Accounting and ERP
Four hours down, one hour of data. Copying a Sage, Cegid or EBP database once at midnight leaves too much exposure on the day a VAT return goes out. Transaction logs want capturing repeatedly between nine and six.
The console reported that last night's job finished. That fact is worth almost nothing on its own. The question worth answering is whether your finance team can open last week's ledger on Monday morning once ransomware has swept through the file server. So we begin at the far end, with the outage each application can absorb, and let that dictate everything upstream of it. Then the whole thing is rehearsed against a clock, at an interval you choose. Drills included, none of it requires anyone to travel.
One settles the contents of the backup and the rhythm behind it. The other guarantees that a single copy always lies out of reach of flames, water, and anybody who has already talked their way into your network.
First comes the list of things that matter: the database under your business software, the shared folder, Microsoft 365 mailboxes, the firewall configuration. Retention, timing, alerts addressed to a named colleague and a short playbook for the morning nothing starts all follow from that list.
One encrypted copy is parked with a host inside the Union, reachable only through credentials of its own and guarded by a lock that declines deletion. An attacker holding every account you own still cannot touch it.
Every system needs an RTO, meaning the longest outage it can absorb, and an RPO, meaning how much recent effort you would be willing to key in again. What follows are plausible figures for a firm of thirty or forty people.
Four hours down, one hour of data. Copying a Sage, Cegid or EBP database once at midnight leaves too much exposure on the day a VAT return goes out. Transaction logs want capturing repeatedly between nine and six.
A day either way. One pass taken after the office empties covers what most companies genuinely require.
Four hours down, one hour of data. Keeping the platform running is Microsoft's commitment. A mailbox stripped bare by somebody working out their notice is not, so mailboxes want a backup of their own.
An hour down, an hour of data. Orders from Amazon.fr and card authorisations do not pause politely while you rebuild from an archive, which leaves a standby environment kept warm as the only honest answer.
A day either way. Realistic only where work is saved into OneDrive or SharePoint rather than a desktop folder on one particular machine.
A second folder on the very same server protects nothing at all. One controller failure, one encryption run, one careless drag of the mouse, and original and duplicate depart together. Two copies on unlike media, plus a third somewhere else entirely, ideally rented from a European host: that is the floor, not the target.
Reaching your servers and the Microsoft 365 portal happens over encrypted remote sessions throughout. Building the thing takes days. Stage four is what turns a configuration into a guarantee, and it is routinely left out.
Important files rarely sit where an organisation chart suggests they will. Recurring surprises: a price list living on one sales laptop, or executed contracts that exist nowhere except as mail attachments.
Each application receives a tolerable outage and a tolerable loss, decided together with you. Budget follows from those numbers; it is not allowed to set them.
Timings, retention, encryption, the off-site leg. Alerting covers failures and, just as importantly, reports that never turn up at all.
On the agreed cycle, chosen data is rebuilt inside a sandbox and the clock is read. What comes out is a dated note you can put in front of an insurer or an auditor.
Put one question to whoever owns them: what was the last thing they brought back? Typical discoveries include a job erroring since spring, a protected folder that stopped being used two reorganisations ago, and an encryption passphrase that walked out of the door with a leaver. Our review ends in a yes or a no, not in a set of suggestions.
They can, provided the credentials that open your network do not also open them. Current criminal practice is to find the repository and empty it first, encrypting afterwards, specifically so that paying becomes the only remaining option. What defeats that is one copy behind a sign-in of its own, frozen against modification for a fixed number of days.
Thirty dailies, thirteen weeklies and twelve monthlies make a reasonable opening position. Accounting records run far longer, since French commercial law expects several years of them, and health records answer to separate rules again. Those durations belong to your accountant or your lawyer; we turn whatever they specify into settings.
The regulation asks, in so many words, that you be able to bring personal data back within an appropriate time. Organisations inside the NIS2 perimeter are expected to manage continuity and to show their working. Dated recovery notes are exactly that evidence, whether the question arrives from an auditor or from the French supervisory authority. Whether NIS2 catches your organisation is a legal matter, and not ours to rule on.
Either a colleague on your side, talked through it stage by stage, or the engineer you already call locally. Hardware is neither shipped nor fitted by us. What we contribute is the diagnosis, the exact bay number, and every task achievable across the wire: array rebuild, data recovery, and the consistency checks that follow.
Your present configuration gets examined remotely, a genuine recovery is attempted from it, and you hear a straight answer about whether it would carry the company through a bad day.
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
Nothing here under that name. Check the spelling, or simply choose the nearest large city instead. Since every engagement runs remotely, whichever you pick changes nothing about what we do for you.