Managed backups that pass an audit and survive a ransomware day.
Uzado manages backups, immutable storage, and disaster recovery for businesses across North America. Restore-tested, compliance-aligned, and operationally quiet.
Managed backups, defined
Managed backups means owning the full lifecycle: design, execution, retention, immutability, restore-testing, and the evidence pack the auditor reads. Most outages and audit findings start with a backup nobody had tested.
Backup is not the same as disaster recovery, and disaster recovery is not the same as business continuity. Backup is a recoverable copy of data. Disaster recovery is the documented ability to bring a workload back online within a defined window. The two metrics that matter are RPO (how much data you are willing to lose, measured in time) and RTO (how long the workload can be down before the business hurts). Defining those two numbers is the conversation everyone skips.
The classic 3-2-1 rule (three copies, two media types, one offsite) was the right answer for a decade. Against modern ransomware, it falls short: the offsite copy can also be encrypted if it is reachable from compromised credentials. That is why the modern answer adds an immutable tier, and why Uzado treats immutability as a non-negotiable architectural element rather than a premium feature.
The blast door for ransomware
Sophisticated threat actors target backup infrastructure first. Once they have backup-admin credentials, they delete or encrypt the backup tier and then trigger the ransomware payload across production. The conventional backup is now a copy of encrypted data. An immutable tier is hardware-enforced or policy-enforced storage that cannot be deleted or modified within its retention window, even by a user with administrative credentials. That is the blast door, and it is the difference between a recoverable incident and a wire transfer.
Why this page exists in a managed-services line-up
Backup is rarely sold as compliance. It should be. The control families below all expect a tested, retained, recoverable backup. Managed Backups produces the evidence as a by-product of running.
If your SOC 2 scope includes Availability, the auditor expects documented backup, restore-test evidence, and an RPO/RTO definition. Managed Backups produces that evidence as a side effect of running.
Annex A.12.3 (Backup) and the related A.17 business continuity controls require a tested backup capability with defined retention. Uzado runs the cadence and produces the certificate-grade evidence.
Article 32 calls out the ability to restore availability and access to personal data in a timely manner after an incident. Managed Backups is the operational layer that makes that obligation real.
PCI DSS expects defined retention for cardholder data and for audit logs. Uzado backs up, retains, and protects that data on the schedule the standard demands, with documented restore tests.
A full managed backup service
Full-system image backup for fast restore-of-record, plus file-level granularity for the everyday accidents (deleted file, corrupted document).
Yes, you still need it. Microsoft's retention is a continuity feature, not a backup. We protect Exchange, OneDrive, SharePoint, and Teams independently.
Salesforce, Google Workspace, Dropbox, and other business-critical SaaS data backed up to a tier outside the SaaS provider's blast radius.
WORM-protected (write-once-read-many) storage. Threat actors cannot delete or encrypt the protected tier even with stolen admin credentials.
Geographically separate copy, encrypted at rest and in transit. The 3-2-1 promise is real, not just a slide.
Documented restore-test cadence. Untested backups are a story; tested backups are a control. Uzado runs the test and gives you the report.
Documented DR runbooks with named owners, RTO targets per workload, and an annual exercise to verify the runbook still matches reality.
A five-step engagement model
Catalogue every workload that needs protection. Define recovery point and recovery time objectives per workload, in writing.
Design the 3-2-1 architecture: three copies, two media types, one offsite, with an immutable tier as the ransomware blast door.
Deploy the backup agents and the immutable storage tier. Validate first full backups and prove the offsite copy.
Schedule restore tests by workload tier (monthly for tier 1, quarterly for tier 2, annual for tier 3). Document every test.
24x7 health monitoring. Monthly executive reports against RPO/RTO and audit-ready evidence packs delivered on demand.
Common managed backup questions
Why isn't Microsoft 365 itself a backup?+
Microsoft's native retention is designed for continuity, not backup. Soft-delete windows expire. Mailbox litigation hold and Purview retention are e-discovery features, not point-in-time restore. Microsoft itself recommends third-party backup. A managed M365 backup protects you against accidental deletion, ransomware that uses the M365 sync as a propagation path, and malicious tenant administrators.
What is the difference between backup and disaster recovery?+
Backup is a copy of data you can restore from. Disaster recovery is the documented capability to bring a workload back online within a defined RTO, often in a different location. You need both. Backups without DR runbooks mean a long, improvisational recovery; DR without verified backups is a runbook with no data behind it.
What is an immutable backup, and why does it matter?+
An immutable backup is stored on WORM (write-once-read-many) media that cannot be modified or deleted within a retention window, even by an administrator. It matters because modern ransomware actors target backup infrastructure first; if the backup tier is mutable and the actor has stolen admin credentials, the backup is encrypted alongside the production data. Immutability is the blast door.
How often should we test restores?+
Tier 1 workloads (anything with a tight RTO) should be restore-tested monthly. Tier 2 quarterly. Tier 3 annually. Untested backups are a hopeful story; the only proof a backup works is a successful restore, run on a cadence the business has actually planned for.
Do we still need backups if we are cloud-native?+
Yes. Cloud platforms protect against infrastructure failure, not against accidental deletion, malicious deletion, ransomware, or SaaS-vendor incidents. The shared responsibility model is explicit: protecting your data is your job. Cloud-native businesses still need backups, just at a different layer of the stack.
What's a sensible RPO target for our environment?+
Most SMBs land around a 4-hour RPO for tier 1 systems and 24 hours for tier 2. Tier 1 systems in regulated environments (finance, health) often go to 15 minutes via continuous data protection. Uzado's first conversation with you is about pricing the right RPO per workload rather than choosing a single number across the estate.
How does Managed Backups support a SOC 2 audit?+
If Availability is in your SOC 2 scope, the auditor expects evidence of backup execution, retention, and restore testing, plus a documented RPO/RTO. Uzado produces all of that as standard output of the service. Pair Managed Backups with Uzado's Managed GRC and the evidence flows into Vanta automatically.
How does this affect cyber insurance?+
Cyber insurers increasingly require immutable backups, multi-factor authentication on backup systems, and documented restore tests as conditions of coverage. Managed Backups is designed to satisfy those requirements out of the box. Uzado provides the attestation language insurers ask for at renewal.
Ready to make backups boring again?
Uzado runs the cadence, the immutability, and the restore tests. Talk to our team and we will scope the workloads.