ONEHUNDRED

01 Solution · NIS2 resilience

Disaster recovery services that start at the backup and end in operations

The NIS2 directive requires an operation that can be demonstrably restored. Germany transposed that on 6 December 2025 with no transition period, and every other member state has its own national act. Our disaster recovery services cover the technical side of it: backup architecture, immutable copies, rehearsed recovery procedures and the operations around them. The legal assessment is not part of it.

In force in Germany since
6 December 2025, with no transition period
Under BSI supervision
around 29,500 organisations instead of about 4,500
Fines
up to EUR 10 million or 2 per cent of worldwide annual turnover
Operations
24/7 with on-call cover, patch and escalation management

02 Starting point

The backup has reported green for months and has never been through a real recovery

Four points that fail together in an incident and show up separately in an audit.

01

The full restore has never run

The job completes without errors and single files come back. Whether a complete system can be rebuilt from it within the time the business needs has not been checked by anyone. The first real test is then the incident itself.

02

RPO and RTO are not written down anywhere

Without target values per application there is no yardstick, neither for the architecture nor for the evidence. The law prescribes no fixed figures, it requires measures that match the risk. The reasoning is yours to make.

03

Every copy hangs off the same data centre

The backup server sits next to production and is reachable through the same accounts. Ransomware takes both. Without physical separation and immutable copies the chain breaks at a single point.

04

The documentation would not survive an audit

What exists are screenshots and the experience of individual people. What is required is documentation an auditor can follow: procedures, target values, test records, deviations.

Technically these are four building sites, in regulatory terms one. Section 30 (2) no. 3 of the German BSIG, the national wording of Art. 21 (2) (c) of the directive, requires backup management, recovery after an incident and crisis management, binding since 6 December 2025 and without a transition period.

03 The solution

Disaster recovery services, from gap assessment to rehearsed restore

Six building blocks, one point of contact: business continuity and disaster recovery solutions that we build and then run. All of it is platform and operations work. Where the line to legal advice runs is set out further down.

01

Technical gap assessment

We compare your current backup and recovery position with the technical minimum requirements: backup management, recovery after an incident, crisis management. The result is a list of gaps, sorted by risk, with the effort noted per item.

02

RPO and RTO per application

For every application we record how much data loss and how much downtime the business can carry. Technology comes after that: these target values determine the architecture, not the other way round.

03

Geo-redundant backup path

Copies in a second German data centre, separated from production and with their own access paths. The backup server is not a neighbour of the systems it is meant to protect. The data centres are ISO 27001 certified.

04

Immutable and separated copies

An immutable backup means that for a defined period nobody can change or delete the copy, not even with administrative rights. Alongside it a copy without a permanent network connection. That is the 3-2-1 backup rule in its current form.

05

Documented procedures and a first full run

Before operations are handed over, a recovery runs through once from end to end, recorded, with measured times against the agreed target values. Whatever does not hold is corrected.

06

Managed backup and disaster recovery

In operations: restore tests at agreed intervals, monitoring, patch and escalation management around the clock, records in a form an auditor can use. The evidence accumulates continuously instead of being assembled shortly before an audit.

04 How it works

Three phases, with a go or no-go decision at every handover

Consulting, transition and operations from one source: one contract, one team, one responsibility.

Phase 01

Consulting

A survey of the current backup and recovery position, target values for RPO and RTO per application, comparison against the technical duties. The result is a prioritised list of gaps, not a slide deck.

Phase 02

Transition

Building the backup and DR path, geo-redundant and with immutable copies. Plus the recovery procedures in writing and one complete test run before anything counts as finished.

Phase 03

Operations

Managed backup and disaster recovery around the clock, with restore tests at agreed intervals, on-call cover and evidence maintained as you go. The configurations stay with you as repositories.

Organisations that are changing the platform anyway, away from VMware or back out of the public cloud, get the backup and DR path right in the same move.

05 Proof

Availability shows in operations, not in the concept

Three customers for whom recovery and continuous operations were the actual brief.

Aerosoft Simulation software with hard load peaks at product launches and on Black Friday. Availability permanently above 99.9 per cent, the complete stack from network through virtualisation to database from one source. Proxmox · HAProxy · Percona · Redis
GeoMobile Digitalisation partner for public transport, the entire application moved from virtual machines to containers. Availability above 99.9 per cent for years, with markedly shorter deployment cycles. Kubernetes · Traefik · Velero · CephFS · PostgreSQL
Net Connection IT services and enterprise content management, 55 employees. Continuous 24/7 operations without a platform engineer or systems architect in house. Proxmox · MariaDB · Jenkins

06 Read on and check

Cover of the whitepaper Digital Sovereignty

Free whitepaper · 8 pages

Digital Sovereignty

By Andreas Hankel, CTO onehundred. Download in exchange for your e-mail address, no sales call.

07 To be honest

What you are right to ask at this point

“We already have a backup.”

Most likely you do. The question is not whether data is being backed up. It is when a complete system was last brought back, how long that took and where it is recorded. In most cases the last full restore is further back than people assume.

“So you handle our NIS2 compliance?”

No, and that is deliberate. We are responsible for the technical implementation: backup, recovery, operations and the evidence that comes out of it. The legal scope assessment, building an ISMS and the governance and reporting processes are not part of it. For those we work with specialised partners.

“Then we depend on you whenever we need to recover.”

Only if we moved you onto a closed platform. We do not. The stack is open source and documented, the configurations stay with you as repositories. Any competent provider can take over operations, and a recovery that works without provider lock-in is part of the evidence anyway.

“We are not even sure whether we are in scope.”

Then start with the classification, not with the technology. Sector, entity type and size decide it, and the thresholds sit in the national act of the member state you operate in. Our overview of the NIS2 directive sets out the criteria. Either way a rehearsed recovery pays for itself the moment an outage lasts longer than a day.

08 Fasttrack analysis

Nils Hornke
Nils HornkeCEO, onehundred

A conversation in which the gaps get named

Non-binding, with someone who runs platforms. Bring what you back up today and how long a recovery is allowed to take. If your current position already holds, we say so.

15 minutes · not a sales call · book directly in the calendar

09 Frequently asked questions

Common questions about backup and disaster recovery under NIS2

What do your disaster recovery services include?
A technical gap assessment, target values for RPO and RTO per application, a backup path with immutable copies, documented recovery procedures with a full test run, and then managed operations with restore tests at agreed intervals. Legal advice is not included.
What does NIS2 require for backup and disaster recovery?
Art. 21 (2) (c) of the directive lists business continuity: backup management, disaster recovery and crisis management. In Germany that is section 30 (2) no. 3 BSIG. The measures have to match the risk, be documented and work when it matters.
What is an immutable backup?
A copy that cannot be changed or deleted for a defined period, not even with administrative rights. Air-gapped means a copy without a permanent network connection. Both exist so that an attacker with admin rights cannot take the backup along with everything else.
What is business disaster recovery?
It is the ability to bring defined systems back to a defined state within a defined time, rehearsed and recorded. A backup that completes without errors is the precondition, not the proof.
How often do restore tests have to be run and documented?
The law sets no fixed frequency. We agree the interval according to how critical the application is and record every test with the times we measured.
What is managed backup and disaster recovery as a service?
onehundred runs the backup and recovery path around the clock, tests recovery at agreed intervals and maintains the documentation. Your team keeps access and configurations and hands over the on-call duty.
How do we evidence the technical implementation to an auditor?
Through the artefacts operations produce anyway: documented procedures, agreed target values, test records with date and measured duration, change history of the configuration. What makes them usable is continuous upkeep, not preparation shortly before the appointment.
Does onehundred carry out the legal scope assessment?
No. We take responsibility for the technical side. The binding legal classification, the registration with the national authority and the reporting processes stay with you and your legal advisers.