Skip to content
Security & Infrastructure pillar

Recover in hours,
not weeks.

Immutable backups, tested runbooks, quarterly drills and DORA / NIS2 / ISO 22301-ready evidence, shipped as a fixed-scope product, not a panic PowerPoint at 3AM.

RTO ≤ 4h
Tested, not promised
RPO ≤ 15min
For critical path systems
Quarterly
Drill cadence with evidence
DORA · NIS2 · ISO 22301
Mapped per control
The bad day

Most backup strategies fail the first time they matter.

Ransomware does not care about your RPO spreadsheet. A cross-account IAM compromise does not care about your nightly tape job. The question is not do you have backups. It is have you restored from them, recently, against a hostile production.

Untested backups

Backups run nightly and nobody has restored from them in 18 months. The first real restore happens at 3AM with the CEO on the line.

Shared-fate storage

Backups sit in the same account, region or SAN as production. One compromised IAM key, one ransomware blast radius. Both gone together.

Zero runbook, zero drill

No written failover procedure, no RTO/RPO targets, no drill evidence. When regulators ask, the answer is a nervous shrug.

Start here · Free

Free Recovery Drill

A 90-minute tabletop plus a read-only audit of your backup estate. We surface immutability gaps, shared-fate storage, missing runbooks and untested recovery paths, and hand you an honest RTO/RPO baseline within 48 hours.

  • Read-only access: no agents, no write credentials, no workload impact.
  • Delivered as a written report + 60-min walkthrough with a senior engineer.
  • No obligation to buy a tier afterwards.
  • EU data residency (Hetzner Falkenstein).

Under the hood

The drill combines the ITSailor Lifeline audit engine (backup inventory, immutability checks, IAM blast-radius scan) with a structured tabletop from our scenario library. Results are reconciled and interpreted by a senior engineer, never shipped raw.

Read-only backup audit + 90-minute tabletop exercise. No agents installed, no write credentials, no workload impact. Report and RTO/RPO baseline delivered within 48 hours.

48h baseline report · 90-min tabletop · zero workload impact.

Productized engagements

Start free. Then fixed scope, never T&M.

Run the readiness drill yourself, then step up to a fixed-scope implementation or a managed retainer. No hourly billing at any tier.

Recovery Readiness Drill

Run it guided. Walk away knowing how bad a bad day would be.

FreeSelf-serve · guided
  • Backup inventory with immutability and off-site verification
  • RTO / RPO baseline per critical system
  • IAM blast-radius scan, shared-fate storage flagged
  • Structured ransomware tabletop from our scenario library
  • Optional engineer-led deep dive: full BIA, executive report and prioritised remediation backlog

Outcome

A real picture of how bad a bad day would be, free. The natural lead-in to the implementation.

Run the free drill
Most popular

Lifeline Implementation

Immutable, tested, evidenced. Yours to keep.

Scoped to youFixed fee · 4-6 weeks
  • Terraform Lifeline modules: backup vaults with WORM / Object Lock
  • Cross-region & cross-account backup pipeline (AWS / Azure / hybrid)
  • Ransomware-resistant immutable tier + off-site copy (Hetzner EU)
  • Runbook library (database failover, region outage, ransomware response)
  • First live restore drill with written evidence pack

Outcome

Verified RTO ≤ 4h, RPO ≤ 15min and an audit binder that writes itself.

Scope the implementation

Managed Continuity

We hold the rope. You run the business.

Scoped to youMonthly retainer · 12 months min.
  • Backup health monitoring + restore test automation
  • Quarterly tabletop + live restore drill with evidence
  • Runbook maintenance, version control and on-call rotation support
  • Annual DORA / NIS2 / ISO 22301 evidence pack refresh
  • Incident retainer: senior engineer on the bridge during a real event

Outcome

Continuity proven every quarter. Insurance renewals stop being painful.

Talk about managed continuity
What you actually get

Concrete artefacts, not a binder of good intentions.

Every engagement ends with code, documents and drill evidence that live in your repositories, yours to keep, inspect and extend.

Business Impact Analysis

Criticality tiers, maximum tolerable downtime (MTD), recovery objectives per system. Signed off by the business, owned by engineering.

Terraform Lifeline modules

Backup vaults with Vault Lock / Object Lock, cross-region replication, KMS isolation. Clean state, documented variables, ready for your CI/CD.

Immutable backup policy

Written WORM policy, retention ladder, legal-hold procedure. Encoded in IaC, not in a wiki page nobody reads.

Runbook library

Markdown runbooks for database failover, region outage, ransomware response and data corruption. Versioned in Git, drilled quarterly.

Drill evidence pack

Every drill produces a signed report: scope, timeline, observed RTO/RPO, issues found, remediation plan. Copy-paste into your audit file.

Crisis communications kit

Pre-approved templates for customer, regulator, board and press communications. Translated, legal-reviewed, ready to send in anger.

On a bad day

What the first 24 hours actually look like.

When the pager goes off, nobody has time to think. Lifeline turns the first 24 hours into a script someone already rehearsed, with named owners, timed checkpoints and pre-approved comms.

  1. T + 0

    Detection

    Monitoring fires. Pager goes off. On-call confirms the event within 5 minutes.

  2. T + 15 min

    Triage & declaration

    Incident commander declared. Severity classified. Comms kit opened. Regulator clock starts where applicable.

  3. T + 1 h

    Failover executed

    Runbook followed step-by-step. Standby region promoted. DNS / traffic cutover completed. Status page updated.

  4. T + 4 h

    Service restored

    Critical path services back online within RTO. Customer-facing confirmation sent. Investigation continues in parallel.

  5. T + 24 h

    Evidence & post-mortem

    Blameless post-mortem scheduled. Evidence pack filed. Regulator notification finalised if required.

Malta & EU compliance

Every control mapped to the clause your auditor will ask about.

ITSailor delivers from the EU. Lifeline controls carry explicit mappings to DORA, NIS2, ISO 27001 and ISO 22301: your audit binder is a side-effect of doing the work, not a separate project.

DORAArticle 11

ICT business continuity & disaster recovery

  • Documented business continuity policy and ICT response plans
  • Backup policy with defined RPO/RTO and immutable off-site copies
  • Periodic testing including realistic failover scenarios
NIS2Article 21(2)(c)

Business continuity, backup management & crisis management

  • Backup management, disaster recovery and crisis management procedures
  • Incident handling obligations with 24/72h regulator notification
  • Supply chain security for backup and recovery vendors
ISO 27001Annex A.17

Information security aspects of business continuity

  • Regular, tested backups stored off-site and encrypted
  • Documented DR plan with defined recovery objectives
  • Segregation of duties for backup administration and restoration
ISO 22301Clauses 8.3-8.5

Business continuity strategy, plans & exercises

  • BIA, risk assessment and continuity strategy selection
  • Documented plans and procedures: reviewed and maintained
  • Exercising and testing programme with management review
The drill, live

Two hours on a Tuesday. Evidence for a year.

This is how a quarterly drill actually runs: restore into an isolated sandbox, measure RTO and RPO against the agreed targets, log what broke, sign the report. The engagement phases (assess, design, implement) exist to make this loop boring.

Loading the interactive console

The posture rule

If your security posture rests on "we're too small to be a target," we don't have a conversation to have.
- Michal Jatczak, founder · ITSailor
Toolchain

Boring technology. Deliberately.

Lifeline is built on proven, widely-deployed components. Nothing exotic, nothing you cannot maintain without us. No vendor lock-in beyond what your cloud provider already imposes.

AWS Backup + Vault Lock

Immutable cloud backup

Azure Backup + Immutable Vault

Immutable cloud backup

S3 Object Lock (Compliance)

WORM object storage

Veeam / Commvault

Hypervisor & file-level backup

Restic + rclone

Open-source encrypted backup

Hetzner Storage Box (EU)

Off-site immutable copy

Terraform + Atlantis

IaC & change control

Grafana + Loki

Backup health dashboards

Same rules, our production

We run ITSailor on the discipline this page sells.

Selling recovery discipline while running our own production on hope would be a strange look. So the backend behind this site follows the same rules, and two of the artefacts below are free to take.

FAQ

Honest answers to the questions buyers actually ask.

Does ITSailor Lifeline protect against ransomware specifically?

+

Yes. Ransomware is the design driver, not an afterthought. Every Lifeline deployment ships with an immutable tier (S3 Object Lock in Compliance mode, Azure Immutable Vault, or Vault Lock) stored in a separate security boundary from production. Credentials that can delete backups are held by no human in day-to-day operations. We test ransomware recovery explicitly in the first drill, not just "can we restore a file", but "can we rebuild the business with production assumed hostile".

Our cyber insurer keeps asking for "evidence of tested recovery". What does that mean in practice?

+

Underwriters want a signed report that proves a specific system was restored from a specific backup within a specific time window. Every Lifeline drill produces exactly that: scope, timeline, observed RTO/RPO, issues found and remediation plan, signed by the engineer who ran it. Clients typically drop two underwriting questionnaires by showing the last four quarterly reports.

We are a FinTech regulated by an EU competent authority. Does this map to DORA?

+

Yes. Every Lifeline control carries explicit mappings to DORA Art. 11 (ICT business continuity), Art. 12 (response and recovery), NIS2 Art. 21 and ISO 22301. The managed retainer includes an annual evidence pack refresh timed to your supervisory review or internal audit. We have shipped Lifeline into FinTech, Legal and Corporate Services operators across EU jurisdictions running on Hetzner, AWS and hybrid bare-metal.

What RTO and RPO can you realistically commit to?

+

RTO ≤ 4h and RPO ≤ 15min for critical path services is our default target, and we only commit once we have seen the environment. Pilot-light architecture is cheaper and typically lands RTO around 2-4h. Warm-standby gets you sub-30-min RTO. Active-active is available but rarely the right answer for an SME budget. We tell you the honest number before you sign, not after.

We already use Veeam / AWS Backup / Azure Backup. Do we need to rip it out?

+

No. Lifeline is not a product. It is an engagement. If your existing tool works, we harden it: add immutability, add off-site copies, add Terraform-managed policies, add the missing runbooks and the missing drill cadence. If it does not work, we say so and propose the minimum-viable replacement.

How disruptive is the first drill? We cannot break production.

+

Zero production impact. The first drill restores to an isolated recovery sandbox: separate account, separate VPC, no public endpoints. We validate integrity, boot the stack, run smoke tests, document the timing. Production traffic never moves. Only the quarterly "full game-day" drill (optional, available under the managed retainer) touches live cutover, and only with a pre-agreed maintenance window.

Who actually does the work?

+

One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person holding the Terraform plan and the runbook pen.

Provisioned stack

Licences that can sit under Operational Resilience & DR.

ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.

AvePoint

AvePoint Cloud Backup for Microsoft 365

€4 / user / month

Monthly commit

Backs up Exchange, OneDrive, SharePoint and Teams to immutable EU storage. Native Microsoft 365 retention is a soft-delete window, not a backup.

View bundle

Find out what the restore actually takes before an incident asks.

Recovery objectives that were never tested are assumptions. The workshop turns them into a tested number for the workload whose loss would stop revenue.