Backup and disaster recovery | High Point, NC
Data Backup and Disaster Recovery for North Carolina Businesses
Preferred Data backs up the workstations and Microsoft 365 of North Carolina manufacturers and small businesses, then proves the backups work by restoring from them. Restore-tested backup is included in every managed IT plan, run from our High Point office with on-site help within 200 miles. Book a backup review to learn how fast you could recover today.
The 3-2-1 rule
What a recoverable backup looks like
- 3copies of important files
- 2different types of storage
- 1copy off-site
Plus the step that proves it works: we test backups by restoring from them.
Restore-tested backup is in every plan- In business since 1987
- 39 years
- Active clients
- 100+
- Average client tenure
- 20+ years
- BBB Accredited rating
- A+
- On-site radius from High Point
- 200 mi
- Threat monitoring on every plan
- 24/7
What does business backup and disaster recovery include?
Backup is the copy of your data; disaster recovery is the plan and practice for getting the business running again from that copy. At Preferred Data, every plan includes restore-tested backup of workstations and Microsoft 365, and servers and line-of-business systems are counted during discovery and covered on the same agreement.
We treat a backup as unproven until someone has restored from it. That is why the pricing page says "restore-tested", not just "backed up": a green checkmark in backup software tells you a job ran, not that the files, mailboxes or databases will open when you need them.
Backup sits inside managed IT services, so the team that restores your files is the same team that patches your machines and answers your help desk calls. When a disaster is a cyberattack, the same team also runs the 24/7 threat detection and response that is in every plan.
- Workstations and Microsoft 365: backed up and restore-tested on every plan, not sold as an add-on.
- Servers, file shares and business applications such as ERP and accounting: counted during discovery and planned to the recovery targets you set.
- Disaster recovery planning: which systems come back first, who makes the calls, and where people work if the building is unusable.
- Anything outside the plan, such as new backup hardware or a server replacement, is quoted in writing before work starts.
Key takeaway: A backup you have never restored from is a hope, not a plan. Restore testing is included in every Preferred Data plan.
What is the 3-2-1 backup rule?
The 3-2-1 rule means keeping 3 copies of important files, on 2 different types of storage, with 1 copy stored off-site, away from your business location. CISA recommends it for small and medium businesses because a single fire, flood, theft or ransomware attack should never be able to reach every copy at once.
Ransomware changed what "off-site" has to mean. CISA warns that many ransomware variants attempt to find and then delete or encrypt accessible backups, so it recommends offline, encrypted backups and notes that some cloud vendors offer immutable storage that cannot be altered once written. A backup drive that stays plugged into the server is on-site and online, within reach of anything that reaches the server.
Our article on immutable backups explains the difference between a copy that is off-site and one that an attacker with your admin password still cannot delete.
- Is at least one copy stored away from your building?
- Could someone with a stolen administrator password delete or encrypt every copy?
- Can you roll data back at least seven days, as CISA advises, in case an infection sat unnoticed for a week?
- When was the last time anyone restored a full system, not just a single file?
What are RTO and RPO, and how should a small business set them?
Recovery time objective (RTO) is how long a system can be down before it hurts the business; NIST defines it as the time a system can be in the recovery phase before negatively impacting the mission. Recovery point objective (RPO) is the point in time to which data must be recovered, which in practice is how much recent work you can afford to re-enter.
| Question | External drive or local device only | File sync (OneDrive, Dropbox) only | 3-2-1 backup with restore testing |
|---|---|---|---|
| Survives a fire, flood or theft at the building? | No, the copy is in the same place | Files yes; servers and applications no | Yes, one copy is off-site |
| Survives ransomware that reaches the network? | Rarely, it is usually online and reachable | Not reliably, sync can copy encrypted or deleted files | Designed to, with an offline or immutable copy |
| Brings back a whole server or ERP system? | Only if it is a full image | No, sync covers documents only | Yes, systems are planned to their RTO |
| Recovers email deleted more than 30 days ago? | No | No, Exchange Online keeps deleted items 14 days by default, 30 at most | Yes, within the backup's retention period |
| Proven to work before an emergency? | Only if someone tests it | Only if someone tests it | Yes, restores are tested |
The two numbers drive the cost of a backup design, so we set them per system rather than for the whole company. If backups run once a night, your RPO is up to a day of work; if an order entry system cannot be down for more than a few hours, restoring it from a slow internet download may not meet its RTO.
For a North Carolina manufacturer, the ERP, order entry and shipping systems usually need the tightest targets, while archived drawings or old project files can wait. Our guide to setting RTO and RPO walks through the questions, and our manufacturing disaster recovery guide covers plant-specific planning.
Can backups help you recover from ransomware without paying?
Yes, if the attacker could not reach them. In Sophos's 2025 survey of 3,400 IT leaders, only 54% of organizations used backups to restore their data, the lowest share in six years, and nearly half paid the ransom. In manufacturing, 51% still paid, even though backup use held at 58%.
Recovery is expensive either way. Sophos put the average cost of recovering from a ransomware attack at $1.53 million in 2025, excluding any ransom, and the mean recovery cost for manufacturers at $1.3 million. Backups the attacker could not reach are what turn that from weeks of rebuilding into a planned restore.
Recovery also depends on what happens before the restore: finding how the attacker got in, removing them, and making sure the data you restore is clean. Our ransomware recovery plan guide covers the order of operations.
- In manufacturing, 40% of attacks in Sophos's data resulted in data being encrypted, which is the moment backups either work or do not.
- Multi-factor authentication, patching and 24/7 threat detection and response are in every plan, so fewer attacks reach the point of needing a restore.
Key takeaway: Backups are only a ransomware defense if the attacker cannot delete them and someone has proven they restore.
Does Microsoft 365 need its own backup?
Yes. Microsoft's own shared responsibility model says that for all cloud deployment types, you own your data and identities, and the customer is responsible for data protection in Microsoft 365 just as on your own servers. Exchange Online, for example, keeps deleted mail in its Recoverable Items folder for 14 days by default and a maximum of 30.
Microsoft keeps the service running. It does not promise to bring back a mailbox a former employee emptied two months ago, a SharePoint library an attacker encrypted through a synced laptop, or files deleted before anyone noticed. That is what a separate backup is for.
Every Preferred Data plan includes restore-tested Microsoft 365 backup along with the Microsoft 365 licensing itself. Our article on the Microsoft 365 shared responsibility gap goes further, and our cloud solutions page covers migrations to Microsoft 365.
How often should backups be tested?
Often enough that a failure is found by you, not by a disaster. CISA advises small businesses to test backup procedures so the team can restore data both fully and partially, and its ransomware guide says to regularly test the availability and integrity of backups in a disaster recovery scenario.
A useful test restores something real and checks that it opens: a mailbox, a shared folder, a server into a test environment, an ERP database the software can read. Checking only that a backup job finished is how a business finds out, on the worst possible day, that the backup was empty or incomplete.
We verify backups by restoring from them as part of every plan. Our backup testing guide lists the tests worth running if you manage backups yourself.
- Test a single-file restore and a full-system restore; they fail for different reasons.
- Time the full restore, and compare it with the RTO you set for that system.
- Keep a short record of each test so an insurer or auditor can see restores were proven, not assumed.
Why choose a North Carolina provider for backup and disaster recovery?
Because recovery is often hands-on. Preferred Data has served North Carolina businesses from High Point since 1987, has more than 100 active clients with an average tenure of over 20 years, and can put an engineer on site anywhere within 200 miles, including the Piedmont Triad, Charlotte and Raleigh.
A national backup vendor can store your data. When a server dies at a furniture plant in High Point or a distribution center in Greensboro, somebody still has to rebuild the hardware, restore the system and get the shipping labels printing again. On Preferred Professional, onsite visits are included when a problem cannot be fixed remotely, and Preferred Complete includes unlimited onsite support and 24/7 help desk coverage.
We also know the systems North Carolina manufacturers depend on, including ERP and accounting software we have built and supported since 1987, so a restore plan covers the software, not just the files. See our work for manufacturers, furniture companies and logistics operations.
- Compare what each plan includes on the pricing page, then book a review of your current backups.
- Check your wider security posture with the free cybersecurity assessment tool.
Related services
Free backup and recovery policy templates
Write down what gets backed up, how often, and how fast you must recover, plus who does what when an incident hits. Read each template in full, then build your own in a few minutes.
Data Backup and Recovery Policy template
Define what gets backed up, how often, where copies live and how fast you must recover, using the 3-2-1-1-0 rule that ransomware now demands.
Incident Response Plan template
Know exactly who does what in the first hours of a ransomware attack, data breach or business email compromise, including who to call and which notification clocks start.
Backup and disaster recovery questions we hear most
How much do backup and disaster recovery services cost in North Carolina?
At Preferred Data, restore-tested workstation and Microsoft 365 backup is included in every managed IT plan, which is priced per user per month rather than billed as an extra. Servers and other equipment are counted during discovery and covered on the same agreement, and new backup hardware or projects are quoted in writing before work starts. The quote is free.
Is backup included in every managed IT plan?
Yes. Preferred Essentials, Professional and Complete all include restore-tested backup of workstations and Microsoft 365, along with 24/7 threat detection and response, multi-factor authentication, patching, email threat protection and security awareness training. No plan is sold with backup removed.
Do you monitor backups 24/7?
What runs around the clock on every plan is threat detection and response, with endpoint management and patching monitored 24/7. Help desk support is business hours on Essentials, extended hours on Professional, and 24/7 including nights and weekends on Complete. Backups themselves are verified by restoring from them, not by trusting a success message.
What is the difference between backup and disaster recovery?
Backup is a copy of your data. Disaster recovery is the plan for restoring systems in the right order, within the downtime (RTO) and data loss (RPO) the business can tolerate, and for where people work while that happens. You need both: a backup with no plan is slow to use, and a plan with no tested backup cannot be carried out.
Is OneDrive or SharePoint a backup?
Not on its own. Sync keeps copies current, which means it can also copy a deletion or an encrypted file, and Microsoft's shared responsibility model leaves your data as your responsibility in Microsoft 365. A separate Microsoft 365 backup, included in every Preferred Data plan, is what lets you go back further.
What RTO and RPO should a small manufacturer target?
There is no single right number; it depends on what an hour of downtime and a day of re-entered orders actually cost you. Most businesses set the tightest targets for ERP, order entry and shipping, and looser ones for archives. We work through those targets with you during discovery and design the backup to meet them.
Can you come on site after a server failure or disaster?
Yes. Our office is in High Point and we provide on-site service within 200 miles, which covers Greensboro, Winston-Salem, Charlotte, Raleigh and most of North Carolina. Onsite visits are included on Preferred Professional when a problem cannot be fixed remotely, and Preferred Complete includes unlimited onsite support.
Sources
- CISA, Back Up Business Data (small and medium businesses)
- CISA, #StopRansomware Guide
- NIST CSRC Glossary, Recovery Time Objective (from NIST SP 800-34 Rev. 1)
- NIST CSRC Glossary, Recovery Point Objective (from NIST SP 800-34 Rev. 1)
- Sophos, State of Ransomware 2025 press release (June 2025)
- Sophos, The State of Ransomware in Manufacturing and Production 2025
- Microsoft Learn, Shared responsibility in the cloud
- Microsoft Learn, Recoverable Items folder in Exchange Online
How fast could you recover tomorrow?
Tell us which systems your business cannot run without. We will review what is backed up today, where the copies live, and whether anyone has restored from them, then put our recommendation in writing.
Preferred Data Corporation, 1208 Eastchester Drive, Suite 131, High Point, NC 27265