{"id":10181,"date":"2026-08-31T08:51:22","date_gmt":"2026-08-31T06:51:22","guid":{"rendered":"https:\/\/qdata.pl\/blog\/backup-restore-what-to-demand-before-you-sign\/"},"modified":"2026-08-31T08:51:22","modified_gmt":"2026-08-31T06:51:22","slug":"backup-restore-what-to-demand-before-you-sign","status":"publish","type":"post","link":"https:\/\/qdata.pl\/pl\/blog\/backup-restore-what-to-demand-before-you-sign\/","title":{"rendered":"Backup i odtwarzanie: co wymaga\u0107 przed podpisaniem umowy"},"content":{"rendered":"<div class=\"qdata-blog-tldr\">\n<h3>TL;DR<\/h3>\n<ul>\n<li>\u201cWe have backups\u201d is not a contract clause \u2014 demand <strong>RPO\/RTO per system tier<\/strong>, last restore test date, and a named owner.<\/li>\n<li>Restore drills must produce a <strong>signed report<\/strong> you can show auditors, insurers, and your board \u2014 not a verbal \u201cit worked\u201d.<\/li>\n<li>Ask how backups behave in <strong>ransomware<\/strong>: immutability, air gap, separate credentials, and recovery without paying ransom first.<\/li>\n<li>If the vendor cannot explain restore time for your ERP or file service in plain language \u2014 treat backups as unproven.<\/li>\n<\/ul>\n<\/div>\n<p>A finance director asked us last month why their \u201cfully managed\u201d host could not produce a restore report newer than fourteen months. Backups ran nightly; dashboards showed green. During a ransomware tabletop, nobody knew whether the off-site copy was reachable without the compromised admin account. The contract mentioned \u201cindustry-standard backup\u201d \u2014 which, in practice, meant a checkbox on a sales deck.<\/p>\n<p>Backup is where managed IT deals often look cheapest and fail most expensively. This guide is for owners, CFOs, and IT leads who need to evaluate proposals without becoming backup engineers \u2014 but who still want evidence, not hope.<\/p>\n<h2>What \u201cbackup included\u201d should mean in scope<\/h2>\n<p>Clarify <em>Co blokuje indeksacj\u0119 albo rozwadnia autorytet<\/em> is backed up: operating system only, application data, databases with consistent snapshots, SaaS tenants, or virtual machines whole-stack. Clarify <em>where<\/em> copies live: same datacentre, partner site, object storage in another region, offline tape. Clarify <em>who<\/em> can delete or overwrite them \u2014 shared admin with production is a common failure mode.<\/p>\n<p>Good scope documents list systems by name or tier, not \u201call servers\u201d. They state retention (daily\/weekly\/monthly), encryption in transit and at rest, and whether you receive restore files directly or only through the provider.<\/p>\n<h2>RPO and RTO \u2014 written, tied to business systems<\/h2>\n<p><strong>Recovery Point Objective (RPO)<\/strong> is how much data you can afford to lose \u2014 four hours of orders, one business day of finance postings. <strong>Recovery Time Objective (RTO)<\/strong> is how long restore may take before the business stops waiting.<\/p>\n<p>Demand a small table in the contract or service description:<\/p>\n<ul>\n<li>Tier-1 (ERP, email, customer-facing apps): RPO ___ \/ RTO ___<\/li>\n<li>Tier-2 (internal tools, reporting): RPO ___ \/ RTO ___<\/li>\n<li>Tier-3 (archives, dev): RPO ___ \/ RTO ___<\/li>\n<\/ul>\n<p>If the vendor gives one number for everything, they have not thought about your business. If they refuse to put numbers in writing, assume worst case.<\/p>\n<h2>Restore tests \u2014 the only proof that matters<\/h2>\n<p>Scheduled backups that never restore are inventory, not insurance. Ask:<\/p>\n<ul>\n<li>When was the last <strong>successful restore test<\/strong> for a client with similar size and stack?<\/li>\n<li>Who witnessed it \u2014 provider only, or customer too?<\/li>\n<li>How long did full restore take versus RTO?<\/li>\n<li>Is there a <strong>signed report<\/strong> or ticket export you can file?<\/li>\n<\/ul>\n<p>Quarterly restore of at least one tier-1 system is a reasonable minimum for mid-market firms. Annual \u201cwe restored a random file\u201d is not enough when ERP must come back whole.<\/p>\n<h2>Ransomware-specific questions<\/h2>\n<p>Modern incidents encrypt production and backups together. Before signing, ask:<\/p>\n<ul>\n<li>Are backup repositories <strong>immutable<\/strong> or WORM-protected for a defined window?<\/li>\n<li>Is there an air-gapped or offline copy on a schedule you can audit?<\/li>\n<li>Do backup credentials differ from domain admin and cloud tenant owner?<\/li>\n<li>What is the documented restore path if Active Directory or Entra ID is compromised?<\/li>\n<\/ul>\n<p>Link this to your incident runbook \u2014 NIS2 and insurance questionnaires increasingly ask for backup integrity after attack, not just existence.<\/p>\n<h2>Red flags in proposals<\/h2>\n<p>\u201cUnlimited retention\u201d without storage cost model. Restore priced per hour with no cap. Backups stored only on the same SAN as production. No mention of database-consistent snapshots for SQL or PostgreSQL. \u201cCloud backup\u201d that is really the same vendor\u2019s second folder. Migration offered free but backup scope excluded from SLA.<\/p>\n<h2>One-page checklist before signature<\/h2>\n<ul>\n<li>Scope list by system\/tier with retention and encryption stated.<\/li>\n<li>RPO\/RTO table signed or attached to SLA.<\/li>\n<li>Last restore test report (&lt; 90 days for tier-1, or explain gap).<\/li>\n<li>Ransomware section: immutability, separate creds, AD recovery note.<\/li>\n<li>Named backup owner on provider side + escalation path.<\/li>\n<li>Exit clause: how you receive backup data if you leave.<\/li>\n<\/ul>\n<h2>What to do next<\/h2>\n<p>Pull your current contract and highlight every sentence that says \u201cbackup\u201d without numbers. Request a restore drill on one non-critical system before renewal \u2014 or before migrating tier-1 workloads. Our <a href=\"\/pl\/service\/secure-public-cloud-infrastructure\/\">Bezpieczna infrastruktura chmury publicznej<\/a> practice designs backup and restore with tested runbooks, not dashboard theatre \u2014 aligned with how auditors and regulators actually ask questions.<\/p>","protected":false},"excerpt":{"rendered":"<p><span data-no-translation>Backup na papierze to nie odporno\u015b\u0107. Checklist dla CFO i IT: RPO\/RTO na pi\u015bmie, testy odtwarzania z dowodem, scenariusz ransomware i kto podpisuje raport \u2014 zanim uwierzycie w obietnic\u0119 dostawcy.<\/span><\/p>","protected":false},"author":1,"featured_media":4716,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-10181","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business-guides"],"_links":{"self":[{"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/posts\/10181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/comments?post=10181"}],"version-history":[{"count":0,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/posts\/10181\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/media\/4716"}],"wp:attachment":[{"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/media?parent=10181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/categories?post=10181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/tags?post=10181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}