Backup and Recovery is the set of processes, technologies, and policies that ensure data and system state can be copied to a secondary store and restored to a known-good condition following data loss, corruption, or infrastructure failure. It encompasses full, incremental, and differential backup strategies alongside recovery time objectives (RTO) and recovery point objectives (RPO) that define acceptable loss and restoration windows.
Content
- Formalised backup practices emerged alongside early mainframe computing in the 1960s, when tape drives provided the primary backup medium. The discipline evolved through RAID arrays in the 1980s and 1990s, snapshot-based backup in the 2000s, and cloud-integrated continuous backup from the 2010s. Ransomware threats from the mid-2010s onwards have made air-gapped and immutable backup storage a critical design requirement.
- Technically, backup strategies are categorised as full (complete copy of all data), incremental (changes since last backup), and differential (changes since last full backup). Backup systems operate at block, file, or application levels, with application-consistent backups ensuring databases and stateful services are captured at a transactionally consistent point. Recovery mechanisms include bare-metal restore, virtual machine snapshot restore, granular file-level recovery, and database point-in-time recovery.
- In enterprise environments, backup orchestration platforms such as Veeam, Commvault, and Rubrik provide unified management across on-premises, virtualised, and multi-cloud environments. Cloud-native services including AWS Backup, Azure Backup, and Google Cloud Backup and DR handle backup lifecycle management for cloud-native workloads. Immutable storage targets — using object lock or WORM media — protect backups from ransomware encryption.
- By 2024–2025, backup and recovery has increasingly adopted AI-driven anomaly detection to identify corruption or unexpected data change before backup, improving RPO. Continuous data protection (CDP) approaches that capture every write to a journal have become more accessible. Regulatory requirements under frameworks such as DORA (Digital Operational Resilience Act) in the EU have made documented, tested backup and recovery procedures mandatory for financial institutions.