Almost every business we speak to in Malta has a backup. Far fewer can tell you how long it would take to get people working again after losing a server on a Tuesday morning.
Those are two different questions, and only one of them is ever asked in advance.
A backup job that reports success tells you the job ran. It tells you a process started, read some data, wrote it somewhere and exited without an error. It does not tell you the restore works, that the data is complete, or that anyone in the building knows the sequence to bring a system back. That distinction only ever matters once, and by the time it matters it is too late to find out.
The Report Is Green. That Is All It Says.
Backup software is good at reporting on itself. A green status means the job completed against the targets it was pointed at. It carries no opinion on whether those targets are still the right ones.
Systems drift. A new file server goes in and nobody adds it to the job. A finance application moves to a different volume. A virtual machine is rebuilt and the agent is never reinstalled. Each of these leaves the schedule reporting success while quietly protecting less than it did last quarter.
The only test that answers the real question is a restore. Not a verification pass, not a checksum, an actual file or system brought back and opened by a person who confirms it is what it should be. Three questions worth answering honestly:
- When did someone last restore something and check it opened?
- If a server failed this afternoon, how many hours until people could work? Not how many hours until the data came back, how many until the business ran.
- Is Microsoft 365 included in that answer, or assumed?
The third one catches most people.
The Microsoft 365 Gap
Microsoft operates a shared responsibility model, and it is written plainly in their own documentation. Microsoft keeps the service running. Microsoft does not keep a backup of your data on your behalf.
That is not a technicality, and it produces three failures that Maltese businesses hit regularly:
A mailbox deleted past its retention window. Retention is not backup. Once the window closes the mailbox is gone, and the window is shorter than most people assume.
Files removed from SharePoint months ago and only noticed now. The recycle bin is a convenience feature with a time limit, not an archive.
Ransomware that encrypts a synced OneDrive folder. Sync does what it is designed to do and replicates the encrypted version everywhere, including the copy in the cloud. A second location is not a second copy if the two are synchronised.
None of this means Microsoft 365 is unsafe. It means the responsibility for the data inside it sits with the business, and a lot of businesses have never read the line that says so.
Recovery Time Is the Number That Costs Money
Most backup conversations optimise for how much data you would lose. That number matters, but it is rarely the one that hurts.
The number that hurts is how long the business stops. Losing four hours of data is a bad morning. Losing four days of trading while someone rebuilds a server from a backup nobody had tested is a different order of problem, and it is the one that shows up in the accounts.
The two are measured separately for a reason:
- How much data you can afford to lose determines how often backups run.
- How long you can afford to be down determines what kind of recovery you need to have ready.
A business can have hourly backups and still be down for three days, because frequency of copying says nothing about speed of returning to work. Whenever the second number has never been agreed, the honest answer to “how long would we be down” is that nobody knows.
What Cove Data Protection Does Differently
Cove Data Protection, part of the N-able stack, is built around recovery rather than around the backup job.
It is cloud-first, which means the primary copy goes to cloud storage rather than to a local appliance that has to be bought, housed, powered and eventually replaced. For a business without a second site, that removes the awkward question of where the offsite copy actually lives.
It covers servers, workstations and virtual environments, and it covers Microsoft 365 as a first-class workload, including Exchange, OneDrive, SharePoint and Teams. That directly addresses the gap above rather than leaving it to a separate tool and a separate renewal.
It is built for recovery testing, so proving a restore works is a routine task rather than a project nobody schedules.
The point is not that a product removes the need to think about recovery. It is that the thinking should happen now, in a planning conversation, rather than at 08:00 on the morning a server does not come back.
A Reasonable Place to Start
You do not need a full disaster recovery programme to make progress this quarter. You need three things written down:
- A tested restore. One system, one file, restored and opened by a person, with the date recorded.
- An agreed recovery time for the two or three systems the business genuinely cannot trade without.
- A clear answer on Microsoft 365. Backed up by something specific, or knowingly accepted as a risk. Either is a decision. Assuming is not.
If those three exist and are current, the backup is doing its job. If any of them cannot be answered today, that gap is worth closing before the quarter closes.
Talk to 4TFront
4TFront is the Authorised N-able Distributor in Malta. We supply Cove Data Protection to internal IT teams and to the IT providers who look after other businesses, and we advise on sizing, retention and what a sensible recovery target looks like for the way a business actually operates.
If you want a second opinion on whether your current backup would survive a real restore, that is a conversation worth having before you need the answer.
Request Cove pricing or a recovery review: sales@4tfront.com or +356 2124 8205.
