it-service@brocent.com
Backup & Recovery
Protected workloads, job outcomes, recovery-point and recovery-time attainment, restore verification and immutable copy position for the August 2026 reporting period.
Backups are complete and tested; the offsite copy is the remaining single point of failure
All nine protected workloads met their recovery-point objective every day in the period. Of 341 scheduled jobs, 338 succeeded on first attempt and the remaining three succeeded on automatic retry, giving an effective success rate of 100% with a first-attempt rate of 99.1%. Two restore tests were performed and both met their recovery-time objective, including a full file-server volume restore completed in 3 hours 12 minutes against a four-hour target.
One material gap remains. The offsite copy is written to a single cloud bucket in the same region as the primary tenant, and only the file-server backup set is immutable; Microsoft 365 backups and the application server set can still be deleted by an administrator with the backup console credential. A ransomware event that captured that credential could remove both the primary and offsite copies of those sets.
Protection position at period end
Effective success counts a job as successful if it completed within its window including retries. First-attempt rate is reported alongside it because a persistent retry pattern is an early warning even when the outcome is good.
Four items require action
Evidence. Only the file-server set is written with an object-lock retention of 30 days. The Microsoft 365 set and the application-server set are stored without immutability, so the backup console credential can delete both the primary and the offsite copy.
Impact. Modern ransomware targets backup consoles before encrypting production. Without immutability the firm's recovery position depends entirely on one credential not being compromised, which is not a control.
Recommendation. Enable object-lock immutability with a 30-day retention on both remaining sets. Storage cost increases by approximately 12% because deleted blocks are held to term; BCS will confirm the figure with the September report.
Evidence. The offsite bucket and the Microsoft 365 tenant are both hosted in the same regional pair. There is one copy offsite, not two, and no copy on separate media or in a separate provider.
Impact. A regional outage or a provider-account compromise affects production and backup together, so the 3-2-1 principle the service description references is not actually satisfied.
Recommendation. Replicate the immutable copy to a second region in a separate provider account with its own credentials. Estimated incremental cost is modest at 6.8 TB; BCS will quote with the immutability change.
Evidence. The application server is backed up at volume level, but there is no written procedure for rebuilding the market-data application, re-establishing its vendor feed, or validating that prices are correct after restore.
Impact. A volume restore returns files but not a working trading capability. Recovery time in a real event would exceed the four-hour objective because the sequence would be improvised.
Recommendation. Document the application recovery runbook with the vendor, then validate it in the Q4 restore test rather than testing the volume alone.
Evidence. Three incremental jobs failed on first attempt with a snapshot timeout on the NAS, on 2026-08-05, 08-19 and 08-26. All succeeded on retry within the same window. The pattern coincides with the weekly integrity scan.
Recommendation. Move the NAS integrity scan two hours later so it no longer overlaps the backup window, then confirm three clean weeks.
The July finding that only mailboxes were protected in the tenant is closed. OneDrive for all 41 users and all SharePoint sites entered protection on 2026-08-04, adding 0.4 TB. First full backup completed 2026-08-06 and daily incrementals have run clean since.
Five of five service levels met
| Committed service level | Target | Actual | Status | Note |
|---|---|---|---|---|
| Recovery point objective | ≤ 12 hours | 6.5 h worst | MET | 31 of 31 days, all workloads |
| Recovery time objective | ≤ 4 hours | 3 h 12 m | MET | Verified by restore test |
| Job success within window | ≥ 99% | 100% | MET | 341 jobs, 3 retries |
| Restore test cadence | ≥ 1 per month | 2 tests | MET | File volume and mailbox |
| Monthly report issued | By 5th working day | 3rd working day | MET | Issued 2026-09-03 |
Three-period movement
| Metric | Jun 2026 | Jul 2026 | Aug 2026 | Direction of travel |
|---|---|---|---|---|
| Workloads protected | 6/9 | 7/9 | 9/9 | Complete after OneDrive and SharePoint onboarding. |
| First-attempt job success | 97.2% | 98.4% | 99.1% | Improving; residual failures are the NAS snapshot overlap. |
| Protected data | 6.1 TB | 6.4 TB | 6.8 TB | Growing about 5% per period, within the storage plan. |
| Restore tests | 1 | 1 | 2 | Cadence increased ahead of the Q4 full-server test. |
| Immutable sets | 1/3 | 1/3 | 1/3 | No movement; awaiting cost approval. |
| Worst RPO gap | 9.1 h | 7.8 h | 6.5 h | Improving as the incremental schedule tightened. |
All three retries were the same NAS source on consecutive Wednesdays, which is why they are reported as a pattern rather than as isolated failures.
Protected workloads
| Workload | Type | Size | Schedule | RPO | Retention | Immutable | Last good copy |
|---|---|---|---|---|---|---|---|
| ACM-SRV-01 | File server | 1.9 TB | Hourly incr. | 1 h | 90 d | YES | 2026-08-31 23:00 |
| ACM-SRV-02 | App server | 0.8 TB | Daily 01:00 | 12 h | 60 d | NO | 2026-08-31 01:34 |
| ACM-NAS-01 | NAS shares | 2.4 TB | Daily 02:00 | 12 h | 90 d | YES | 2026-08-31 02:41 |
| M365 mail | 41 mailboxes | 0.9 TB | 4× daily | 6 h | 7 yrs | NO | 2026-08-31 22:00 |
| M365 OneDrive | 41 accounts | 0.4 TB | Daily 03:00 | 12 h | 7 yrs | NO | 2026-08-31 03:22 |
| M365 SharePoint | 6 sites | 0.3 TB | Daily 03:30 | 12 h | 7 yrs | NO | 2026-08-31 03:58 |
| Cloud VM 01 | Cloud server | 0.1 TB | Daily snapshot | 12 h | 30 d | NO | 2026-08-31 04:00 |
| Cloud DB | Managed DB | 0.02 TB | Continuous | 5 m | 35 d | PITR | 2026-08-31 23:55 |
| Endpoints | 35 computers | — | OneDrive sync | 12 h | 7 yrs | VIA M365 | 2026-08-31 03:22 |
Endpoints hold no unique data by policy: user documents live in OneDrive and are protected there. The three backup sets referred to in the findings are the on-premises set, the Microsoft 365 set and the cloud set.
Restore verification
| Test | Date | Scope | Target | Actual | Validation performed |
|---|---|---|---|---|---|
| File server volume | 2026-08-09 | 1.9 TB share | 4 h | 3 h 12 m | Restored to isolated host; 200-file checksum sample compared; permissions verified. |
| Mailbox point-in-time | 2026-08-23 | 1 mailbox, 30 days back | 1 h | 22 m | Items compared against the live mailbox; calendar and rules confirmed intact. |
| Application server | Q4 planned | Full server | 4 h | — | Deferred until the recovery runbook exists — see finding. |
A restore test only counts as passed when data is restored to a separate location and validated against a defined check. A job that reports success without validation is not evidence of recoverability.
Restore requests handled
| Ticket | Date | Request | Elapsed | Outcome |
|---|---|---|---|---|
| SR-4471 | 2026-08-06 | Deleted folder, 3 days back | 18 m | Restored in place; user confirmed. |
| SR-4488 | 2026-08-14 | Overwritten spreadsheet version | 9 m | Prior version recovered from OneDrive history. |
| SR-4502 | 2026-08-21 | Mailbox items after rule error | 41 m | 112 items restored to the original folder. |
| SR-4519 | 2026-08-28 | Leaver mailbox export for HR | 1 h 26 m | PST delivered to HR through the secure share. |
Open items carried between periods
| Ref | Risk | Severity | Owner | Due | Status | Next action |
|---|---|---|---|---|---|---|
| BKUP-R01 | Backup sets deletable by a single credential — 2 of 3 sets not immutable | HIGH | Client COO | 2026-09-30 | Open | Approve the storage cost; BCS to enable 30-day object lock. |
| BKUP-R02 | Single offsite region — 3-2-1 not satisfied | HIGH | Client COO | 2026-10-31 | Open | Approve second-region replication in a separate provider account. |
| BKUP-R03 | No application recovery runbook — RTO not achievable in a real event | MEDIUM | BCS + Client IT | 2026-11-30 | Open | Draft the runbook with the vendor; validate in the Q4 test. |
| BKUP-R04 | No annual full disaster-recovery exercise — component tests only | MEDIUM | Client COO + BCS | 2026-12-31 | Open | Schedule a tabletop plus technical failover exercise for Q4. |
| BKUP-R05 | NAS snapshot window overlap — recurring first-attempt failures | LOW | BCS Support Center | 2026-09-30 | In progress | Move the integrity scan two hours later; confirm three clean weeks. |
Next period commitments
| BCS Support Center will | Client is asked to |
|---|---|
| Quote immutability and second-region replication as one costed change. | Approve the incremental storage cost for immutable copies. |
| Reschedule the NAS integrity scan and confirm three clean backup weeks. | Confirm the recovery-time expectation for the market-data application. |
| Draft the application recovery runbook with the vendor. | Nominate a date for the Q4 disaster-recovery exercise. |
| Continue monthly restore tests and report validation evidence. | Confirm the 7-year retention remains correct for Microsoft 365 data. |
How this report was produced
| Source | Extracted | Records | Used for |
|---|---|---|---|
| Backup platform job log | 2026-09-01 01:30 HKT | 341 jobs | Outcomes, retries, durations, last good copy per workload. |
| Microsoft 365 backup console | 2026-09-01 01:40 HKT | 3 workloads | Mail, OneDrive and SharePoint protection state and retention. |
| Object storage configuration | 2026-09-01 02:00 HKT | 3 buckets | Immutability, retention lock, region placement. |
| Restore test records | 2026-08-23 | 2 tests | Recovery time and validation evidence. |
| Service desk tickets | 2026-08-31 | 4 restores | User restore requests and elapsed time. |
Method and definitions
Recovery point objective is the maximum acceptable age of the most recent recoverable copy. Attainment is measured daily per workload; a single day where any workload exceeded its RPO would fail the whole month, which is why the worst observed gap is reported rather than an average.
Recovery time objective is only reported from an actual restore test, never from a vendor estimate or a calculation. Where no test has been performed the field reads as pending, as it does for the application server this period.
Immutability means the backup copy cannot be deleted or altered before its retention expires, by any credential including the backup administrator's. Versioning and soft-delete are not immutability and are not counted as such.
Exclusions. Endpoint local drives are out of scope by policy — user data resides in OneDrive. Market-data vendor archives held on the vendor's platform are outside the backup service. Backup infrastructure availability is reported in the Availability Monitoring report.
This copy is an anonymised sample prepared for illustration. The client name, server names, share names, ticket references and vendor names have been replaced with fictitious or generic values; volumes, ratios, dates and findings reflect a representative managed estate. No real client data appears in this document.
BCS Support Center · it-service@brocent.com
Questions clients ask about this report
No, and this is the most important distinction in the report. A recovery-time objective is only reported from an actual restore to a separate location, validated against a defined check. A job that reports success without a restore test is not evidence of recoverability.
An immutable copy cannot be deleted or altered before its retention expires, by any credential including the backup administrator's. Ransomware targets backup consoles first, so versioning and soft-delete are not counted as immutability in our reporting.
Component restores are tested monthly and reported here. A full disaster-recovery exercise combining a tabletop and a technical failover is scheduled annually, and the report tracks it as an open item until it is done.
See what your own Backup & Recovery report would say
A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.