“We have a backup provider” is not the same as “we know our backup works.”
By: Marc Schwartz, President of Ozone IT Services
Here’s a scenario that plays out more often than most companies would like to admit: a mid-size company outsources its data backup to an IT provider. The contract is signed, the backups run on schedule, and the report shows green checkmarks month after month. Leadership stops thinking about it. It’s handled.
Then a server fails. Or ransomware hits. Or an employee accidentally deletes a folder no one realizes matters until it’s gone. The company goes to restore from backup and discovers the backup that had been running “successfully” for months was incomplete, corrupted, or simply couldn’t be restored within a timeframe that mattered. The provider had been backing up the data. No one had ever tested whether that data could actually come back.
This is the story behind more real crises than most companies realize and it’s almost never a story about bad intentions. It’s a story about assumption standing in for verification. How do we know this? Because Ozone has been called to the rescue more than once. Keep reading to see what every company needs to avoid an IT emergency.
Where the Assumption Usually Breaks Down
“Our provider handles backups” isn’t the same as “have we tested recovery?” Backup and recovery are two different disciplines. A backup job completing successfully tells you data was copied. It doesn’t tell you that data can be restored quickly, completely, and in a form your business can actually use during an active crisis, which is the only moment that actually matters.
Outsourcing IT isn't the same as outsourcing accountability.
When a company hands backup and security responsibility to an outside provider, it’s easy to treat that relationship as “solved” rather than as an ongoing partnership that requires oversight, reporting, and periodic testing. The providers worth trusting build and manage that oversight and process. The ones that don’t leave companies discovering the gap at the worst possible moment.
Recovery time objectives are rarely discussed until they're missed.
Most companies never ask, in concrete terms, how long a full recovery would actually take. When a crisis hits, “we’ll restore from backup” sounds reassuring until the restore takes three days, and the business can’t function for three days.
What "Assume Nothing" Actually Looks Like
The companies that come through a crisis with minimal damage aren’t the ones who got lucky. They’re the ones who treated backup and recovery as something to be planned, tested, and verified regularly, not something to be assumed.
That means:
- Regularly testing recovery, not just backup completion. A backup that’s never been restored is a theory, not a plan.
- Documented, known recovery time objectives. Everyone from IT to leadership should know how long a real recovery takes before it’s needed.
- Clear accountability with any outsourced provider. Reporting shouldn’t stop at “backup succeeded.” It should include recovery testing results, gaps identified, and how they were closed.
- A crisis plan that assumes something will go wrong eventually (because eventually, for every company, something does) is an effective and valuable resource to every company.
Crisis and Recovery Planning are Essential in IT but Frequently not an Investment Priority
Crisis and recovery planning sits at the intersection of backup infrastructure and cybersecurity because, increasingly, the crises companies face aren’t hardware failures. They’re ransomware and targeted attacks specifically designed to compromise backups along with production systems. A backup strategy built without security in mind is a backup strategy an attacker has already accounted for.
This is where specialized expertise matters. Internal IT teams are exceptionally good at supporting the business day-to-day, but building and continuously testing a recovery strategy that holds up against modern ransomware requires a level of specialized, current expertise that’s difficult for any single in-house team to maintain alongside everything else on their plate.
How Ozone Approaches Crisis & Recovery Differently
Ozone builds backup and recovery strategy around one standard: if it hasn’t been tested, it isn’t proven. That means:
- Backup-as-a-Service (BaaS) architecture built for real recoverability, not just scheduled copying
- Regular recovery testing, so the first time a restore is attempted isn’t during an actual crisis
- Documented recovery time objectives your team and leadership can actually plan around
- Security-integrated backup strategies designed with the assumption that ransomware will specifically target backup systems
The goal isn’t to replace your internal team’s role in this process; it’s to make sure the plan they’re relying on has actually been proven to work, backed by the kind of continuous testing and specialized expertise that’s difficult to maintain internally alongside day-to-day IT demands.
Don't Wait for the Crisis to Find the Gap
The companies that inspired this cautionary tale didn’t fail because they didn’t care about backup and recovery. They failed because they assumed a system was working without ever verifying it. That’s an easy assumption to make and an expensive one to be wrong about.
Ozone IT Services partners with manufacturing and mid-size organizations across the U.S. to build the secure, well-supported IT foundation company needs while acting as an integrated extension of internal IT teams.