Anyone can turn on backups. The real question is: have you ever done a restore and timed it? Most SMBs discover the answer on the worst possible day. We deploy on-prem backup, test the restore quarterly, and give you an RTO in minutes — not one the vendor made up.
You've got Windows File Server sitting in a closet with a NAS attached to it. Somebody set up a scheduled backup job in 2021. Green checkmarks show up on the Synology dashboard every night. Nobody has ever restored a file from it. That's not a backup — that's a hope.
Meanwhile, ransomware is now specifically designed to encrypt or delete local backups first before hitting production files. So even if your backup job is running, it might not actually be recoverable when you need it.
You need a backup solution that's tested, immutable, off-network from your production, and documented — not just a checkbox on your compliance form.
HOW WE FIX IT
01
Design for real recovery scenarios
What are you actually protecting against? Deletion (accidental or malicious), corruption, ransomware, hardware failure, site loss. Each requires different backup properties. We start with a written recovery matrix — what workloads, what RTO, what RPO, what threat model — before spec'ing hardware.
02
Deploy hardware appropriate to scale
For most SMBs: a NAS (Synology, QNAP) with dedicated backup software (Veeam, Synology Active Backup, Nakivo) is enough. For orgs with strict RTO or regulated workloads: a hybrid appliance (Datto SIRIS, Unitrends Recovery Series) that combines local + cloud + built-in ransomware detection. We size the storage, not the vendor.
03
Immutable + air-gapped
Backups written to WORM (write-once-read-many) storage or an S3-locked object store. Backup admin credentials separated from your regular Active Directory. Backup network segmented from production VLANs. Ransomware that reaches your file server can't reach the backup.
04
Restore-test quarterly
The core commitment. Every quarter we perform a real restore of a real workload to a staging environment, time it, and hand you a written report. If the RTO drifts, we investigate before the next disaster forces us to. This is what separates a real backup from an expensive false comfort.
Initial design + deployment is a project engagement. Ongoing operation (monitoring, alerts, quarterly restores) is either included in your managed plan or a small standalone monthly retainer.
Timeline
Design + deployment: typically 2-4 weeks for a single-site SMB. Multi-site or regulated environments: 4-6 weeks with more testing.
Rough cost
Hardware + software: usually $3-15k depending on total data volume and appliance tier. Our deployment fee: $4-10k for a typical SMB. Ongoing management: $400-800/month standalone; included at no extra cost in a managed plan.
QUESTIONS WE GET
Local backup vs cloud backup — which do we need?
Almost always both. Local is fast (restore a deleted file in seconds); cloud is safe (survives site loss). We usually deploy them together — see also our cloud backup page.
How often do you test restores?
Quarterly, minimum. For clients with strict RTOs (health, financial services), monthly. Restore tests are the single thing that separates real backup from a checkbox — we don't skip them.
What about ransomware protection?
Immutable snapshots (S3 Object Lock, ZFS snapshots, Datto's built-in), separated credentials, network segmentation. Layered so an attacker who gets domain admin can't also encrypt your backups.
Do you replace our existing NAS or work with it?
Depends on the NAS. Modern Synology / QNAP / TrueNAS with real spare CPU headroom is often fine — we add proper backup software and lock down the config. Old consumer-tier NAS or ones running end-of-life firmware get replaced.
What data volumes do you typically handle?
Sweet spot for local-backup engagements is 1TB - 20TB of protected data. Below that, cloud-only often makes more sense. Above 100TB we're into a different architecture.