Backup and Disaster Recovery as a Managed Service
Backup and disaster recovery (BCDR) as a managed service protects the data and uptime a business cannot operate without, as a recurring, high-margin offering. Backup is a copy of data; disaster recovery is the tested ability to resume operations. According to Sophos research, tested, isolated backups are the most effective ransomware defense.
Backup and disaster recovery (BCDR) as a managed service protects the data and uptime a business cannot operate without, delivered as a recurring, high-margin offering. Backup is a copy of data; disaster recovery is the tested ability to resume operations. According to Sophos research, a large share of organizations are hit by ransomware each year, and tested, isolated backups are the most effective defense.
Backup and disaster recovery is the service clients resent paying for, right up until the day it saves their business. Then it becomes the reason they never leave. That asymmetry, low perceived value until catastrophe, then total dependence, is exactly what makes BCDR one of the most important services an MSP can deliver and one of the most poorly understood. Most failures in this space are not failures of backup; they are failures of recovery, and understanding the difference is what separates an MSP that protects clients from one that merely stores their data.
Backup Is Not Recovery
The most dangerous misconception in this space is that having backups means you are protected. Backup is a copy of your data; disaster recovery is the ability to actually resume operations after an outage. Those are not the same thing. A business can have months of backups and still be down for days if the restore process is slow, untested, or incomplete.
True BCDR includes the plan, the infrastructure, and the tested process to bring systems back within an acceptable timeframe. MSPs that sell backups without recovery planning leave clients exposed at the exact moment protection matters most. The product you are really selling is not storage; it is the confidence that the business can be running again quickly, which is a far more valuable and defensible thing to own.
RTO, RPO, and Designing the Plan
A real disaster recovery plan starts with two numbers. RTO, the recovery time objective, is how quickly systems must be back after an incident. RPO, the recovery point objective, is how much data loss is acceptable, measured as the time between backups. A business with a four-hour RTO and a one-hour RPO needs frequent backups and fast recovery infrastructure; one that can tolerate a day of downtime needs far less.
Defining RTO and RPO per client is the foundation of both the design and the price, because tighter objectives require more infrastructure and cost more. This is where a disaster recovery readiness assessment earns its place: it surfaces where a client current setup would fail to meet the recovery they assume they have, turning a vague worry into a specific, sellable gap. The assessment is also the natural follow-on to any cloud migration, since a new environment needs a recovery plan designed for it.
Ransomware, Testing, and Recurring Value
Ransomware has turned backup and disaster recovery from a best practice into a necessity. Tested, isolated backups are the single most effective ransomware defense because they let a business restore rather than pay. Sophos and other industry research show a large share of organizations are hit each year, and the ones that recover fastest are those with immutable, off-site, regularly tested backups.
The scale of the threat is the entire case for funding recovery. According to the Sophos State of Ransomware 2024 report, 59 percent of organizations were hit by ransomware in the past year, down from 66 percent in each of the prior two years. The decline is real but small, and a clear majority of organizations are still hit, which is precisely why backup and disaster recovery belongs in every managed agreement rather than being treated as an optional line item.
| Category | Value |
|---|---|
| Prior two years | 66% |
| 2024 | 59% |
Source: Sophos State of Ransomware 2024, 2024A small decline, but a majority of organizations are still hit, which is the entire case for funded backup and disaster recovery.
The key word is tested. An untested backup discovered to be incomplete during an attack is worse than no plan at all, because it traded real protection for false confidence. Regular restore testing verifies the backups are complete, the recovery process works, and the RTO is achievable in practice, and documented DR tests double as a powerful trust signal to show clients in business reviews. Priced per device or workload as a recurring monthly fee, BCDR becomes durable revenue that strengthens both your recurring base and the security posture clients increasingly demand.
The 3-2-1-1-0 Rule, Updated for Ransomware
The longstanding backup standard was the 3-2-1 rule: keep three copies of your data, on two different media, with one copy off-site. Ransomware forced an update, and the version security practitioners and backup vendors now teach is 3-2-1-1-0: the same three copies, two media, and one off-site, plus one copy that is immutable or air-gapped, and zero errors verified through testing. The two added digits are precisely the gaps ransomware exploits. An online backup an attacker can reach and encrypt is not a recovery option, and a backup nobody verified is a coin flip.
For an MSP, the rule is a sales and design tool as much as a technical one. Walking a client through which digit their current setup is missing, usually the immutable copy and the verification, turns a vague sense of being backed up into a specific, fundable gap. The framework gives the conversation a structure the client can follow, and it positions the upgrade as meeting a recognized standard rather than as the provider inventing requirements to bill more.
How Immutability and Air-Gapping Actually Work
Immutability is the single most important advance in backup over the past several years, and clients deserve to understand what they are buying. An immutable backup cannot be altered or deleted for a defined retention window, even by an administrator with full credentials, which is what defeats the modern attack pattern. Ransomware operators no longer just encrypt live data; they hunt for and destroy the backups first, because they know an organization that can restore will not pay. Immutability takes that move off the table.
Air-gapping achieves a similar end by keeping a copy physically or logically disconnected from the network, so it is unreachable from a compromised environment. In practice, many MSPs layer both: immutable cloud storage for fast recovery plus a periodic air-gapped copy for the worst case. The design choice maps directly to the client recovery objectives and budget, which is why it belongs in the same conversation as RTO and RPO rather than being sold as a generic add-on.
A Worked RTO and RPO Tradeoff
The reason RTO and RPO must be set per client, not assumed, becomes obvious with numbers. Take a 30-person accounting firm during tax season. If their RPO is 24 hours, a failure at 4 p.m. can lose a full day of client work, dozens of returns in progress, which during the busy season is unacceptable. Tightening the RPO to one hour means more frequent snapshots and more storage, but it caps the worst-case loss at an hour of work. Likewise, an RTO of two days is fine for a low-stakes internal system and a disaster for the firm core practice-management software.
Pricing follows directly from those numbers. The firm critical systems justify frequent backups, immutable storage, and fast recovery infrastructure, a premium tier, while their archival file shares can sit on a cheaper, slower plan. Presenting clients with a tiered choice grounded in their own tolerance for downtime and data loss is both more honest and more profitable than a one-size plan, and it makes the price feel like a decision the client controls rather than a number the MSP imposed.
The SaaS Backup Gap Most Clients Assume Away
One of the most dangerous misconceptions in the cloud era is that data in Microsoft 365 or Google Workspace does not need backing up because the provider handles it. It does not, at least not the way clients assume. These platforms operate a shared-responsibility model: they guarantee the infrastructure and their own uptime, but recovering data lost to accidental deletion, a malicious insider, or a ransomware-encrypted sync is the customer responsibility, and the native retention windows are short. A file deleted and purged past the recycle window is simply gone.
This gap is one of the clearest backup opportunities an MSP has, and it pairs naturally with any cloud migration. A client who just moved their files and email into Microsoft 365 needs a third-party backup of that tenant precisely because the migration removed the on-premise copy they used to have. Framing SaaS backup as completing the migration, rather than as a separate sale, both protects the client and strengthens the recurring agreement, the same way disciplined recovery planning strengthens the broader managed services relationship.
A Worked Example: Tiering BCDR by Recovery Objective
The reason BCDR prices as a tiered recurring service, rather than a flat one-size fee, becomes clear when the recovery objectives from the worked tradeoff above are attached to real systems. Take the same 30-person accounting firm and sort its systems by how much downtime and data loss each can tolerate. The practice-management software, the system the firm bills from, might carry a tight one-hour RPO and a fast RTO, which the post already established means frequent snapshots, immutable storage, and recovery infrastructure standing ready. The shared file archive of closed prior-year returns, by contrast, can sit at the looser 24-hour RPO and the two-day RTO the example used for low-stakes systems, on cheaper, slower storage.
Those two objectives describe two different products at two different costs, which is exactly what justifies a tiered price the client can see and choose. The premium tier protecting the practice-management software has to satisfy the full 3-2-1-1-0 standard the post described, three copies on two media with one off-site, one immutable, and zero errors verified by testing, because a system with a one-hour RPO that turns out to have an unverified or reachable backup is the worst-case ransomware scenario. The archive tier can run leaner. Presenting the firm with that split, premium recovery for the systems that bill, economy recovery for the systems that merely store, turns the price into a decision the client controls rather than a number imposed on them, and it lets the MSP put its most expensive infrastructure only where the recovery objective actually demands it.
The ransomware case is what makes the premium tier non-negotiable rather than optional, and this is where the one cited figure does the work. Because Sophos research shows a large share of organizations are hit by ransomware every year, the firm should price as though an incident is a question of when, not if, for at least its critical systems. The tier protecting the practice-management software is therefore not an upsell padding the bill; it is the line item that lets the firm restore in an hour instead of paying a ransom or losing days of tax-season work. Framed that way, the higher tier sells itself, because the alternative the client is implicitly choosing by declining it is paying an attacker and hoping. That asymmetry, modest recurring premium against catastrophic worst case, is the entire economic argument for designing BCDR around recovery objectives rather than selling a single undifferentiated backup.
The tiering also disciplines the MSP own margin, which is the part owners overlook when they quote a single flat backup fee. Recovery infrastructure that can hit a one-hour RPO costs the provider materially more to stand up and maintain than nightly snapshots to slow storage, so an MSP that charges one undifferentiated price either overcharges the clients whose archives never needed fast recovery or, more dangerously, underprices the critical-system protection and quietly absorbs the cost of the infrastructure the tight objective demands. Mapping each system to the recovery objective it actually requires, and pricing each tier to the infrastructure behind it, is what keeps the service profitable as the client environment grows rather than letting the most demanding workloads silently erode the margin on the whole agreement.
Building a DR Testing Cadence Clients Can See
Because testing is the digit most often skipped, the MSPs that take recovery seriously formalize it into a schedule rather than leaving it to good intentions. A practical cadence pairs automated daily verification that backups completed and are restorable with a deeper, scheduled restore test on a quarterly or semiannual basis, where an actual system is recovered into an isolated environment and timed against its RTO. The test produces a written result: what was recovered, how long it took, and any gaps found and fixed.
That documented result is where operational discipline becomes visible value. Bringing a clean DR test report to a client review turns an invisible background service into proof, the client can see that the protection they pay for actually works, which is exactly the kind of evidence that defends retention. An MSP that can say it has tested and verified recovery, with the report to show for it, is selling something fundamentally different from a competitor who merely promises backups exist.
Related: how MSPs add cybersecurity services.
Related: guiding clients through cloud migration.
Related: help desk metrics that matter for MSPs.
Related: lead generation for IT service providers.
Summary
Key takeaways
- BCDR is essential, recurring, and high-margin, and ransomware has made it non-negotiable for clients
- Backup is a copy of data; disaster recovery is the tested ability to resume operations, the two are not the same
- RTO (recovery time) and RPO (acceptable data loss) per client drive both the DR design and the price
- Tested, immutable, off-site backups are the most effective ransomware defense; an untested backup is a hope, not a capability
Part of the IT Services cluster.
Try the Disaster Recovery Readiness
Sell recovery, not just backup. Embed an assessment that shows a client where their recovery plan would fail, then design the BCDR service that closes the gaps.
Adam
Founder, CalcStack
Adam built CalcStack to help businesses turn website visitors into qualified leads using interactive content. The platform now serves hundreds of tools across every major industry.
Follow on X