Microsoft 365 and server backup, tested restores, and a written disaster recovery plan — so the worst day is an inconvenience, not an ending.
Backup is keeping independent, restorable copies of your data — email, documents, servers — outside the systems that could lose them. Disaster recovery is the written, tested plan for getting your firm working again after ransomware, deletion, hardware failure, fire, or outage: what gets restored first, by whom, and how fast. The two are only as good as the last restore you actually tested — an untested backup is a hope, not a plan.
nicwerks® builds and runs backup and disaster recovery for Los Angeles law firms, financial practices, and entertainment companies — including the Microsoft 365 data most firms wrongly assume Microsoft is backing up for them.
Independent backup of Exchange, SharePoint, OneDrive, and Teams — because Microsoft's retention policies are not a backup, and its shared-responsibility model says so.
On-premises servers and key workstations protected with versioned, encrypted backups — sized to how much data your firm can actually afford to lose.
Scheduled restore tests with documented results — the difference between believing your backups work and knowing they do.
A plain-English plan naming priorities, owners, and recovery-time targets — the document your insurer asks about and your worst day depends on.
Immutable, separated backup copies that ransomware can't encrypt along with the originals — restoring clean data is the alternative to paying.
When something is deleted, corrupted, or encrypted, we run the restore — from a single email to a full system — and report exactly what came back.
As part of Encurio's FTC Safeguards compliance work, nicwerks drafted the piece most firms skip: a written disaster recovery plan, refined over working review sessions alongside the firm's WISP and privacy policies. Backup coverage, restore priorities, and responsibilities were put on paper before any incident could force the question.
That's the pattern we bring to every client: backup that's independent of the systems it protects, restores that get tested on a schedule, and a plan your team has read before the day it's needed.
A firm that has never tested a restore; a practice assuming Microsoft backs up its 365 data; a business whose insurer is asking about backup and recovery plans; or anyone whose current answer to “how fast could we be back up?” is a guess.
You want the cheapest checkbox backup with no testing or plan — untested backup is the one product we won't sell you, because it fails exactly when you need it.
No — this is the most expensive misconception in small-firm IT. Microsoft keeps your services running; under its shared-responsibility model, protecting and restoring your data is your job. Retention policies can't roll back ransomware or a bad sync.
With immutable backups and a tested plan: hours to days depending on scope, and defined in writing as a recovery-time objective you've agreed to — not discovered mid-crisis. Without them, weeks — or a ransom negotiation.
File-level restores at least quarterly, fuller recovery scenarios annually — and always after major system changes. Every test is documented, which doubles as evidence for insurers and compliance reviews.
What systems get restored in what order, who does what, how you communicate while systems are down, recovery-time and data-loss targets, and where the backups live. Ours are plain-English documents your team can follow under stress — not binders.
Book a free backup & recovery review — we’ll check coverage, test status, and your real recovery timeline.