01 Solution · NIS2 resilience
Disaster recovery services that start at the backup and end in operations
The NIS2 directive requires an operation that can be demonstrably restored. Germany transposed that on 6 December 2025 with no transition period, and every other member state has its own national act. Our disaster recovery services cover the technical side of it: backup architecture, immutable copies, rehearsed recovery procedures and the operations around them. The legal assessment is not part of it.
- In force in Germany since
- 6 December 2025, with no transition period
- Under BSI supervision
- around 29,500 organisations instead of about 4,500
- Fines
- up to EUR 10 million or 2 per cent of worldwide annual turnover
- Operations
- 24/7 with on-call cover, patch and escalation management
02 Starting point
The backup has reported green for months and has never been through a real recovery
Four points that fail together in an incident and show up separately in an audit.
The full restore has never run
The job completes without errors and single files come back. Whether a complete system can be rebuilt from it within the time the business needs has not been checked by anyone. The first real test is then the incident itself.
RPO and RTO are not written down anywhere
Without target values per application there is no yardstick, neither for the architecture nor for the evidence. The law prescribes no fixed figures, it requires measures that match the risk. The reasoning is yours to make.
Every copy hangs off the same data centre
The backup server sits next to production and is reachable through the same accounts. Ransomware takes both. Without physical separation and immutable copies the chain breaks at a single point.
The documentation would not survive an audit
What exists are screenshots and the experience of individual people. What is required is documentation an auditor can follow: procedures, target values, test records, deviations.
Technically these are four building sites, in regulatory terms one. Section 30 (2) no. 3 of the German BSIG, the national wording of Art. 21 (2) (c) of the directive, requires backup management, recovery after an incident and crisis management, binding since 6 December 2025 and without a transition period.
03 The solution
Disaster recovery services, from gap assessment to rehearsed restore
Six building blocks, one point of contact: business continuity and disaster recovery solutions that we build and then run. All of it is platform and operations work. Where the line to legal advice runs is set out further down.
Technical gap assessment
We compare your current backup and recovery position with the technical minimum requirements: backup management, recovery after an incident, crisis management. The result is a list of gaps, sorted by risk, with the effort noted per item.
RPO and RTO per application
For every application we record how much data loss and how much downtime the business can carry. Technology comes after that: these target values determine the architecture, not the other way round.
Geo-redundant backup path
Copies in a second German data centre, separated from production and with their own access paths. The backup server is not a neighbour of the systems it is meant to protect. The data centres are ISO 27001 certified.
Immutable and separated copies
An immutable backup means that for a defined period nobody can change or delete the copy, not even with administrative rights. Alongside it a copy without a permanent network connection. That is the 3-2-1 backup rule in its current form.
Documented procedures and a first full run
Before operations are handed over, a recovery runs through once from end to end, recorded, with measured times against the agreed target values. Whatever does not hold is corrected.
Managed backup and disaster recovery
In operations: restore tests at agreed intervals, monitoring, patch and escalation management around the clock, records in a form an auditor can use. The evidence accumulates continuously instead of being assembled shortly before an audit.
04 How it works
Three phases, with a go or no-go decision at every handover
Consulting, transition and operations from one source: one contract, one team, one responsibility.
Phase 01
Consulting
A survey of the current backup and recovery position, target values for RPO and RTO per application, comparison against the technical duties. The result is a prioritised list of gaps, not a slide deck.
Phase 02
Transition
Building the backup and DR path, geo-redundant and with immutable copies. Plus the recovery procedures in writing and one complete test run before anything counts as finished.
Phase 03
Operations
Managed backup and disaster recovery around the clock, with restore tests at agreed intervals, on-call cover and evidence maintained as you go. The configurations stay with you as repositories.
Organisations that are changing the platform anyway, away from VMware or back out of the public cloud, get the backup and DR path right in the same move.
05 Proof
Availability shows in operations, not in the concept
Three customers for whom recovery and continuous operations were the actual brief.
06 Read on and check
Free whitepaper · 8 pages
Digital Sovereignty
By Andreas Hankel, CTO onehundred. Download in exchange for your e-mail address, no sales call.
07 To be honest
What you are right to ask at this point
“We already have a backup.”
Most likely you do. The question is not whether data is being backed up. It is when a complete system was last brought back, how long that took and where it is recorded. In most cases the last full restore is further back than people assume.
“So you handle our NIS2 compliance?”
No, and that is deliberate. We are responsible for the technical implementation: backup, recovery, operations and the evidence that comes out of it. The legal scope assessment, building an ISMS and the governance and reporting processes are not part of it. For those we work with specialised partners.
“Then we depend on you whenever we need to recover.”
Only if we moved you onto a closed platform. We do not. The stack is open source and documented, the configurations stay with you as repositories. Any competent provider can take over operations, and a recovery that works without provider lock-in is part of the evidence anyway.
“We are not even sure whether we are in scope.”
Then start with the classification, not with the technology. Sector, entity type and size decide it, and the thresholds sit in the national act of the member state you operate in. Our overview of the NIS2 directive sets out the criteria. Either way a rehearsed recovery pays for itself the moment an outage lasts longer than a day.
08 Fasttrack analysis
A conversation in which the gaps get named
Non-binding, with someone who runs platforms. Bring what you back up today and how long a recovery is allowed to take. If your current position already holds, we say so.
15 minutes · not a sales call · book directly in the calendar
09 Frequently asked questions
Common questions about backup and disaster recovery under NIS2
What do your disaster recovery services include?
What does NIS2 require for backup and disaster recovery?
What is an immutable backup?
What is business disaster recovery?
How often do restore tests have to be run and documented?
What is managed backup and disaster recovery as a service?
How do we evidence the technical implementation to an auditor?
Does onehundred carry out the legal scope assessment?
10 Insights · NIS2 and digital sovereignty
Further reading
The overview of the directive, the sovereignty question behind it and the groundwork for securing day-to-day operations.

Book a call