Cloud Backup & Disaster Recovery for Colorado Businesses

Backup is the control everyone assumes is handled and nobody checks. It is also the last thing standing between a ransomware incident and a business that no longer exists — which is why tested, immutable backup is the phrase that matters, rather than simply “we have backups.”

North Star designs, operates and tests backup and disaster recovery for businesses across the Denver metro area, Colorado Springs and Fort Collins, covering both halves of the problem: the data living in cloud services like Microsoft 365, and the servers and workstations running your business.

Backup Is Not One Thing

Most businesses have half a backup strategy without knowing it. The two halves protect different things, fail in different ways, and need different tools.

Cloud and SaaS data

Email, files, sites, chat history and user accounts that live entirely in a cloud service. There is no server to image, so this needs backup that connects to the service itself and takes an independent copy — held outside that provider’s own infrastructure, retained on your schedule rather than theirs, and restorable to a specific point in time at the level of a single mailbox, file or account.

Servers and workstations

Machines with an operating system, applications and configuration that took real effort to build. Here the requirement is image-based backup — a complete copy of the system rather than a list of files — written both to local storage for speed and to offsite cloud storage for survivability. When a server fails, the image can be started as a virtual machine, either on the local appliance or in the cloud, so the business keeps operating while the original is rebuilt.

Businesses that have migrated heavily to the cloud often assume the second half no longer applies. Businesses running on-premises servers often forget the first. Both gaps are common, and both are found during a network health and security assessment.

The Microsoft 365 Assumption That Costs Businesses Their Data

Cloud providers operate on a shared responsibility model, and it is worth reading carefully. Microsoft is responsible for keeping the service running. You are responsible for your data in it. Their infrastructure is redundant across data centres, so the platform will not lose your mailbox to a hardware failure — but that is a different promise from protecting your content against the things that actually destroy it.

What the native retention in Microsoft 365 does not reliably cover:

  • Deletion that is noticed late. Recycle bins and retention windows expire. A folder removed during a reorganisation and needed nine months later is frequently gone.
  • Departed employees. When a licence is removed, the mailbox and its OneDrive are eventually purged. Businesses discover this when they need a former employee’s correspondence for a dispute.
  • Ransomware that syncs. Encrypted files on a synced desktop propagate to the cloud copy. Version history helps, and is neither unlimited nor pleasant to unwind across thousands of files.
  • A compromised administrator. An attacker inside a tenant with administrative rights can disable retention and delete at scale. Anything the tenant controls, they control.
  • Long-term retention obligations. Where a regulator, insurer or contract requires records kept for years, native settings rarely satisfy it on their own.

An independent backup of your cloud tenant closes all five, because the copy is held somewhere the tenant — and anyone who compromises it — cannot reach. We cover mailboxes, OneDrive, SharePoint sites, Teams conversations and files, and directory objects including groups and user accounts. This is delivered alongside our managed Microsoft 365 services.

Why Ransomware Changed What Backup Has to Do

Attackers understand that backup is what defeats them, so backup became a target rather than an afterthought. Modern intrusions look for the backup server, the network share holding the copies, and the credentials that manage them — and destroy or encrypt those first, sometimes waiting weeks so that every recent copy is already compromised before anyone notices.

That changes the requirements:

  • Immutability. Once written, a backup cannot be altered or deleted for its retention period — not by an administrator, not by stolen credentials, not by us. This is the single most important property.
  • Separated credentials. Backup systems do not authenticate against the same directory as everything else, so compromising your network does not hand over your recovery.
  • Sufficient history. Enough retained recovery points to reach back past the intrusion, since the encryption is often the last step of something that started much earlier.
  • Offsite copies. The classic rule still holds: multiple copies, more than one type of storage, at least one somewhere else. Fire, flood and theft have not stopped happening because ransomware arrived.
  • An air-gapped copy. At least one copy kept beyond the reach of your production network entirely — not reachable over a mapped drive, not authenticated by your directory, not deletable from a compromised workstation. If an attacker who owns your network can also reach the backup, there is no gap.

A word on that term, because it gets used loosely. A true air gap originally meant physically disconnected media — tapes in a safe, a drive unplugged and carried offsite. Almost nothing works that way now, and what most providers mean today is a logical air gap: the backup copy sits in storage your network has no route to, under credentials your directory does not control, with immutability enforced by the storage platform rather than by policy. The practical test is the same either way. Can an attacker holding domain administrator rights delete this copy? If the answer is no, the gap is doing its job. We build to that standard and will tell you plainly which parts of your environment currently fail it.

Backup is the last layer, not the first. It works alongside managed threat protection to catch the intrusion early and the wider layered cybersecurity program to prevent it. Recovering from backup means the other layers were beaten — the point is that being beaten is survivable.

A Backup You Have Never Restored From Is Not a Backup

It is a hypothesis. Backups fail quietly and in ordinary ways: an agent stops reporting after an update, a new server is never added to the job, a database is copied while open and the file is unusable, retention is set shorter than anyone realised. The dashboard stays green throughout, because it is reporting that the job ran rather than that the result works.

We verify recoverability rather than job completion — booting server images to confirm they actually start, and performing sample restores of cloud data. You receive documented evidence of those tests, which is also what an auditor or a cyber insurer asks for when they want proof rather than a policy document.

How Quickly Could You Be Running Again?

Two numbers decide what backup costs and what it protects, and both are business decisions rather than technical ones.

How much work can you afford to lose? If backups run nightly and a server fails at 4pm, you lose the day. Some businesses can retype a day of orders; others cannot lose fifteen minutes. Backup frequency follows from that answer.

How long can you be down? Restoring a large server from cloud storage over a business internet connection can take days. This is why a local appliance matters: the image is already on site, so the system can be virtualized and brought up in minutes rather than transferred first. The cloud copy is the fallback for when the building itself is the problem.

We work these out with you, write them into the design, and document what the environment can actually deliver — so the answer during an incident is a plan rather than an estimate.

What the Service Includes

  • Image-based server and workstation backup to local storage and offsite cloud, with virtualization for rapid recovery.
  • Independent cloud and SaaS backup covering mailboxes, files, sites, chat and directory objects, retained beyond native limits.
  • Immutable, air-gapped retention so copies cannot be altered or deleted within their retention window, and cannot be reached from your production network or its credentials.
  • Encryption in transit and at rest using current industry standards, with keys managed so that the storage provider cannot read your data.
  • Daily monitoring of every job, with failures investigated rather than logged.
  • Scheduled recovery testing with written evidence of the results.
  • A documented recovery plan naming what gets restored in what order, who is called, and what the business does in the meantime.
  • Retention aligned to your obligations, whether that comes from a regulator, an insurer, a contract or your own judgement.

A Note on Tooling

We do not publish which platforms we deploy. Backup vendors get acquired, rebranded and repositioned regularly, and a provider whose service is defined by one product has to rebuild that service every time the product changes. What we commit to is the capability, the testing and the recovery time — selected for your environment and reviewed as the market shifts. We are glad to walk through the current toolset during an assessment.

Where This Fits

Backup is delivered as part of managed IT services and managed security services rather than sold as an isolated product, because it depends on knowing what is running and what matters. For businesses with no IT department it comes as standard with small business IT support; where you have internal staff, co-managed IT can take on backup monitoring and testing specifically, which is the part that most often slips. A Microsoft 365 cloud migration also reduces how much needs protecting in the first place by retiring aging on-premises servers.

Serving the Denver Metro Area, Colorado Springs & Fort Collins

We protect data for organizations across Colorado’s Front Range, including Denver, Aurora, Lakewood, Arvada, Westminster, Thornton, Northglenn, Broomfield, Commerce City, Brighton, Centennial, Greenwood Village, Englewood, Littleton, Highlands Ranch, Parker, Castle Rock, Golden, Wheat Ridge, Colorado Springs, Monument, Fountain, Fort Collins, Loveland, Windsor and Greeley, along with the surrounding communities and clients running remote and hybrid teams. Retention and recovery requirements vary by field — see the industries we serve.

Frequently Asked Questions

Doesn’t Microsoft already back up our Microsoft 365 data?

Not in the way most people mean. Microsoft protects the availability of the service and its own infrastructure; responsibility for your data within it sits with you. Native recycle bins, version history and retention policies help with recent, small mistakes, but they expire, they can be altered by anyone with administrative access, and they are not designed to recover a tenant after a compromise. An independent copy held outside the tenant is what covers that.

What does immutable backup mean?

That once a backup is written it cannot be modified or deleted until its retention period expires — including by an administrator or by someone using stolen administrative credentials. It matters because attackers now deliberately target backups before deploying ransomware, and a backup they can delete is not a recovery option.

What does air-gapped backup mean, and is yours actually air-gapped?

An air-gapped backup is one your production network cannot reach. Historically that meant physically disconnected media such as tape; today it usually means a logical air gap — storage with no network route from your environment, separate credentials outside your directory, and immutability enforced by the storage platform rather than by a setting someone could change. The honest test is whether an attacker holding domain administrator rights on your network could delete the copy. Ours are built so the answer is no. Be sceptical of any provider who uses the phrase without explaining which kind they mean.

How often do you test restores?

Server images are verified on a recurring schedule by booting them to confirm they start, and cloud data is checked through sample restores. The frequency is set with you based on how critical each system is. You get written evidence, which is also what cyber insurers and auditors ask for.

How long would it take to get us running after a server failure?

With a local appliance holding recent images, a failed server can usually be virtualized and serving users within minutes to a couple of hours, depending on its size and role. Recovering the same system from cloud storage alone can take considerably longer, which is why local and offsite copies do different jobs. We document the realistic figures for your environment rather than quoting a general number.

We already have backups. Why would we change anything?

You might not need to. What we typically find in assessments is not an absence of backup but gaps in it: a server added last year that was never included, no cloud data protection at all, retention shorter than anyone believed, copies reachable from the same network with the same credentials, and no restore ever attempted. The assessment tells you which of those apply, whether or not you engage us afterward.

Find Out Whether Your Backups Would Actually Work

Most businesses believe they are protected. The difference between believing and knowing is a restore test, and it is better to run one now than to discover the answer during an incident. Call 303-552-0018 or book a time below.