows what to do during a crisis, and training so the plan isn't just a document in a drawer.
We develop BCPs that are actually used, not shelved. That means involving the people who own each business process, keeping the plan current as systems change, and running regular drills. We also integrate BCP with your incident response and security policies—when something goes wrong, you have a playbook.
Recovery Documentation & Audit Readiness
Regulators and auditors want evidence that you can recover. That means detailed documentation: which backups are immutable, where they're stored, who can access them, how often they're tested, what RTO/RPO they support. We maintain this documentation systematically—your backup system generates recovery test reports, we track changes to your infrastructure, and we provide audit-ready reports showing your resilience posture.
For companies subject to PDPA, MAS TRM (if financial services), or ISO 27001, this documentation is mandatory. For everyone else, it's just smart risk management.
Backup Cost Optimization
Backup costs can spiral: every system gets backed up, replicated offsite, tested, held for years "just in case." A lot of this is waste. You probably don't need years of email retention. Your development database doesn't need to be backed up at all (it can be rebuilt). We help you right-size: backup what's critical, delete the rest on schedule, use cheaper storage tiers for older backups.
Deduplication (backup software recognizing that most of your backup is identical across snapshots and storing only the differences) can reduce backup storage dramatically. We implement this as standard.
How much would it cost to recover from a complete data loss?
A complete data loss (database corrupted, all backups destroyed) is catastrophic and might not be fully recoverable—you'd rebuild from archives and memory. The cost is often your entire business if you can't operate without the data. That's why immutable offsite backups matter. A ransomware attack where you recover from immutable backups costs a fraction of what paying ransom (and still not getting your data back) can cost, plus you're not funding crime.
Do we really need to test disaster recovery regularly?
Yes, on a regular cadence — at minimum quarterly, with critical systems (your ERP, your payment systems) tested more often. Untested backups fail when you need them most. We've seen companies confident their backups worked, then unable to recover because the backup tape got damaged during storage, or the restore procedure never actually worked. Testing finds these failures before disaster.
What do we do during a ransomware attack?
Isolate affected systems immediately (unplug from the network), preserve evidence (don't try to clean up or delete malware files), contact your incident response team (us or your internal team), notify your cyber insurance provider, and begin recovery from immutable backups. Do NOT pay ransom. Do NOT restore from potentially compromised backups. The attacker is counting on panic—having a tested plan and practiced response prevents poor decisions.