Talk to HTS
Blog · 2026-08-06

Acronis Managed Services for Verkada Customers: Why Verified Backups Are the Real Recovery Plan

For a multi-site healthcare provider, an HTS BCDR rollout turned a 30-day ransomware-recovery scenario into a one-hour, Gold-tier failover — and produced the first monthly insurance-grade PDF the practice could hand to its cyber-insurance broker.

The Backup Gap: Why "We Have Backups" Is No Longer a Recovery Plan

Backups exist in nearly every mid-market IT shop. What does not exist, in most, is the second sentence: a verified, tested, immutable copy that an auditor will accept and a ransomware operator cannot reach. The data has been moving in that direction for years.

Veeam's 2024 Ransomware Trends report found that 96% of ransomware attacks now explicitly target backup repositories, and 76% of those attempts succeed — the operator neutralizes the recovery path before triggering encryption [1]. Sophos's 2024 State of Ransomware puts the average cost to recover from an attack, excluding any ransom, at $2.73 million, a 50% jump year over year [3]. The cost gap is dramatic: organizations with compromised backups face a median recovery cost 8× higher than those with intact backups — $3 million vs. $375,000 [4]. A third of victims who paid the ransom still could not recover their data [1].

Regulators have caught up. HHS OCR (the Department of Health and Human Services' Office for Civil Rights) closed four HIPAA ransomware settlements on April 23, 2026, specifically naming untested backup systems as a control failure alongside missing MFA and inadequate logging, totaling $1.165 million in penalties [7]. The proposed HIPAA Security Rule amendments codify a 72-hour RTO (Recovery Time Objective) and 48-hour RPO (Recovery Point Objective) floor, with annual DR (disaster recovery) testing as a standalone standard [8]. SOC 2 (Service Organization Control Type 2) trust services criterion CC7.5 already requires periodic recovery-plan testing with documented restore results [12].

Three numbers, then, define the gap: 96% of attacks now target backup repositories [1], a single failed recovery averages $3 million [4], and "we have backups" is now an audit finding rather than a control.

What Acronis Managed Services Actually Run, Day to Day

HTS BCDR is the managed wrapper around Acronis Cyber Protect Cloud [14]. HTS already runs Acronis for roughly 59 internal endpoints and customer backups; the product is the customer-facing surface over that investment — the SLA, the verification cadence, the dashboard, and the monthly report.

The technical baseline is image-based plus file-based backup for every protected endpoint and server, with 3-2-1 topology by default: three copies, on two different media, with one off-site [2]. For healthcare and regulated customers, BCDR ships immutable storage on by default, using object lock (a write-once, read-many retention policy) and Acronis notarization. M365 backup — Exchange Online, OneDrive, SharePoint, and Teams — is a separate $4/user/month companion service delivered through RMM / Asio / the ConnectWise portal, not through BCDR or Acronis; Microsoft is explicit that availability of M365 data is its responsibility, but backup of that data is the customer's [14].

Three capabilities sit on top of that baseline. First, Acronis Active Protection: behavioral, not signature-based, ransomware defense that watches process behavior, kills the offending process, and rolls back file changes from a self-protected cache. It has consistently scored 100% ransomware detection in SE Labs and AV-TEST evaluations with no false positives [15]. Second, automated verification: BCDR spins up a protected workload in an isolated network on schedule, validates boot and application correctness, and produces a pass/fail artifact — monthly for the standard tier, weekly for Gold. Third, backup-integrity scanning: every backup is scanned for known indicators of compromise when taken and again when mounted, and the platform refuses to restore a backup containing the known IoC (indicator of compromise) [14].

Disaster Recovery RTO and RPO, Mapped to Workload, Not Customer

A common mistake is to assign one RTO and one RPO to a customer. The right unit is the workload: a file server tolerates a 24-hour recovery; an EHR (electronic health record) production database tolerates minutes. BCDR ships three tiers, mapped to industry resilience bands [23][24]:

TierRTO targetRPO targetWhat it includes
Bronze24 hours24 hoursImage + file backup, 3-2-1, immutable storage, monthly verification, restore portal
Silver4 hours4 hoursBronze + automated daily verification, priority NOC (Network Operations Center) response
Gold1 hour15 minutesSilver + hot standby compute, weekly verification, 24/7 incident response, quarterly DR drill

Bronze is the regulatory floor under the proposed HIPAA amendments [8]; Gold aligns with the EHR-class SLA a hospital or specialty practice needs. The tier choice is workload-level, not customer-level — most mid-market customers run a mix.

What Auditors and Ransomware Operators Care About

BCDR's anti-ransomware posture is layered, and each layer is auditable. Layer 1: Active Protection on the endpoint. Layer 2: backup-integrity scanning on every restore. Layer 3: immutable storage that cannot be modified even with admin credentials. Layer 4: anomaly detection on the backup stream — sudden size or duration changes, missing backups, new geographic origin — surfaced to the HTS NOC before the attack becomes an outage. Layer 5, shipping in Q4 2026: an air-gapped copy on a separate storage tenant with out-of-band authentication.

The combined posture matches what Veeam identifies as the three most important contributors to ransomware recovery success: immutable and air-gapped repositories, verifiably recoverable and clean data, and orchestrated workflows for recurring testing [2]. The recovery-cost data confirms the model: a customer with verified, immutable backups recovers inside a week at an ITIC 2024 mid-market median of $300,000 per hour, roughly $1.7 million in direct cost [10]. The same customer with compromised backups is looking at 30-plus days, an additional $3.7 million in downtime, plus the regulatory fine on top.

SOC 2 CC7.5 expects at least one documented restoration test per quarter [12]. The monthly insurance-grade PDF BCDR auto-emails on the first business day of each month — backup success rate, last verification result, immutable status, achieved RTO/RPO, ransomware events, and a compliance section mapping to SOC 2 CC7.5, HIPAA §164.308(a)(7), and the 2026 Security Rule amendments — is the artifact an auditor or broker expects to see.

From the Anchor: A Multi-Site Healthcare Provider in Practice

The healthcare provider is a multi-site specialty medical group and a long-standing HTS managed-services customer. Across its six sites, the practice runs more than 500 protected endpoints, 10 servers (including a production EHR), and a service agreement that already includes Verkada camera monitoring, access control, badge printing, and a per-card-reader line item. The customer is HIPAA-bound and SOC 2 Type 2 in progress.

Before BCDR, the practice backed up via Windows Server Backup on premises and consumer OneDrive sync for the M365 data. The backups were not verified, the M365 data was not backed up at all, and the on-prem target sat on the same network as production. After BCDR, the 500-plus endpoints run Acronis image-and-file backup with 3-2-1 and immutable cloud storage; the 10 servers run Silver-tier backup with a 4-hour RTO commitment; the production EHR runs Gold-tier with hot-standby compute in the Acronis Cloud. Separately, M365 backup is delivered through RMM / Asio / the ConnectWise portal for all 500-plus users with daily granularity and one-year retention. Verification runs weekly on the Gold server and monthly on the rest. The monthly PDF is forwarded to the practice's cyber-insurance broker at renewal and packaged into Comply for the next OCR review. Separate BCDR and RMM lines now live on the same HTS Managed agreement as the Verkada and badge lines, replacing the second backup vendor — and every Verkada SOW (Statement of Work) HTS writes is now a backup SOW.


If you want a recovery plan an auditor can read and a ransomware operator cannot reach, HTS Managed helps you build it on Acronis, run by the HTS NOC, on one agreement.


References

  1. Veeam, 2024 Ransomware Trends Report. https://www.veeam.com/company/press-release/ransomware-continues-to-cause-mayhem-as-victims-are-unable-to-recover-43-percent-of-affected-data.html
  2. Veeam, 2023 Ransomware Trends Report. https://www.veeam.com/company/press-release/new-veeam-research-finds-93-percent-of-cyber-attacks-target-backup-storage-to-force-ransom-payment.html
  3. Sophos, State of Ransomware 2024 (press). https://www.sophos.com/en-us/press/press-releases/2024/04/ransomware-payments-increase-500-last-year-finds-sophos-state
  4. Sophos, State of Ransomware 2024 (whitepaper). https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2024-wp.pdf
  5. HHS OCR Risk Analysis Initiative settlements, April 23, 2026. https://www.hipaajournal.com/ocr-fines-four-regulated-entities-hipaa-violations-ansomware-attacks/
  6. HIPAA Security Rule proposed amendments. https://www.linkedin.com/pulse/hipaa-2026-compliance-floor-just-moved-ocr-already-xtzef
  7. ITIC, Hourly Cost of Downtime, 2024. https://outagecost.com/cost-of-it-downtime
  8. ComplianceBase, SOC 2 CC7.5. https://www.compliancebase.org/controls/soc-2/cc7-5
  9. Acronis, Cyber Protect Cloud. https://www.acronis.com/en/products/cloud/cyber-protect/
  10. Acronis, Active Protection. https://www.acronis.com/en/products/true-image/features/active-protection/
  11. Unitrends, RPO and RTO guide. https://www.unitrends.com/blog/rpo-rto/
  12. AWS, Multi-Region Fundamentals. https://docs.aws.amazon.com/prescriptive-guidance/latest/aws-multi-region-fundamentals/fundamental-1.html

Harris Technology Services (HTS) · https://www.hts.pro · Support: support@hts.pro

HTS BCDR

This post covers the service behind it. See the HTS BCDR page or email hello@htsmanaged.com.