This page is written from the far end of the subject. There is no backup product for sale here — this is the bench the disks turn up at once a plan has been tried and found wanting, which is an unusually honest place to write about backup from.
Start with the disclosure, because it decides what the rest of this is worth. This is a recovery laboratory and not a backup provider. There is no contract to sign, no cloud storage to rent, no agent to install, no monitoring, no continuity retainer and nothing at all to subscribe to. Designing and running backup belongs with an IT provider who understands your systems, and if nobody currently holds that job, closing that gap comes before anything written below. What sits on this bench is the opposite view of the same subject: whatever turns up once the arrangements have already been tried, along with a reasonably dependable sense of which of those outcomes could have been headed off.
Two numbers do most of the useful work in this subject and neither of them is technical. The first is how much work you can afford to lose — an hour, a day, a week. That number alone decides how often a backup has to run, and it is why a nightly job is fine for a document archive and useless for an order system. The second is how long you can afford to be stopped, which decides what the recovery has to look like: restoring 2 TB over a domestic broadband connection is a perfectly good backup and a hopeless disaster recovery plan if the business cannot trade for three days. Backup answers the first number. Disaster recovery answers the second, and it is a decision made calmly in advance so nobody has to make it at four o'clock on a very bad afternoon.
Sorted by mechanism rather than by industry, almost everything that lands on this bench is one of five things. An array nobody was monitoring, where a disk failed months ago into a report nobody read and the second failure was the one that stopped the business. A single copy living on the machine that makes the money — a workstation in the corner of a workshop holding calibration records, test results and drawing archives that exist nowhere else. A backup that ran faithfully for years and had never once been restored from, so nobody knew until the morning it mattered that it had been writing an empty set since spring.
Then the two that people argue about. A sync folder mistaken for a backup, which copies a deletion, an overwrite or an encryption run to the other end within seconds and does it perfectly. And the archive that outlived its own hardware — closed matters, old projects, historic drawings on a server that has been replaced twice, migrated by copying the volume across each time until nobody is quite sure what the original was.
The Berkshire version of this is mostly a question of who ends up holding the storage. Across the estates on the A329(M) and Western Road, and among the firms spread along the M4 towards Reading and Slough, a great many important systems were chosen years ago for a smaller job and quietly became indispensable without a decision ever being taken. Workshop machines in the engineering and electronics units around Bracknell Forest hold records that exist nowhere else. Professional practices run modern live systems alongside an archive that has never been migrated. A failed back-office box in the hotels and venues around Ascot and Windsor takes bookings and till history with it. Practices near Wokingham and Crowthorne find their retention duties running longer than the equipment holding the records. Very little of this is negligence. It is the predictable result of the same person producing the data, minding the data, and working to a deadline that has nothing to do with either.
If one thing survives from this page, make it the 3-2-1 arrangement, because it is the shortest accurate description of a backup that works. Three copies of anything you cannot lose, on two different kinds of media, with one of them off site. Three copies means the live data plus two backups, not the live data plus one. Two kinds of media means the second copy does not share a box, an array or a controller with the first, so that one power event or one failed unit cannot take both. One off site means somewhere genuinely else — a disk that leaves the building in rotation, or reputable cloud storage — so a fire, a flood or a burglary at one address is not the end of the story.
The three mistakes are consistent enough to list. Counting a sync as one of the copies, when it is really a second live copy with the same exposure as the first. Keeping the off-site copy permanently mounted and writable from the office, which makes it off site in geography and not in risk — a copy nothing can write to is worth several that anything can. And keeping every copy online, when anything that would genuinely stop the business deserves at least one that is unplugged and sitting in a safe. Immutability, air gaps and offline rotation are three routes to the same destination, which is a copy that a bad afternoon on the network cannot reach.
Then prove it, on a schedule, and time the exercise. Pull one real file back out once a quarter and open it. Once a year, restore a whole system to spare hardware and put a stopwatch on it, because that figure — not the plan on paper — is how long your firm is actually down. Write down the rest of it while you are there: what comes back first, in what order, who authorises the decision and who has to be told. A good half of what an incident costs is people waiting to be given permission.
Shut the affected system down rather than letting it grind on, and do not start a rebuild or let one that is already running continue. An array rebuilding onto a disk that is itself failing is the most dependable way there is of turning a recoverable set into an unrecoverable one, because the rebuild reads every sector of every surviving member at full tilt, which is exactly the workload that finishes off a tired disk. Mark each disk with the bay it came out of before anything is moved — write it on the disk with a marker, not on a label that will fall off in transit — because that map is worth real money later and it evaporates the moment somebody tidies the set into a box.
Then ring 0800 689 0668, Mon–Fri 9:00am–5:30pm, and lead with what the business can no longer do rather than with a description of the hardware. That call is what puts the job in front of an engineer the moment the parcel is opened, instead of leaving it to work through a queue. Send storage and not furniture: the disks, not the rack or the chassis. Tracked, insured post reaches Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford, GU2 8XH the next working day from anywhere in Berkshire, and reception takes hand deliveries Mon–Fri 9:00am–5:30pm if somebody would rather drive it — about eighteen miles and forty minutes from Bracknell on the A322 and the A3. Nothing is collected anywhere on this network, so no part of a recovery waits on a van.
Every disk is imaged individually before anything is reconstructed, so no stage of the work is ever carried out on a live array. The diagnostic is free and closes 2 working days after the media is booked in, and the fixed written figure arrives before any chargeable work begins: arrays, NAS boxes, SANs and servers from £500 + VAT, a single server disk or SSD £300 + VAT. Bring your own IT people into it wherever you can; the work tends to run more smoothly with them involved, since the sequence a rebuild has to follow is their territory and getting readable data off dead hardware is ours.
Until somebody has pulled a real file back out of it and opened it, a backup is a claim rather than a copy. Test one file every quarter and one full system every year, and put a stopwatch on the second exercise — that number, not the plan on paper, is how long your firm is genuinely off the air.
Free diagnostic closing 2 working days after your device is booked in, one fixed written quote, and no fix, no fee on logical faults. Cards and USB sticks £250 + VAT, any single drive or SSD £300 + VAT.