Legal & compliance centre

HLD Group

Backup & recovery policy

Backup scope, encryption, and restore testing.

Last updated: 24 July 2026

Version 1.0 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy defines the requirements for backing up HLD Group and customer data and for verifying that it can be restored. Reliable, tested backups are the foundation of recovery from data loss, corruption, ransomware, and infrastructure failure, and are a prerequisite for meeting the recovery objectives set in the Business Continuity Policy.

2. Scope

This policy applies to all production data and to the systems, configuration, and secrets required to reconstitute production services, across all environments operated by HLD Group.

  • Production databases and data stores
  • Configuration, infrastructure-as-code state, and secrets management material
  • Critical file shares and object storage
  • Systems required to rebuild the production estate
  • Customer data under our management, subject to any stricter customer requirement

3. Definitions

  • Backup — a copy of data retained to enable restoration to a prior point
  • Full, incremental, and differential backup — methods varying in what is copied at each run
  • Immutability — a property preventing a backup from being altered or deleted for a defined period
  • Restore — the process of recovering data from a backup to a usable state
  • Air gap — logical or physical isolation preventing a backup from being reached from production credentials
  • RPO — the maximum tolerable data loss, expressed as a time window

4. Policy statement

Data in scope is backed up on a schedule that meets its recovery point objective, protected against unauthorised access and tampering, replicated to a separate geography, and periodically restore-tested. A backup that has never been restore-tested is not treated as a reliable recovery capability.

5. Backup scope and scheduling

Backup frequency is derived from the recovery point objective of each system. Tier 1 systems are backed up at least hourly where feasible; other tiers are backed up at least daily. Ephemeral caches and reproducible artefacts are excluded unless required for compliance or forensics.

6. Backup controls

  • Encryption at rest and in transit for all backups, with keys managed under the Encryption Policy
  • Immutability or versioning enabled where the platform supports it, to resist ransomware and accidental deletion
  • Logical or physical air-gapping so backups cannot be destroyed using production credentials alone
  • Access restricted to backup operators and break-glass roles, with all access logged and reviewed
  • Retention aligned to customer contracts, legal hold, and the Data Retention Policy
  • Backup jobs monitored, with failures alerted and treated as incidents

7. Restore testing and validation

Restores are tested on a schedule so that recovery capability is proven, not assumed. A failed restore test is handled as an incident and remediated before the next cycle.

  • Restore tests for Tier 1 systems at least quarterly
  • Validation that restored data is complete, consistent, and usable, not merely that files were retrieved
  • Measurement of actual restore time against the RTO
  • Test evidence retained for auditors and customer assurance

8. Geographic separation and resilience

Backups are replicated to an availability zone or region distinct from primary production, so that a single-site event cannot destroy both the primary data and its only backup. The 3-2-1 principle — at least three copies, on two media or platforms, with one off-site — is applied to Tier 1 data.

9. Ransomware and integrity protection

  • Immutable, versioned backups retained beyond the typical dwell time of an intrusion
  • Isolation of backup credentials and infrastructure from the production identity plane
  • Integrity checks to detect corruption or tampering of backup sets
  • Regular exercises of recovery from a clean, known-good point

10. Framework alignment

  • ISO/IEC 27001:2022 Annex A control 8.13 (information backup)
  • NIST SP 800-53 Rev. 5 controls CP-9 (system backup) and CP-10 (system recovery and reconstitution)
  • SOC 2 Trust Services Criteria availability category (A1.2)
  • NIST SP 800-34 Rev. 1 contingency planning guidance

11. Roles, exceptions, and review

Backup operations are owned by the infrastructure function under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually and after any data-loss incident or material change to the production estate.

Related frameworks

For contractual attestations or audit packs, contact [email protected].