TechKnowSurge
VideoSecurityFree

Backup Design Considerations

Designing an effective backup strategy requires evaluating multiple factors, including data criticality, recoverability, cost, recovery objectives, backup windows, security, and how frequently data changes.

Complete this video to capture a CTF flag worth 1 point.

About this video

Building a sound backup strategy starts with understanding the nature of the data itself. A key distinction is whether data is recreatable or nonrecreatable. Recreatable data — such as operating system installations or standard software configurations — can be restored by downloading files, reapplying licenses, and rebuilding the environment, even if doing so takes time and effort. Nonrecreatable data, by contrast, is data that simply cannot be recovered once lost, such as customer records, transaction histories, or proprietary datasets. This category demands the highest level of backup rigor, because its permanent loss can be devastating to an organization's operations, reputation, and legal standing. Criticality and cost are two additional dimensions that shape backup decisions and often intersect in meaningful ways. Data can be nonrecreatable but low in criticality, or highly critical but fully recreatable, and each combination calls for a different level of investment and priority. While storage costs have dropped significantly, the ongoing management overhead of maintaining large backup repositories still represents a real operational expense that must be weighed against the actual value of the data being protected. Operational factors round out the decision-making framework. Recovery point objectives and recovery time objectives define how much data loss and downtime an organization can absorb, directly influencing backup frequency and the speed of recovery systems. Backup windows — the periods during which backups can run without disrupting normal operations — must be planned carefully, particularly when data volumes are large enough to stretch backup jobs across multiple days. Security requirements for sensitive data add another layer of planning, ensuring that backed-up information receives the same protections as live data. Finally, how dynamic the data is — whether it changes rarely or continuously — determines how often backups should run and what backup methodology, such as full, incremental, or differential, is most appropriate for the environment.

What you'll learn

What's covered

Backup Strategy Considerations

Key terms

Recovery Point Objective
RPO
The maximum acceptable amount of data loss measured in time, defining how far back data must be recoverable.
Recovery Time Objective
RTO
The maximum acceptable time to restore a system or service after a disruption.
Data Criticality
A measure of how essential data is to business operations, used to prioritize backup and recovery efforts.
Recreatable Data
Data that can be restored or reproduced from original sources if lost, such as operating system files or installable software.
Nonrecreatable Data
Data that cannot be recovered or reproduced once lost, such as unique customer records or proprietary statistics, making it the highest priority for backup.
Backup Window
The scheduled period of time during which a backup operation is performed, which must be managed to minimize disruption to systems and users.

Topics

Backup Strategy Data Recovery Rpo Rto Backup Windows Data Criticality Disaster Recovery

Transcript

When designing our backup, there's several considerations that we have to think about. So let's start exploring what some of those considerations look like.

When we're choosing a backup strategy, there's going to be several considerations that we're going to have, such as: is it recreatable data? Is it critical? What's the criticality of it? What's the cost? What's the RPO, RTO? What time frames are we trying to achieve from a recovery standpoint? What type of disruption is it going to have? What do the backup windows look like? What does security look like? And how dynamic is the information that we are actually going to be backing up?

Recreatable and Nonrecreatable Data

My employees made fun of me for coining the term nonrecreatable data. I've not heard anybody else say that before, but I think it makes complete sense to me when I say nonrecreatable data. What does that even mean? What does recreatable mean?

Essentially, we have maybe a server. If I'm setting up a server, there is data involved with installing the operating system, getting things set up. There is data and time that I use to set that all up. Now, for the most part, I really don't need to save that. I don't necessarily need a backup of that server. If I need to, I can go download those server install files again. I can put the licensing on again. I can install the software again. I can recreate that server and set it up and get it up and running back to where it was before. It might take some time to do that, but I still can do it. I can figure it out.

But there is some data that once we lose, it's gone. For instance, maybe it's some sort of customer statistics or customer data, or who's logged into your system, or maybe it's some sort of critical data that we have that we can't recreate, that once it's gone it no longer exists. We can't get it back. This is what I would classify as nonrecreatable data. This is the real critical stuff that we need to 100% make sure we got right. This is important too because there are certain time targets that we might have. This is the stuff that if we don't have a good copy of it, it could be devastating to the company or organization.

Now, there are times when that data could be recreatable but it's still very critical, or times when that data we can't recreate but it's not very critical. What are some examples of this? We might have customer identification information, and this is something that once we lose, we could lose it altogether. We could not have it again. Not only that, but it's really critical because we're selling to these customers, so the criticality of this information is really important. We could also have maybe some statistics that we're keeping that is not as important, that we really don't do much with, and so the criticality is really low. It's nonrecreatable, but the criticality of that information is pretty low on the spectrum.

Cost

Something to factor into this is cost. The cost is how much is it going to take to back this up? Maybe this is a large amount of data, for storing this data that's not very critical. That seems like a big waste if it's costing a lot to store it. What I found is that storage costs nowadays are pretty cheap and it's not a very big investment from that perspective. But there are other costs involved in this as well. I have to manage all of this data and I have to keep track of it, and so there's actually a cost to the management of that data as well. We've got to think about the cost of how much is it going to cost to back up this data.

Disruption, RPO and RTO

We also have to take into account how much disruption our systems will have. That is for our end users. Are we going to start losing customers and money if our systems are down for a longer period of time? Same thing when it comes to our internal users: do we lose productivity with that? Here again, that really plays into that recovery point objective and the recovery time objective. How far back are we willing to lose, and how long until we actually recover and get those systems back up and running?

Backup Windows, Security and How Dynamic the Data Is

Another consideration is what do the backup windows look like? Can we just do it on the weekend, or can we do it on the weekdays? What does that look like? Because I've certainly had backup windows, backup times, that extend beyond just a single day if there's a lot of data that you're backing up, and that can be problematic. This is an important factor when you're deciding what you're going to back up and how you're going to back it up.

This also could be very sensitive data. If it's very sensitive data, what security concerns do we have over this? What security considerations should we consider when implementing backup?

Another thing also is how dynamic is this information? Is it like a server that you set up and really doesn't change over weeks or months or even years? Or is this a server that changes constantly, that's pulling in new data all the time? How dynamic this data is might depend on how often we back it up and what our backup solution looks like.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →