Short answer: no honest provider can promise your compliance on their own, because compliance covers how your whole business handles data. What we can do, and do, is make sure the backup side meets the standards that apply to you and give you the evidence an auditor will ask for.
What regulators and auditors tend to look for
| Area | What good looks like |
|---|---|
| Data protection (UK GDPR) | Personal data can be restored after an incident, and security measures are proportionate and documented |
| Retention | Backups kept for as long as you need them and no longer, with a clear policy |
| Access control | Only named people can access or restore backups, protected by multi-factor authentication |
| Location of data | You know where backups are stored and that the location suits your obligations |
| Evidence | Backup logs, restore test records and a written recovery plan |
How we support you
- Identify your obligationsWhich rules apply to you, such as UK GDPR or sector requirements from your regulator or insurers.
- Match the backup to themRetention, encryption, storage location and access settings configured accordingly.
- Produce the paperworkReports and records that answer an auditor questions without a scramble.
- Review each yearRules and your business both change, so we revisit the set-up regularly.
Sources and further reading
Want this looked after for you?
ABCOM has supported Sussex businesses and charities since 1996 and is an NCSC Assured Service Provider – Cyber Advisor (Cyber Essentials). Talk to a real person about your IT.
Also read
How ABCOM can help
Talk to a real person at our Burgess Hill office. We are an NCSC Assured Service Provider and have supported Sussex businesses since 1996.