Back to blog
Backup and Disaster Recovery: Why “We Have a Hard Drive” Is Not Enough

Security · 20 May 2026

Backup and Disaster Recovery: Why “We Have a Hard Drive” Is Not Enough

Adrian CosmaAuthorAdrian CosmaUNICORE Author · Digital transformation & technology

“We have a backup: it is on a hard drive in the drawer” sounds comforting — until the disk is in the same room as the burning server, ransomware encrypts the copy too, or nobody has restored for two years. Real backup is not an object. It is a process: copies, separation, tests, time to recover. At UNICORE that ties to cloud (where copies live) and cybersecurity (how you stop an attack from killing the backup too).

Backup ≠ disaster recovery. Backup = you have a copy of the data. Disaster recovery (DR) = you know how to get back to work after an incident (fire, ransomware, human error, cloud outage). You can have copies and still face 3 days of downtime if nobody knows the steps, passwords, or service order.

The 3-2-1 rule, briefly. Keep at least 3 copies of important data, on 2 different media types, with 1 copy off-site (another location or a separate cloud). The office hard drive is often “1 copy on 1 medium in the same place” — the opposite.

RPO and RTO without jargon. RPO (Recovery Point Objective): how “fresh” the copy must be — how much work you accept losing (1 hour? 24 hours?). RTO (Recovery Time Objective): how quickly you must be back online. A city hall with digital registry and an online shop have different numbers — but both must write them down, not guess in a panic.

Why ransomware makes a local HDD dangerous. If the disk is always on the network (or mapped as a drive), malware can encrypt it with the server. That is why immutable / offline / separately retained copies matter — and least-privilege accounts. “We have a backup” without isolation is often an illusion.

The test many skip: restore. An unverified backup is a hope, not a guarantee. Schedule periodic restores (file, database, VM — whatever matters). Note real time: that is your real RTO, not the brochure one. Document steps so someone outside IT can start.

Cloud does not automatically mean “we are saved.” The provider protects infrastructure; you own your data and configuration (shared responsibility). Accidental delete, compromised account, region outage — all need backup policies and sometimes a second region. Choose where copies live and who holds the keys.

Conclusion. “We have a hard drive” is a timid start, not a plan. Backup + DR means separated copies, clear objectives (RPO/RTO), restore tests, and a link to security. If you want a short audit of the current situation (what is saved, what is not, how long recovery takes), contact us.

Frequently asked questions

Why is an office hard drive not enough?+

It sits in the same place as incidents (fire, theft, network ransomware), is rarely restore-tested, and is often a single copy. Real backup needs separated copies and a recovery plan.

What is the 3-2-1 rule?+

At least 3 copies of the data, on 2 media types, with 1 copy off-site. It reduces the risk that one event wipes everything.

What do RPO and RTO mean?+

RPO = how fresh the copy must be (how much you can lose). RTO = how quickly you must be operational again. Both are decided before an incident.

Does the cloud automatically include backup?+

Not necessarily. The provider protects infrastructure; you configure retention, copies, and restore. Check the policy — do not assume.

How often should restore be tested?+

At least periodically (quarterly is a reasonable minimum for many organizations) and after major changes. Without a test, backup is a hope.

Digital transformation never stops

Have a digital challenge? Let's turn it into a real advantage — clear consulting, an actionable plan, and a team ready to deliver.

Contact us