Recover in hours,
not weeks.
Immutable backups, tested runbooks, quarterly drills and DORA / NIS2 / ISO 22301-ready evidence, shipped as a fixed-scope product, not a panic PowerPoint at 3AM.
Most backup strategies fail the first time they matter.
Ransomware does not care about your RPO spreadsheet. A cross-account IAM compromise does not care about your nightly tape job. The question is not do you have backups. It is have you restored from them, recently, against a hostile production.
Untested backups
Backups run nightly and nobody has restored from them in 18 months. The first real restore happens at 3AM with the CEO on the line.
Shared-fate storage
Backups sit in the same account, region or SAN as production. One compromised IAM key, one ransomware blast radius. Both gone together.
Zero runbook, zero drill
No written failover procedure, no RTO/RPO targets, no drill evidence. When regulators ask, the answer is a nervous shrug.
Free Recovery Drill
A 90-minute tabletop plus a read-only audit of your backup estate. We surface immutability gaps, shared-fate storage, missing runbooks and untested recovery paths, and hand you an honest RTO/RPO baseline within 48 hours.
- Read-only access: no agents, no write credentials, no workload impact.
- Delivered as a written report + 60-min walkthrough with a senior engineer.
- No obligation to buy a tier afterwards.
- EU data residency (Hetzner Falkenstein).
Under the hood
The drill combines the ITSailor Lifeline audit engine (backup inventory, immutability checks, IAM blast-radius scan) with a structured tabletop from our scenario library. Results are reconciled and interpreted by a senior engineer, never shipped raw.
Start free. Then fixed scope, never T&M.
Run the readiness drill yourself, then step up to a fixed-scope implementation or a managed retainer. No hourly billing at any tier.
Recovery Readiness Drill
Run it guided. Walk away knowing how bad a bad day would be.
- Backup inventory with immutability and off-site verification
- RTO / RPO baseline per critical system
- IAM blast-radius scan, shared-fate storage flagged
- Structured ransomware tabletop from our scenario library
- Optional engineer-led deep dive: full BIA, executive report and prioritised remediation backlog
Outcome
A real picture of how bad a bad day would be, free. The natural lead-in to the implementation.
Lifeline Implementation
Immutable, tested, evidenced. Yours to keep.
- Terraform Lifeline modules: backup vaults with WORM / Object Lock
- Cross-region & cross-account backup pipeline (AWS / Azure / hybrid)
- Ransomware-resistant immutable tier + off-site copy (Hetzner EU)
- Runbook library (database failover, region outage, ransomware response)
- First live restore drill with written evidence pack
Outcome
Verified RTO ≤ 4h, RPO ≤ 15min and an audit binder that writes itself.
Managed Continuity
We hold the rope. You run the business.
- Backup health monitoring + restore test automation
- Quarterly tabletop + live restore drill with evidence
- Runbook maintenance, version control and on-call rotation support
- Annual DORA / NIS2 / ISO 22301 evidence pack refresh
- Incident retainer: senior engineer on the bridge during a real event
Outcome
Continuity proven every quarter. Insurance renewals stop being painful.
Concrete artefacts, not a binder of good intentions.
Every engagement ends with code, documents and drill evidence that live in your repositories, yours to keep, inspect and extend.
Business Impact Analysis
Criticality tiers, maximum tolerable downtime (MTD), recovery objectives per system. Signed off by the business, owned by engineering.
Terraform Lifeline modules
Backup vaults with Vault Lock / Object Lock, cross-region replication, KMS isolation. Clean state, documented variables, ready for your CI/CD.
Immutable backup policy
Written WORM policy, retention ladder, legal-hold procedure. Encoded in IaC, not in a wiki page nobody reads.
Runbook library
Markdown runbooks for database failover, region outage, ransomware response and data corruption. Versioned in Git, drilled quarterly.
Drill evidence pack
Every drill produces a signed report: scope, timeline, observed RTO/RPO, issues found, remediation plan. Copy-paste into your audit file.
Crisis communications kit
Pre-approved templates for customer, regulator, board and press communications. Translated, legal-reviewed, ready to send in anger.
What the first 24 hours actually look like.
When the pager goes off, nobody has time to think. Lifeline turns the first 24 hours into a script someone already rehearsed, with named owners, timed checkpoints and pre-approved comms.
- T + 0
Detection
Monitoring fires. Pager goes off. On-call confirms the event within 5 minutes.
- T + 15 min
Triage & declaration
Incident commander declared. Severity classified. Comms kit opened. Regulator clock starts where applicable.
- T + 1 h
Failover executed
Runbook followed step-by-step. Standby region promoted. DNS / traffic cutover completed. Status page updated.
- T + 4 h
Service restored
Critical path services back online within RTO. Customer-facing confirmation sent. Investigation continues in parallel.
- T + 24 h
Evidence & post-mortem
Blameless post-mortem scheduled. Evidence pack filed. Regulator notification finalised if required.
Every control mapped to the clause your auditor will ask about.
ITSailor delivers from the EU. Lifeline controls carry explicit mappings to DORA, NIS2, ISO 27001 and ISO 22301: your audit binder is a side-effect of doing the work, not a separate project.
ICT business continuity & disaster recovery
- Documented business continuity policy and ICT response plans
- Backup policy with defined RPO/RTO and immutable off-site copies
- Periodic testing including realistic failover scenarios
Business continuity, backup management & crisis management
- Backup management, disaster recovery and crisis management procedures
- Incident handling obligations with 24/72h regulator notification
- Supply chain security for backup and recovery vendors
Information security aspects of business continuity
- Regular, tested backups stored off-site and encrypted
- Documented DR plan with defined recovery objectives
- Segregation of duties for backup administration and restoration
Business continuity strategy, plans & exercises
- BIA, risk assessment and continuity strategy selection
- Documented plans and procedures: reviewed and maintained
- Exercising and testing programme with management review
Two hours on a Tuesday. Evidence for a year.
This is how a quarterly drill actually runs: restore into an isolated sandbox, measure RTO and RPO against the agreed targets, log what broke, sign the report. The engagement phases (assess, design, implement) exist to make this loop boring.
The posture rule
“If your security posture rests on "we're too small to be a target," we don't have a conversation to have.”
Boring technology. Deliberately.
Lifeline is built on proven, widely-deployed components. Nothing exotic, nothing you cannot maintain without us. No vendor lock-in beyond what your cloud provider already imposes.
Immutable cloud backup
Immutable cloud backup
WORM object storage
Hypervisor & file-level backup
Open-source encrypted backup
Off-site immutable copy
IaC & change control
Backup health dashboards
We run ITSailor on the discipline this page sells.
Selling recovery discipline while running our own production on hope would be a strange look. So the backend behind this site follows the same rules, and two of the artefacts below are free to take.
Our own stack
ITSailor production runs on a hardened EU VPS in Falkenstein: pinned service versions, nightly backups to storage outside the server's blast radius, and a full restore verified in June 2026. The same machine serves this site's backend.
Architecture and resilience workshop
Bring your current dependencies, recovery targets and runbooks. Leave with a scoped decision record, implementation plan and Exit Kit for your environment.
Review the workshopThe DR drill runbook, in the kit
RUNBOOK-09-dr-drill.md ships inside the Azure landing-zone delivery kit, next to the Terraform it exercises. The whole kit is browsable, folder by folder, on the infrastructure page.
See the delivery kitHonest answers to the questions buyers actually ask.
Does ITSailor Lifeline protect against ransomware specifically?
+
Yes. Ransomware is the design driver, not an afterthought. Every Lifeline deployment ships with an immutable tier (S3 Object Lock in Compliance mode, Azure Immutable Vault, or Vault Lock) stored in a separate security boundary from production. Credentials that can delete backups are held by no human in day-to-day operations. We test ransomware recovery explicitly in the first drill, not just "can we restore a file", but "can we rebuild the business with production assumed hostile".
Our cyber insurer keeps asking for "evidence of tested recovery". What does that mean in practice?
+
Underwriters want a signed report that proves a specific system was restored from a specific backup within a specific time window. Every Lifeline drill produces exactly that: scope, timeline, observed RTO/RPO, issues found and remediation plan, signed by the engineer who ran it. Clients typically drop two underwriting questionnaires by showing the last four quarterly reports.
We are a FinTech regulated by an EU competent authority. Does this map to DORA?
+
Yes. Every Lifeline control carries explicit mappings to DORA Art. 11 (ICT business continuity), Art. 12 (response and recovery), NIS2 Art. 21 and ISO 22301. The managed retainer includes an annual evidence pack refresh timed to your supervisory review or internal audit. We have shipped Lifeline into FinTech, Legal and Corporate Services operators across EU jurisdictions running on Hetzner, AWS and hybrid bare-metal.
What RTO and RPO can you realistically commit to?
+
RTO ≤ 4h and RPO ≤ 15min for critical path services is our default target, and we only commit once we have seen the environment. Pilot-light architecture is cheaper and typically lands RTO around 2-4h. Warm-standby gets you sub-30-min RTO. Active-active is available but rarely the right answer for an SME budget. We tell you the honest number before you sign, not after.
We already use Veeam / AWS Backup / Azure Backup. Do we need to rip it out?
+
No. Lifeline is not a product. It is an engagement. If your existing tool works, we harden it: add immutability, add off-site copies, add Terraform-managed policies, add the missing runbooks and the missing drill cadence. If it does not work, we say so and propose the minimum-viable replacement.
How disruptive is the first drill? We cannot break production.
+
Zero production impact. The first drill restores to an isolated recovery sandbox: separate account, separate VPC, no public endpoints. We validate integrity, boot the stack, run smoke tests, document the timing. Production traffic never moves. Only the quarterly "full game-day" drill (optional, available under the managed retainer) touches live cutover, and only with a pre-agreed maintenance window.
Who actually does the work?
+
One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person holding the Terraform plan and the runbook pen.
Licences that can sit under Operational Resilience & DR.
ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.
AvePoint
AvePoint Cloud Backup for Microsoft 365
€4 / user / month
Monthly commit
Backs up Exchange, OneDrive, SharePoint and Teams to immutable EU storage. Native Microsoft 365 retention is a soft-delete window, not a backup.
View bundleFind out what the restore actually takes before an incident asks.
Recovery objectives that were never tested are assumptions. The workshop turns them into a tested number for the workload whose loss would stop revenue.