Tech Multiplier
Tech Multiplier is the podcast for smart business leaders who want to turn technology into a competitive advantage. Each episode explores how to use tech as a force multiplier—to accelerate growth, streamline operations, and protect what you’re building.
Join us as we break down the latest tools, trends, and strategies that help you lead with confidence and scale with intention. Whether you're looking to level up your tech stack or avoid common digital pitfalls, Tech Multiplier gives you actionable insights to multiply what matters—your impact, profits, and success.
Subscribe now and start turning tech into your growth engine. For resources and more, visit mytek.net.
Tech Multiplier
Your Backup Worked. Your Business Still Went Down.
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Having a backup doesn’t mean your business is prepared for downtime.
When ransomware hit Fairlife, Coca-Cola’s ultra-filtered dairy brand, production at all four U.S. plants stopped. The company had incident response and business continuity plans in place—but much of its production remained offline for 11 days. What kept products on store shelves wasn’t a backup. It was inventory.
Most small and midsize businesses don’t have that kind of cushion.
In this episode of The Tech Multiplier, we break down the critical differences between backup, disaster recovery, and business continuity—and why a successful backup is only the beginning of a real recovery strategy.
We cover:
- The difference between backup, disaster recovery, and business continuity
- The two numbers every business should know: RTO and RPO
- Why your restore time is only a guess until you actually test it
- What critical systems, configurations, and credentials can get missed in a backup
- Why the timing of an outage can dramatically change its financial impact
- How Arizona SMBs can build a practical business continuity plan without an in-house IT or security team
The real question isn’t simply, “Are we backed up?”
It’s “If our systems went down today, how long would it actually take us to operate again?”
Listen to learn how to answer that question before an outage answers it for you.
Learn more about MyTek, an Arizona-based Managed IT Services and IT Security firm: https://mytek.net/
Okay, let's unpack this because um today's deep dive is covering a topic that I think is a massive blind spot for a lot of us.
SPEAKER_00Oh absolutely a huge blind spot.
SPEAKER_02Yeah. So our mission today is really about shattering this illusion that um that just because you have a backup, your business is somehow completely safe from a digital disaster. Trevor Burrus, Jr.
SPEAKER_00Right, that little green check mark on your dashboard.
SPEAKER_02Exactly. People see that and they think, well, we're good. But um we've got a whole stack of material fueling this discussion today. We're pulling from recent SEC 8K filings, uh the iTICS 2024 hourly cost of downtime report. There's some Splunk research in here on the Global 2000, and of course the updated frameworks from NIST and SISA.
SPEAKER_00They have the hitters.
SPEAKER_02Right. So we really want to help our listeners understand this massive financial cliff of IT downtime. Yeah. And the critical difference between just having a backup and actually having business continuity.
SPEAKER_00Aaron Ross Powell Because they are not the same thing at all.
SPEAKER_02No. And to kick this off, I want to talk about Fairlife, you know, the Coca-Cola dairy brand.
unknownYeah.
SPEAKER_02Ultra filtered milk.
SPEAKER_00Yeah, people love that stuff.
SPEAKER_02Yeah. So back on July 16th, Coke filed an 8K with the SEC, and they reported that ransomware had actually reached the production systems at Fairlife.
SPEAKER_00Right. Which is, you know, a worst case scenario for manufacturing.
SPEAKER_02Total nightmare. And the company, to their credit, they activated their incident response and their business continuity protocols that exact same day. But despite that, all four of their U.S. plants just stopped anyway. They were completely down. And most of that production stayed offline until July twenty-seventh.
SPEAKER_00That's eleven days.
SPEAKER_02Eleven days. But here's where I have to push back a little bit on the source material or at least ask a question. Because if their plants were completely down for almost two weeks, how did the shells stay full? Like I was buying milk that week. Shoppers barely noticed.
SPEAKER_00Well, what's fascinating here is that Fairlife wasn't actually saved by their IT recovery speed.
SPEAKER_01Okay.
SPEAKER_00They were saved by physical inventory. They had finished cases of product just sitting in distribution centers all over the place.
SPEAKER_01Oh, I see.
SPEAKER_00Yeah, that warehouse inventory acted as this massive physical cushion. So it kept the store shelves stocked while the engineers spent, you know, 11 days sweating and working through the digital rebuild.
SPEAKER_02Right, because that was Coca-Cola.
SPEAKER_00Exactly.
SPEAKER_02They have a national distribution network. But if you're, say, a 30-person operation and Chandler, you don't get that cushion.
SPEAKER_00You absolutely do not. A local retail shop or, you know, a local logistics firm, they don't have weeks of finished services just hiding their downtime. If their system crashes at 9 a.m., their customers feel it at 9.01. Yeah. And that's why we have to define these terms. Because people use backup, disaster recovery, and business continuity like they're the exact same thing.
SPEAKER_02Right. They use them interchangeably.
SPEAKER_00Yeah. But your vendor doesn't. And NIST definitely doesn't view them that way.
SPEAKER_02So break those down for us. What is the actual difference?
SPEAKER_00Okay. So think of backup as just storage. That's it. It just proves that a copy of your files exists somewhere.
SPEAKER_02Okay. So like a bullprint in a safe.
SPEAKER_00Right. Now, disaster recovery is the actual heavy lifting of turning that copied data back into functioning systems.
SPEAKER_02Which takes time.
SPEAKER_00A lot of time. And the costs start compounding immediately. But then business continuity, that asks a totally different question. It asks, can you actually keep serving your customers during that gap?
SPEAKER_02While the recovery is happening.
SPEAKER_00Exactly. You know, surviving an incident and actually resuming operations, those are two very different outcomes for an organization.
SPEAKER_02Aaron Powell So if backup doesn't just automatically equal continuity, how do businesses actually measure that gap? Because I imagine you need to put a number on it.
SPEAKER_00Aaron Powell You do. And that leads directly to the two vital acronyms every listener needs to know: recovery time objective and recovery point objective. RTO and RPO.
SPEAKER_02Aaron Ross Powell RTO and RPO. Okay, let's unpack those.
SPEAKER_00Aaron Ross Powell So RTO, your recovery time objective, is basically how long you can afford to run without a system before the damage to your business really starts to compound.
SPEAKER_02Trevor Burrus Like how long the clock can tick.
SPEAKER_00Aaron Powell Right. And then RPO, your recovery point objective, is how much recent work you can actually afford to lose. How far back in time do we go to get the data?
SPEAKER_02Okay. Let's use a relatable example to ground this. Because I think in the abstract it's hard to grasp. Picture a dental practice, maybe in Gilbert. Yeah. And they have their system set up to back up every night at 11 p.m.
SPEAKER_00Aaron Ross Powell Very common. Aaron Ross Powell Right.
SPEAKER_02So that's essentially an eight-hour or a 12-hour RPO during clinic hours.
SPEAKER_01Trevor Burrus Yes.
SPEAKER_02So if a failure happens, say in the middle of the afternoon, like at 3 p.m., they are losing every single chart note, every x-ray, every payment that was posted since 11 p.m. the night before.
SPEAKER_00It's all gone.
SPEAKER_02Aaron Powell And nobody chose that. Right. Trevor Burrus Like no dentist sits down and says, yeah, I'd love to lose a full day of patient records. It just arrived with the backup schedule.
SPEAKER_00Trevor Burrus Exactly. It's the vendor default.
SPEAKER_02Trevor Burrus It's like letting a rental car agency pick your seat position and your mirror angles for a cross-country road trip. Trevor Burrus, Jr.
SPEAKER_00Oh, that's a good way to put it.
SPEAKER_02Trevor Burrus You know, sure, you can technically drive the car, but if it's not set for you, it's going to end in a disaster. Trevor Burrus, Jr.
SPEAKER_00Well, and the data backs this up. There was a recent data resilience report that looked at 900 senior IT and risk leaders. Okay. And 90% of them, 90%, were confident they could recover inside their RTOs.
SPEAKER_02Aaron Powell Wow, that's really high.
SPEAKER_00Aaron Powell It is. But when asked if those RTOs actually aligned with their business continuity goals, only 69% said yes.
SPEAKER_02Aaron Powell Wait, really? So they know they can hit the target, but they also know the target is a wrong target.
SPEAKER_00Basically, yeah. They know their recovery speed isn't actually fast enough to save the business.
SPEAKER_02Aaron Powell That is a massive disconnect. And it's not just an IT headache. Like if those numbers are misaligned, that's a ticking financial time bomb for the company.
SPEAKER_00Oh, it is.
SPEAKER_02Which brings us to the financial cliff. And here's where it gets really interesting looking at this IDEX 2024 data and the Splunk research.
SPEAKER_00The numbers are staggering.
SPEAKER_02They really are. So for micro SMBs, we're talking businesses with just one to 20 employees. The data shows they lose a minimum of $100,000 per hour of downtime.
SPEAKER_00Per hour for a tiny company.
SPEAKER_02Yeah. And then mid-size and large enterprises, they're losing $300,000 or more per hour.
SPEAKER_00It's just bleeding cash.
SPEAKER_02And if you're in a regulated sector like healthcare or finance, 41% of those enterprises are losing between $1 million and $5 million plus per hour.
SPEAKER_00Yeah. And the Global 2000 companies, they're losing $9,000 every single minute.
SPEAKER_02Every minute. I mean, if we connect this to the bigger picture, why is it so high? Like where's all that money going?
SPEAKER_00Well, the costs multiply across four distinct areas. First, you have lost employee productivity.
SPEAKER_02Because everyone's just sitting around.
SPEAKER_00Exactly. The network is down, but payroll keeps running. Then obviously you have lost revenue. You can't process orders.
SPEAKER_02Right.
SPEAKER_00Third is the IT recovery costs. Because in an emergency, you're paying premium drop everything hourly rates to get people to fix it.
SPEAKER_02Oh, sure. Emergency fees.
SPEAKER_00And then the fourth, which is huge, is compliance and security risks. Splunk noted that regulatory fines average around $22 million a year for these kinds of incidents.
SPEAKER_02Oh my gosh. $22 million. Okay, let's let's bring this down to earth a bit. Let's look at a 15-employee logistics firm in Phoenix.
SPEAKER_00Okay, good example.
SPEAKER_02You know, it's not just that their email is down.
SPEAKER_00Yeah. No.
SPEAKER_02It's stranded fleets. They literally can't see where their trucks are.
SPEAKER_00They lose GPS, they lose dispatch.
SPEAKER_02Exactly. And the payroll is still going for all those drivers just sitting at truck stops. Yep. Plus, they're missing their delivery windows, which triggers massive SLA penalties with their clients.
SPEAKER_00Oh, the service level agreements? Yeah. Those contracts are ruthless.
SPEAKER_02That's right. And ultimately it's reputation loss. The research shows 44% of businesses face lasting reputation damage after an outage.
SPEAKER_00Because the clients don't care about your server, they just care that their freight didn't arrive.
SPEAKER_02Exactly. So the financial cost is just catastrophic, which means getting the system back online quickly is paramount. But this is where the whole theory of recovery really violently collides with reality.
SPEAKER_00Because having the data doesn't mean the data is usable yet.
SPEAKER_02Right. Let's look at NIST's revised guidance on this. The SP 800 61R3 framework.
SPEAKER_00They point out that restores almost always stall because of the order of operations.
SPEAKER_02What do you mean by that?
SPEAKER_00Well, imagine you successfully restore your massive file server.
SPEAKER_02Okay, great. Got the files.
SPEAKER_00Right. But it's completely useless if you didn't restore the identity and authentication system first because the server doesn't know who is allowed to log in.
SPEAKER_02Oh so nobody can actually open the files.
SPEAKER_00Exactly. Or you bring an application back online, but it fails because DNS, the system that helps apps find each other on the network, isn't correct yet.
SPEAKER_02Aaron Powell It's like putting the cart before the horse.
SPEAKER_00Basically. And teams discover mid-crisis that nobody actually wrote down what needs to come back first.
SPEAKER_02And then there's the whole bandwidth issue, the throughput bottleneck.
SPEAKER_00Oh, physics always wins.
SPEAKER_02Right. Because pulling, say, four terabytes of data down a temp B business fiber line, it just takes time, regardless of what your cloud contract says.
SPEAKER_00Yeah, you can't bypass the physical limits of the wire.
SPEAKER_02Our sources had this great analogy. Having a backup is like having a spare tire in your trunk.
SPEAKER_00Yes, I love this one.
SPEAKER_02It's great to have, but if you've never actually timed yourself changing that tire on the shoulder of the I-10 freeway in August.
SPEAKER_00In 115 degree heat.
SPEAKER_02Right. Then you really have no idea how long you're going to be stranded. You might not even have a jack.
SPEAKER_00Aaron Powell, which is why testing is so critical. You have to test your backups quarterly and after any major environment change. And it has to be a real test.
SPEAKER_02Aaron Powell What does a real test look like?
SPEAKER_00It means actually restoring a critical system to a fully working state while someone literally stands there with a stopwatch.
SPEAKER_02Wow.
SPEAKER_00And that time goes right next to your RTO. And if those two numbers don't match, well, you found the problem before the problem found you.
SPEAKER_02That makes total sense. But um there's another blind spot here, right? Because both RTO and RPO assume that everything you actually need was backed up in the first place.
SPEAKER_00Aaron Powell Which is often not the case at all.
SPEAKER_02Aaron Ross Powell So what sits outside the backup? What gets missed?
SPEAKER_00Aaron Ross Powell Well, a lot of critical things. First is settings. People back up files, but they forget the configurations. License keys, firewall rules, the specific config that some engineer spent days tuning.
SPEAKER_02Aaron Ross Powell Oh, so the data is there, but the system doesn't know how to behave.
SPEAKER_00Right. It won't connect. Another one is a line of business applications that just live on someone's desktop. Like a specific estimating tool your project manager relies on, but it isn't on the main server.
SPEAKER_02So it's completely unprotected.
SPEAKER_00Exactly. And then terrifyingly, there are the backup credentials themselves.
SPEAKER_02Wait, what do you mean?
SPEAKER_00Remember that case study we looked at where an AI agent was accidentally given too many permissions. Oh yeah. It went rogue, it wiped the company's database, but then it also took out all the backups.
SPEAKER_01How does that even happen? How does it reach the backups?
SPEAKER_00Because the company used the exact same credentials for the production environment and the backup environment.
SPEAKER_01Oh no.
SPEAKER_00So once it compromised the live system, it just walked right into the backups and wiped those two.
SPEAKER_02Aaron Powell That is a nightmare. It really highlights the risk. And um it makes me think about Microsoft 365 too. Because there's this shared responsibility shock. Yes. People think, well, my stuff is in the cloud with Microsoft, so Microsoft is backing it up.
SPEAKER_00And they are not.
SPEAKER_02Right. Microsoft keeps the service on, they keep the servers running. But your actual data, your emails, your files, that is your responsibility.
SPEAKER_00It's a shared responsibility model. If you accidentally delete something or if ransomware encrypts your inbox, Microsoft isn't going to save you.
SPEAKER_02Which brings us to that Veeam statistic. And this one is heavy.
SPEAKER_00It is.
SPEAKER_02They found that among organizations hit by ransomware, only 28% actually recovered all their affected data.
SPEAKER_00Just 28%.
SPEAKER_02And 44% got back less than 75%.
SPEAKER_00Almost half the companies lost a quarter of their data permanently.
SPEAKER_02Even with backups.
SPEAKER_00Yes.
SPEAKER_02So with all this in mind, the old way of doing things, this break fix model where you just wait for a server to die and then call an IT guy who's just dead, isn't it?
SPEAKER_00Trevor Burrus, Jr. It has to be. The threat landscape is way too advanced now. I mean, look at the University of Phoenix zero-day breach. Trevor Burrus, Jr.
SPEAKER_02Right. 3.5 million records exposed.
SPEAKER_00Yeah. And Forrester is predicting that we're going to see two major multi-day outages this year, just from rushed AI data center upgrades. And it's not even always sophisticated cyber attacks. It could be an AI voice clone tricking an employee or just aging hardware finally giving out, or simple human error. Trevor Burrus, Jr.
SPEAKER_02The threats are everywhere. So we have to shift the paradigm. We have to be proactive.
SPEAKER_00Aaron Powell Yes. The breakfix model is dead. Proactive IT means you have 247 monitoring. You have automated patch management so the holes are plugged before they get exploited.
SPEAKER_02Aaron Powell And cloud redundancy, right?
SPEAKER_00Trevor Burrus Exactly. Instead of just having a backup file, you have backup servers in the cloud that can just instantly take over the workloads if your main system goes down.
SPEAKER_02Aaron Powell That makes a huge difference.
SPEAKER_00Yeah.
SPEAKER_02Okay. So what does this all mean for the listener? Let's bring it all together. Trevor Burrus, Jr. Sure. The big takeaway here is that downtime is an hourly financial drain. It's a cliff.
SPEAKER_00Aaron Ross Powell A very steep cliff.
SPEAKER_02Yeah. And your RTO and your RPO, you can't just leave those to whatever the default settings are. They have to be deliberately chosen by leadership. And tested. And tested. Right. Quarterly with a stopwatch.
SPEAKER_00Aaron Ross Powell Because prevention is infinitely cheaper than recovery.
SPEAKER_02Trevor Burrus It really is. So for everyone listening, take those CISA framework questions back to your teams. Ask them, you know, which apps actually drive our daily revenue. And what concrete proof do we have that our offline backups will actually work?
SPEAKER_00Aaron Powell You know, this raises an important question that I think we should leave our listeners to mull over.
SPEAKER_02Okay, what's that?
SPEAKER_00Building on that Veeam statistic we talked about. The one where 44% of organizations recover at less than 75% of their data.
SPEAKER_02Aaron Powell Yeah, losing a quarter of everything.
SPEAKER_00Aaron Powell Right. We always look at the financial cost of that downtime, right? The the lost hours and the recovery fees.
SPEAKER_01Sure.
SPEAKER_00But what happens to the corporate memory that lives in that missing 25%? Think about it. If that lost data contains the unwritten rules, the nuanced configurations, the custom tools that nobody ever documented. Why yeah. Could a company technically survive an outage? You know, they get the green lights back on, only to wake up with operational amnesia.
SPEAKER_02Just fundamentally altering how they do business forever.
SPEAKER_00Because the corporate memory is just gone.
SPEAKER_02That is a terrifying and really fascinating thought to end on. Because getting back online isn't the same as getting your company back.
SPEAKER_01Not at all.
SPEAKER_02Well, thank you all for joining us on this deep dive. Go check those RTOs and RPOs, and we will catch you next time.