Skip to content

Endpoint Protection & Backup

A backup nobody has restored is a hypothesis.

Two things account for most of the bad days: an endpoint that was three months behind on patches, and a backup that had been reporting success while writing nothing usable. Both are boring to fix and both are routinely deferred. This service is the discipline of doing them properly — patches applied on a known cadence, and restores rehearsed often enough that the first real one is not the first one.

Restores tested, with times recorded
RehearsedRestores tested, with times recorded
Including Microsoft 365 and cloud data
CoveredIncluding Microsoft 365 and cloud data
Patches meet a test group first
RingedPatches meet a test group first

Sounds like

You might recognise one of these.

  • We have backups, but I could not tell you the last time anyone restored from one.

  • Half the laptops are behind on updates and we find out when something breaks.

  • Our antivirus is whatever came with the machine.

  • If the office flooded tonight, I genuinely do not know how long we would be down.

What this includes

The work, specifically.

Not every engagement needs all of it. This is the range we cover and what each part is actually for.

  • Endpoint protection

    Managed detection on every device, configured and monitored, with alerts that reach a person rather than a dashboard nobody opens.

  • Patch management

    Operating system and third-party patching on a published cadence, with a ring order so an update meets a test group before it meets the whole company.

  • Backup and restore

    Backups covering endpoints, servers and cloud data — including Microsoft 365, which most organizations assume is backed up and is not.

  • Restore rehearsal

    Scheduled test restores against real data, with the time it took recorded. This is the deliverable; a green job status is not evidence.

  • Continuity planning

    What actually happens if a site, a server or an account is lost: the order of recovery, who does it, and how long it realistically takes.

What you get

Deliverables, not documents.

  • Managed protection deployed and monitored across the estate
  • A published patch cadence and ring order
  • Backup coverage mapped against what the business would need to keep running
  • Test-restore records with measured restore times
  • A written continuity plan, in recovery order

Shapes

How this usually runs.

  1. Backup and patch audit

    1–2 weeks

    What is protected, what is not, what the backups would actually restore, and how long it would take.

  2. Remediation

    2–6 weeks

    Closing the gaps the audit found, in the order of what would hurt most.

  3. Managed protection

    Ongoing

    Patching, monitoring, backup operation and scheduled restore rehearsals.

Tooling

What we build it with.

No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.

Protection
  • Managed endpoint detection and response
  • Disk encryption
  • Application control
Patching
  • OS and third-party patch management
  • Staged deployment rings
Backup
  • Endpoint and server backup
  • Microsoft 365 backup
  • Immutable offsite copies

Questions

Endpoints & backup, honestly.

  • Microsoft replicates your data for their availability, not for your recovery. Retention on a deleted mailbox or a purged site is finite, and a deletion that propagates is still a deletion. Their own service terms recommend third-party backup, which is the part most organizations discover after the fact.

  • On a schedule agreed with you and recorded with the measured time to restore. The number that matters is how long you would be down, and that is not knowable from a job status.

  • No, and the distinction is deliberate. This is operational hygiene — patching, protection, backups. Adversarial testing, compliance engineering and incident response are a separate practice with separate people; if you need those, the cybersecurity division is where that work is done properly rather than as an add-on here.

Next step

Tell us what’s breaking.

Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.