Incident Response Planning
A response plan your team has rehearsed, including who decides, who speaks, and who to notify.
Read moreRecovery you have actually rehearsed, at a cost the business can justify.
Most organisations have backups. Far fewer have restored from them recently, and fewer still know how long a full recovery would take. The gap between those two positions is where outages turn into existential events.
We start from the business side — how long can each service be down, and how much data can you afford to lose — then design recovery to meet those numbers and, critically, run a drill to prove it. A plan that has never been tested is a document, not a capability.
RTO and RPO agreed per service with the people who carry the consequences, not chosen by IT alone.
Automated restore testing, so a corrupt or incomplete backup is discovered on a Tuesday rather than during an incident.
Warm standby where downtime is expensive, restore-from-backup where it is tolerable. Not everything needs the same tier.
A documented runbook and a drill your team has run, including who calls whom.
Each service is ranked by the business cost of downtime and of data loss.
Backup, replication and failover approaches selected per tier, with the cost of each stated plainly.
Automated backups, cross-region copies, immutability where ransomware is a concern, and monitoring on all of it.
A live recovery exercise, with the runbook corrected afterwards based on what actually happened.
At least annually for a full drill, with automated restore verification running continuously. Any major architecture change should also trigger a test.
Not by itself. Backups in the same account as production are vulnerable to the same compromise. Separate accounts, immutability and tested restores are what make them real.
Immutable backups, isolated credentials and an offline or cross-account copy. We also make sure the recovery runbook does not depend on systems that may themselves be encrypted.
A response plan your team has rehearsed, including who decides, who speaks, and who to notify.
Read moreOngoing support for your cloud and platform environment, with defined response times and a monthly written report.
Read moreArchitecture, build and optimisation on Amazon Web Services, from a single workload to a multi-account landing zone.
Read moreWe will tell you what we would do, roughly what it costs, and whether it is worth doing yet.