Servers and Cloud

Disaster Recovery Planning and Ransomware-Resilient Backup

If the server room floods, ransomware encrypts every disk or the building loses power, which system comes back, how quickly and with data from which point in time? We write that down in advance and test it.

CybUP TeamLast updated: 7 min read

In short

A disaster recovery (DR) plan is the technical plan and infrastructure that brings critical systems back within a set time, with an acceptable amount of data loss, after a major failure, disaster or cyber attack. It is for companies that run their own servers and hold their own data. CybUp sets RPO/RTO targets, builds replication and immutable backups, writes a step-by-step recovery runbook and runs regular tests.

What is a disaster recovery plan, and how is it different from backup?

Backup means taking a copy of your data; disaster recovery is the plan for how quickly, in what order and where the business is brought back up from that copy. A company that has backups but does not know which server starts first, how DNS changes or which address users connect to will spend the hours after a disaster hunting for those answers.

A plan brings two things together: infrastructure (a second site, replication, immutable backups) and procedure (who does what, in which order). If either is missing, the plan does not work. For the foundations on the infrastructure side, see our Veeam backup setup page.

What are RPO and RTO, and how do you set them?

RPO (Recovery Point Objective) is the most data loss you can accept, expressed as time. An RPO of four hours means you have accepted losing up to the last four hours of data in a disaster. RTO (Recovery Time Objective) is the longest you can accept before the system is usable again.

Each system gets its own targets, and the tighter the target, the higher the cost. An ERP database may need a 15-minute RPO and a two-hour RTO, while an archive file server can live with a one-day RPO and a two-day RTO. We do not make these numbers up; we arrive at them with you by asking department heads, “what happens if this system is down for half a day?”

Once the target is set, the technical means follows. A nightly backup gives you a 24-hour RPO. Hyper-V Replica sends copies every 30 seconds, 5 minutes or 15 minutes. Replication at database level can bring RPO down further still.

Should your DR site be a second location or the cloud?

A second site can be another of your buildings, a branch office or a rented rack in a data centre. The advantage is that the data stays under your control on a fast local network; the drawback is buying and maintaining a second set of hardware. A backup site on the same fault line and in the same power distribution area as your Istanbul head office will not cover every scenario either, and we say so openly when planning.

In the cloud, Azure Site Recovery can continuously replicate on-premises VMware and Hyper-V VMs and physical servers to Azure, and lets you run drills without affecting production. In a disaster, the machines start up in Azure. The Azure subscription is opened in your own account on your behalf; for details, see our Azure and AWS setup page. Holding data in a region outside Türkiye needs separate assessment under KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698).

How do you protect backups against ransomware?

In ransomware attacks, the attackers try to find and delete backups before they encrypt files. That is why the #StopRansomware Guide from CISA, the US cybersecurity agency, recommends keeping offline, encrypted backups of critical data and testing them regularly in a disaster recovery scenario. The guide also advises keeping ready-made “golden images” of critical systems.

The layers we apply are: a backup server taken out of the domain, an immutable repository, at least one copy on a target that cannot be reached over the network or that has object lock, multi-factor authentication for backup administration, and alerts when backup jobs see unexpected deletions or changes. Microsoft’s guidance on preparing for ransomware likewise calls for protecting critical system backups against deliberate deletion and encryption by attackers, with immutable or fully offline storage as the strongest option, and asks that recovery documents and network diagrams be kept somewhere that will survive the attack.

  • Backup server outside the domain, with a separate admin account
  • Immutable repository or a cloud copy with object lock
  • At least one copy offline or isolated from the network
  • Multi-factor authentication for backup administration
  • Regular restore drills with a results report

“It is important that backups are maintained offline, as many ransomware variants attempt to find and subsequently delete or encrypt accessible backups to make restoration impossible unless the ransom is paid.”

— CISA — #StopRansomware Guide

How does technical recovery work after a ransomware attack?

After a ransomware incident, the first job is to disconnect the affected systems from the network and prepare an environment you are sure is clean. Restoring from backup into a network where the attacker is still present means living through the same attack twice. So we carry out ransomware recovery on an isolated network, with servers built from clean images and accounts whose passwords have been changed; the domain controller and identity system always come first.

To be clear about where our role stops: we do not promise to decrypt encrypted files, we do not negotiate ransoms and we do not carry out forensic investigations. For that work we recommend specialist incident response firms and your legal adviser; notification duties under KVKK are also part of the process. Our role is to bring the infrastructure back up from clean backups in the right order, then harden it against the next incident.

“Reconnect systems and restore data from offline, encrypted backups based on a prioritization of critical services.”

— CISA — #StopRansomware Guide

What is a DR runbook, and how often should you test disaster recovery?

A runbook is the document that sets out, in order, the steps to follow in a disaster: which system starts first, which IP and DNS changes are made, who makes which decision and what users are told. A runbook that is perfect on the day it is written goes stale six months later when a new server is added. That is why we tie it into your change management.

How often to test depends on how important the system is. We recommend automated backup tests every week, drill restores of selected systems every three months, and the whole plan exercised at least once a year with a tabletop and a technical drill. For example, at a manufacturer with 150 staff, on one Saturday a year the ERP system, the domain and the file server are started in the DR environment, a few users enter orders from there, and the measured time is compared with the RTO target. If it falls short, the plan is updated.

What you receive

  • System inventory, business impact assessment and RPO/RTO table
  • Second-site or cloud replication infrastructure
  • Ransomware-resilient backup architecture (immutable and offline copies)
  • Step-by-step recovery runbook and communication plan
  • First drill, with a report of measured RTO and RPO
  • Annual test schedule and update process

How we work

  1. 1

    Free review

    We map your systems, existing backups and dependencies, and report the biggest risks in order of priority.

  2. 2

    Setting targets

    We agree RPO and RTO targets for each system together with your department heads.

  3. 3

    Infrastructure

    Replication, the DR site or cloud target, immutable backups and monitoring are put in place.

  4. 4

    Runbook

    Recovery steps, roles and the communication plan are written and reviewed with your team.

  5. 5

    Drill

    The plan is tested with a real recovery, the results are reported and the plan is updated.

Frequently asked questions

Does a small company need a disaster recovery plan?

Yes, but at a different scale. For an office with five servers, the plan might be one immutable backup, a copy in the cloud and a two-page runbook. What matters is that the steps for the day of the disaster are written down and tried out beforehand.

Can you recover our files after a ransomware infection?

If you have a sound, clean backup, we rebuild your systems from it. We do not promise to decrypt encrypted files and we do not carry out forensic investigations; for those, we recommend working with an incident response firm.

Can RPO be zero?

Synchronous replication can get close to zero in theory, but it needs a low-latency link and specialised storage. For most companies, an RPO measured in minutes is a better balance of cost and complexity.

Does disaster recovery testing affect production?

Not if the test is set up correctly. Tools such as Hyper-V Replica, Azure Site Recovery and Veeam SureBackup start the test copy on a network isolated from production.

Is using the cloud as a DR site against KVKK?

Not in itself, but holding data in a region outside Türkiye must be assessed under the rules on transfers abroad. We recommend that your legal adviser makes that assessment; we apply the technical measures, such as region choice, encryption and access logging.

How long does it take to put a DR plan in place?

Anywhere from a few weeks to a few months, depending on scope. We put urgent items such as immutable backups in place in the first weeks and complete the rest of the plan in stages.

How much does a disaster recovery plan cost?

We give you a written quote once we have reviewed the scope, and the review is free. The quote depends on the number of systems, the RPO/RTO targets and whether the DR target is a building or the cloud.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.