Salta al contenuto principale
Lympha technologies

Services

Data Protection

Simply taking backups does not mean you are protected.

All too often, multiple copies of the same files are made on unreliable media, with no criteria and no verification: that does not protect you from disasters, viruses, data loss or corruption. Data must be saved methodically, of course, but first of all you need to understand what to protect and how. We start from the value of your processes.

How it works

  • Analysis and policies: data classification, backup criteria, retention and encryption
  • DPaaS (Data Protection as a Service): copies of data, servers or your entire infrastructure in our Green Data Center or in other data centres you trust
  • Periodic restore checks: a backup is only worth anything if it can be restored
  • Careful management of storage space and the resources used

Benefits

  • Pay-per-use subscription: costs always under control, no upfront investment
  • Opens the way to Disaster Recovery even for those without the budget for major projects
  • Protection consistent with the GDPR and your corporate policies
  • Data held in a zero-emissions data centre

Who it is for: any organisation that regards its data as an asset — from the SME starting with managed backup to the large enterprise replicating its entire infrastructure.

From backup to business continuity: the RPO–RTO continuum

Data protection is not a product: it is a position on a continuum. On the left, the question “how much data can I afford to lose?” — that is the RPO (Recovery Point Objective), which looks backwards from the moment of failure. On the right, “how quickly must I be up and running again?” — that is the RTO (Recovery Time Objective), which looks forwards. The definitions are those of the ISO 22301 standard, and the trade-off is structural: the closer the two objectives get to zero, the higher the costs and complexity. The art lies in placing each service at the right point on the curve — not the whole company at a single point.

The RPO–RTO continuum with recoverability tiers and availability classes Diagram with time on the horizontal axis: at the centre, the moment of failure (T zero); to the left the RPO (from real time to weeks), to the right the RTO (from seconds to weeks). Three horizontal bands show the availability classes and the sites: Backup/Restore on the Core Site, Rapid Data Recovery on the Disaster Recovery site, Continuous Availability on the Business Continuity site. The recoverability tiers rise from the edges towards the centre: Tiers 1 and 2 with backup and restore from tape (days or weeks, disaster recovery scope); Tiers 3 and 4 with continuous backup, software replication and asynchronous replication (hours or minutes); Tier 5 with synchronous replication and standby servers (seconds); Tiers 6/7 at the centre with zero-data-loss systems, inter-site high availability and a tri-data-centre architecture (real time, business continuity scope). Costs and resilience increase with the tier. Continuous Availability Rapid Data Recovery Backup / Restore BC Site DR Site Data Centre Core Site T0 Zero data loss systems Tri-Data Centre Architecture Ethernetreplication Syncreplication High Availabilityinfrasite Syncreplication Ethernetreplication Low speed softwarereplication Standby server DRS/H Standby server Low speed softwarereplication Server rebuild Backup Continuousbackup Asyncreplication Syncreplication Syncreplication Syncreplication Rapidrestore Restorefrom tape TIER 1 TIER 2 TIER 3 TIER 4 TIER 5 TIER 6/7 TIER 5 TIER 4 TIER 3 TIER 2 TIER 1 costs resilience / redundancy time weeks days hours minutes seconds real-time seconds minutes hours days weeks Disaster Recovery Business Continuity Disaster Recovery RPO RTO / NRO T0
The RPO–RTO continuum: the recoverability tiers (SHARE/IBM model) rise from the edges towards the moment of failure (T₀), crossing the three availability classes spread across the three sites — Core, Disaster Recovery, Business Continuity. Simplified diagram: the technologies shown are representative of each tier.

Backup / Restore

Tiers 1–4, on the Core Site: backup, continuous backup, asynchronous replication. Modest costs, back up and running in days or hours. This is DPaaS territory: the first step on the continuum.

Rapid Data Recovery

Tiers 4–6, towards the DR site: software and synchronous replication, standby servers. Back up and running in minutes or seconds, for services that cannot wait.

Continuous Availability

Tiers 6/7, with a BC site: inter-site high availability and zero data loss systems in a tri-data-centre architecture. No data loss, at the highest cost.

Seven tiers, one common language

The framework behind the diagram comes from the seven tiers of disaster recovery defined in 1992 by SHARE — the historic IBM mainframe user group — and later developed with IBM's contribution: from Tier 1 (off-site copies, recovery in weeks) up to Tiers 6/7 (synchronous replication and zero data loss systems). The model is more than thirty years old, but it remains the common language in which business and technical teams agree on capabilities and costs.

The guided path

Moving along the continuum is not a single technological leap: it is a progression to be governed. Our consultancy service supports this progression in five phases:

  1. Assessment and Business Impact Analysis — an inventory of systems, classification by business value, RTO and RPO defined per criticality level: it is the BIA that sets the objectives, not the technology catalogue
  2. Target architecture design — positioning on the tiers and site topology (Core / DR / BC): robust protection for critical systems, lightweight solutions for workloads that can wait
  3. Security integration — resilience is not the same thing as security: ISO/IEC 27031 acts as the bridge between continuity (ISO 22301) and information protection (ISO/IEC 27001, whose control 5.30 in the 2022 edition requires precisely a planned and tested ICT readiness)
  4. Implementation and testing — simulations and drills against the clock: an untested plan is not a plan
  5. Continuous improvement — the whole programme follows the Plan-Do-Check-Act cycle, the same one as our method: objectives and architecture are revisited as threats and requirements change

The result is to turn “we want to be more resilient” into measurable, sustainable objectives, placing each system on the appropriate tier.