TL;DR
- “We have backups” is not a contract clause — demand RPO/RTO per system tier, last restore test date, and a named owner.
- Restore drills must produce a signed report you can show auditors, insurers, and your board — not a verbal “it worked”.
- Ask how backups behave in ransomware: immutability, air gap, separate credentials, and recovery without paying ransom first.
- If the vendor cannot explain restore time for your ERP or file service in plain language — treat backups as unproven.
A finance director asked us last month why their “fully managed” host could not produce a restore report newer than fourteen months. Backups ran nightly; dashboards showed green. During a ransomware tabletop, nobody knew whether the off-site copy was reachable without the compromised admin account. The contract mentioned “industry-standard backup” — which, in practice, meant a checkbox on a sales deck.
Backup is where managed IT deals often look cheapest and fail most expensively. This guide is for owners, CFOs, and IT leads who need to evaluate proposals without becoming backup engineers — but who still want evidence, not hope.
What “backup included” should mean in scope
Clarify what is backed up: operating system only, application data, databases with consistent snapshots, SaaS tenants, or virtual machines whole-stack. Clarify where copies live: same datacentre, partner site, object storage in another region, offline tape. Clarify who can delete or overwrite them — shared admin with production is a common failure mode.
Good scope documents list systems by name or tier, not “all servers”. They state retention (daily/weekly/monthly), encryption in transit and at rest, and whether you receive restore files directly or only through the provider.
RPO and RTO — written, tied to business systems
Recovery Point Objective (RPO) is how much data you can afford to lose — four hours of orders, one business day of finance postings. Recovery Time Objective (RTO) is how long restore may take before the business stops waiting.
Demand a small table in the contract or service description:
- Tier-1 (ERP, email, customer-facing apps): RPO ___ / RTO ___
- Tier-2 (internal tools, reporting): RPO ___ / RTO ___
- Tier-3 (archives, dev): RPO ___ / RTO ___
If the vendor gives one number for everything, they have not thought about your business. If they refuse to put numbers in writing, assume worst case.
Restore tests — the only proof that matters
Scheduled backups that never restore are inventory, not insurance. Ask:
- When was the last successful restore test for a client with similar size and stack?
- Who witnessed it — provider only, or customer too?
- How long did full restore take versus RTO?
- Is there a signed report or ticket export you can file?
Quarterly restore of at least one tier-1 system is a reasonable minimum for mid-market firms. Annual “we restored a random file” is not enough when ERP must come back whole.
Ransomware-specific questions
Modern incidents encrypt production and backups together. Before signing, ask:
- Are backup repositories immutable or WORM-protected for a defined window?
- Is there an air-gapped or offline copy on a schedule you can audit?
- Do backup credentials differ from domain admin and cloud tenant owner?
- What is the documented restore path if Active Directory or Entra ID is compromised?
Link this to your incident runbook — NIS2 and insurance questionnaires increasingly ask for backup integrity after attack, not just existence.
Red flags in proposals
“Unlimited retention” without storage cost model. Restore priced per hour with no cap. Backups stored only on the same SAN as production. No mention of database-consistent snapshots for SQL or PostgreSQL. “Cloud backup” that is really the same vendor’s second folder. Migration offered free but backup scope excluded from SLA.
One-page checklist before signature
- Scope list by system/tier with retention and encryption stated.
- RPO/RTO table signed or attached to SLA.
- Last restore test report (< 90 days for tier-1, or explain gap).
- Ransomware section: immutability, separate creds, AD recovery note.
- Named backup owner on provider side + escalation path.
- Exit clause: how you receive backup data if you leave.
What to do next
Pull your current contract and highlight every sentence that says “backup” without numbers. Request a restore drill on one non-critical system before renewal — or before migrating tier-1 workloads. Our Secure Public Cloud Infrastructure practice designs backup and restore with tested runbooks, not dashboard theatre — aligned with how auditors and regulators actually ask questions.
Want to discuss a project?
Contact usMore from this topic

Cloud RFP: How to Compare Three Vendors Without the Deck
Three proposals, three logos, zero comparability. A scoring matrix for mid-market firms: scope, SLA, restore proof, admin model,…

ERP Migration: When Cloud — and When to Stay On-Prem
“Move ERP to cloud” is not a strategy. Decision criteria for mid-market: downtime tolerance, integration with shopfloor, licensing,…

How to Choose Managed Cloud When You Have 50–200 Employees
You are past “a server in the office” but not ready for a 15-person platform team. A plain-language…


