Atlas Resilience
Backup & Disaster Recovery
3-2-1 backups with restores actually tested before handover — immutable on-site snapshots and encrypted offsite copies you own outright.
Why this exists
Without Atlas Resilience
Backups run nightly to a NAS in the same room as the servers. A water leak destroys everything. Nobody has tested a restore in 18 months — when last tested, the backup was corrupt. A ransomware attack encrypts both primary storage and the network backup because the backup share is mapped on all workstations. DORA Art. 12 requires tested recovery — untested backups do not count.
With Atlas Resilience
Bareos runs full weekly + incremental daily, monitored and restored through the Bareos WebUI — a browser interface for job status, browse-and-restore and role-based (ACL) access, so operators never depend on the console. TrueNAS ZFS snapshots are immutable — ransomware cannot encrypt them because they are read-only. An AES-256 encrypted S3 copy goes to Hetzner Object Storage nightly — geographically separated. Restore is tested on-site before handover. DR runbooks document exact commands to restore each critical service, with expected durations and decision points.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(c) | Backup, disaster recovery, and crisis management capabilities required | Bareos job history · tested restore log · RTO/RPO documentation |
| DORA Art. 12(1) | Documented backup scope, frequency, retention, and tested restoration | Bareos policy export · restore test log with timestamps |
| DORA Art. 12(4) | Backup restoration must be periodically tested, not just configured | Restore test log · RTO measurement · sign-off by IT lead |
| GDPR Art. 32(1)(c) | Backup ensures availability and resilience of personal data processing | TrueNAS replication log · S3 offsite backup confirmation |
| BSI OPS.1.2.2 | Documented DR procedures, tested restore, recovery time targets | DR runbook · tested restore certificate · RTO/RPO targets |
| BSI OPS.2.2 | 3-2-1 rule, encryption, offsite copy, regular restore test required | Bareos config · TrueNAS snapshot log · S3 access log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
Bareos backup — standalone
Bareos 22.x director + storage daemon + file daemon on up to 5 hosts. Full weekly + incremental daily schedule. Email report on completion/failure. Zabbix alert on failure. Retention policy configured. Restore test included.
€ 990
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteS3 offsite backup config
Configure AES-256 encrypted offsite backup to S3-compatible storage (Hetzner Object Storage, AWS S3, or Backblaze B2) for existing backup solution. Retention policy, cost estimate, first successful backup verified.
€ 590
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteDR runbook creation
Document and test recovery for up to 3 critical services. Each runbook: recovery steps, Vault credential references, expected recovery time, dependencies, decision tree. One live recovery test per service.
€ 790
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteFull integration
Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.
5–50 users · 1 site · 1 month on-site
from € 12,000
Net, excl. VAT · fixed price scoped by audit
50–500 users · multi-site · 3 months on-site
from € 36,000
Net, excl. VAT · fixed price scoped by audit
500+ users · multi-site · 6 months on-site
from € 84,000
Net, excl. VAT · fixed price scoped by audit
All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.
Request audit engagementCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz