Is Microsoft 365 or Azure already resilient?
+
Microsoft protects the availability and resilience of its services. Your organisation still chooses what data and workloads are protected, which recovery points are acceptable, who can alter the protection, how dependencies return, and how the business validates the restored service. Microsoft 365 Backup or Azure Backup can be part of the design. Neither replaces the recovery plan or the drill.
Does a successful backup job prove recovery?
+
It proves that the job reached a successful state. Recovery proof also needs a selected recovery point, an approved target, integrity checks, application checks, dependency checks, observed timing, business acceptance, and a record of exceptions.
Will you replace our current backup platform?
+
We start with the platform already in place. Replacement is recommended only when the existing recovery path cannot meet an agreed target, cannot provide the required separation, or cannot pass the drill.
Is production touched during the drill?
+
The default is a controlled restore into an approved recovery target. Production failover, failback, or any action with production impact requires an explicit change window, separate acceptance criteria, and a reversal plan where the platform supports one.
What happens when a drill fails?
+
The workload is not marked recoverable. The failure becomes an owned issue with evidence, residual risk, a due date, and a re-test condition. Finding that gap before an incident is useful work, not a cosmetic failure.
Do you provide 24/7 incident response?
+
No. The standard service designs, corrects, drills, and documents recovery. Live ransomware response, forensics, malware containment, and round-the-clock incident command remain with your retained SOC or IR provider. RUNBOOK-10 defines and rehearses that handoff.
Can the evidence support DORA or NIS2 work?
+
Yes, as implementation evidence mapped to agreed control objectives. DORA Articles 11 and 12 and NIS2 Article 21(2)(c) are common references. This is not legal advice, certification, regulatory approval, or an assurance attestation.
Who performs the engagement?
+
The founder performs the engineering directly, with specialist agent review for architecture, security, evidence, and testing. Your business and technical workload owners approve targets and acceptance. There is no account-manager handoff.
Can we inspect a runbook before signing?
+
Yes. Ask to inspect any file from the ten-runbook set during discovery. The working versions live in your repository during delivery, not in a private ITSailor portal.
How do we leave?
+
The Exit Kit exists from the start. It records the architecture, recovery targets, runbooks, evidence locations, open exceptions, ownership, and access removal. Licences and cloud resources remain in your accounts or are transferable through the agreed marketplace path.