Endpoint Protection & Backup
A backup nobody has restored is a hypothesis.
Two things account for most of the bad days: an endpoint that was three months behind on patches, and a backup that had been reporting success while writing nothing usable. Both are boring to fix and both are routinely deferred. This service is the discipline of doing them properly — patches applied on a known cadence, and restores rehearsed often enough that the first real one is not the first one.
- Restores tested, with times recorded
- RehearsedRestores tested, with times recorded
- Including Microsoft 365 and cloud data
- CoveredIncluding Microsoft 365 and cloud data
- Patches meet a test group first
- RingedPatches meet a test group first
Sounds like
You might recognise one of these.
We have backups, but I could not tell you the last time anyone restored from one.
Half the laptops are behind on updates and we find out when something breaks.
Our antivirus is whatever came with the machine.
If the office flooded tonight, I genuinely do not know how long we would be down.
What this includes
The work, specifically.
Not every engagement needs all of it. This is the range we cover and what each part is actually for.
Endpoint protection
Managed detection on every device, configured and monitored, with alerts that reach a person rather than a dashboard nobody opens.
Patch management
Operating system and third-party patching on a published cadence, with a ring order so an update meets a test group before it meets the whole company.
Backup and restore
Backups covering endpoints, servers and cloud data — including Microsoft 365, which most organizations assume is backed up and is not.
Restore rehearsal
Scheduled test restores against real data, with the time it took recorded. This is the deliverable; a green job status is not evidence.
Continuity planning
What actually happens if a site, a server or an account is lost: the order of recovery, who does it, and how long it realistically takes.
What you get
Deliverables, not documents.
- Managed protection deployed and monitored across the estate
- A published patch cadence and ring order
- Backup coverage mapped against what the business would need to keep running
- Test-restore records with measured restore times
- A written continuity plan, in recovery order
Shapes
How this usually runs.
Backup and patch audit
1–2 weeksWhat is protected, what is not, what the backups would actually restore, and how long it would take.
Remediation
2–6 weeksClosing the gaps the audit found, in the order of what would hurt most.
Managed protection
OngoingPatching, monitoring, backup operation and scheduled restore rehearsals.
Tooling
What we build it with.
No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.
- Protection
- Patching
- Backup
Questions
Endpoints & backup, honestly.
Microsoft replicates your data for their availability, not for your recovery. Retention on a deleted mailbox or a purged site is finite, and a deletion that propagates is still a deletion. Their own service terms recommend third-party backup, which is the part most organizations discover after the fact.
On a schedule agreed with you and recorded with the measured time to restore. The number that matters is how long you would be down, and that is not knowable from a job status.
No, and the distinction is deliberate. This is operational hygiene — patching, protection, backups. Adversarial testing, compliance engineering and incident response are a separate practice with separate people; if you need those, the cybersecurity division is where that work is done properly rather than as an add-on here.
Often paired with
Next step
Tell us what’s breaking.
Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.