Cloud Backup and Disaster Recovery
This service delivers cloud-first backup and disaster recovery for servers, workstations, and Microsoft 365 Data. Engineered for ransomware resilience, it ensures data continuity through immutable copies and automated recovery testing.
Features
- Cloud-first backup for servers, workstations, and Microsoft 365.
- Automated recovery testing for guaranteed restoration and compliance
- Immutable backup copies isolated by default for ransomware resilience.
- Delta technology eliminates redundancies for high-efficiency data transfers.
- Flexible recovery to almost any location or hardware environment.
- Unified multi-tenant dashboard for centralised visibility and management.
- High-frequency backups performed as often as every 15 minutes.
- End-to-end security with mandatory MFA and always-on encryption.
- Vendor-managed patching, security, and storage for infrastructure simplicity.
- Comprehensive protection for local, cloud, and Microsoft 365 data.
Benefits
- Strengthen ransomware resilience through isolated and immutable backup copies.
- Maintain business continuity with rapid, reliable disaster recovery processes.
- Reduce administrative burden and staff time with automated management.
- Guarantee regulatory compliance via automated and scheduled recovery testing.
- Protect diverse infrastructure including servers, workstations, and Microsoft 365.
- Accelerate data transfers using Delta technology to eliminate redundancies.
- Enhance data security with mandatory MFA and always-on encryption.
- Simplify complex infrastructure management tasks using a single dashboard.
- Improve budget predictability and lower total cost of ownership.
- Enable flexible restoration to any location for multi-cloud resilience.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 9 5 6 0 3 9 1 3 1 4 2 8 1 5
Contact
JOSKOS SOLUTIONS LIMITED
Tom Singh
Telephone: 07950914002
Email: tenders@joskos.com
About your service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
- Backup and Recovery Reporting Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- This service is a specialised extension for Microsoft 365, providing dedicated backup and recovery for Teams, SharePoint, and OneDrive. It also further integrates as a resilient data protection extension for on-premises and cloud-resident server and workstation operating systems.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- This service follows a 'configure rather than customise' approach, ensuring standard functionality for seamless upgrades and common code-base stability. As a SaaS model, maintenance and patching are vendor-managed; significant updates are documented and pre-advised to buyers. Technical constraints include access via supported browser services on buyer-provisioned organisational devices. Dedicated helpdesk support is available during business hours (9 am–5pm UK Time, Monday to Friday), with ticket submission available via the Help Centre. Finally, all service deployments are subject to a finalised scope of work and formal contract to ensure technical alignment.
- System requirements
-
- Fast, stable internet connection for high-frequency, resilient data transfers.
- Supported web browser services to access the multi-tenant management dashboard.
- Organisation-owned devices are required to access and manage the service.
- No proprietary hardware appliances or local storage servers are required.
- Mandatory multi-factor authentication is required for all administrative user access.
- On-premises or cloud servers and workstations require supported operating systems.
- Active Microsoft 365 subscriptions are required for M365 data protection.
- Integrated cloud storage is included, removing local capacity requirements.
- Vendor-managed patching and security ensures the service remains updated.
- Finalised scope of work must be agreed before service deployment.
User support
- Email or online ticketing support
- Yes
- Support response times
- We respond to all questions through our service desk within standard business hours, typically within one working hour for priority issues and within four working hours for general enquiries. Weekend and bank holiday responses follow our out-of-hours arrangements, where urgent issues are monitored and addressed, and routine queries are handled on the next working day.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have tested our web chat and ticketing interface with common assistive technologies to ensure accessibility. Testing included NVDA and VoiceOver screen readers, keyboard-only navigation, high-contrast mode, and zoom and reflow checks for users with visual impairments. We also reviewed compatibility with speech-to-text tools and browser accessibility extensions. Internal accessibility champions provided feedback on focus order, form labels, and colour contrast. Automated WCAG 2.2 AA checks were completed, and we continue reviewing new features to maintain accessibility for users relying on assistive technologies.
- Onsite support
- Yes, at extra cost
- Support levels
- We provide three support levels: Standard, Enhanced, and Premium. Standard support is included within the service cost and provides access to our service desk during business hours, with response and resolution times aligned to our published SLAs. Enhanced support includes extended hours, priority handling, and faster response times for an additional monthly fee. Premium support provides full extended-hours coverage, proactive monitoring, and scheduled technical reviews. All support requests are managed through our online ticketing system, email, or phone. Each customer is assigned a named technical account manager who oversees onboarding, configuration, and ongoing service performance. Cloud support engineers are available for escalations, integration support, and advanced troubleshooting. Support costs are transparent and based on the level selected, with pricing provided in the accompanying rate card. We also offer optional onboarding and configuration packages for organisations requiring additional setup assistance or complex integrations.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
To facilitate the effective adoption of our services, we provide a robust array of tools, including a dedicated Help Centre and technical documentation focused specifically on cloud application adoption. A team of professional trainers lead interactive webinars and masterclasses to guide users through setup and configuration tasks. For institutions with bespoke requirements, we offer onsite training and tailored engagement strategies, drawing on our award-winning experience in school collaboration (for an additional cost).
Furthermore, our National Response Centre provides proactive remote management and issue scanning, while dedicated support specialists are available via phone or support tickets during business hours (9am–5pm) to ensure prompt technical resolution. These integrated support channels are designed to provide a frictionless onboarding journey, allowing organisations to maximise the value of their cloud infrastructure and productivity suites. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Exported upon request. Contact the Support Helpdesk or Technical Account Manager.
- End-of-contract process
- Following the initial term, Joskos services continue on a rolling basis per agreed notice periods. Should an organisation choose to exit, we provide professional assistance to ensure seamless migration and operational continuity. Our transition methodology aligns with ISO (9001, 14001, 27001) and ITIL standards to ensure a dependable and sustainable handover.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- It has a web administration portal.
- Accessibility standards
- None or don’t know
- Description of accessibility
- If further information is required, a copy of this information can be provided upon request.
- Accessibility testing
- Please contact N-Able for further information.
- API
- No
- Customisation available
- Yes
- Description of customisation
- The name of the service can be customised, along with the colour of key objects in the user interface, and an image within the portal can be changed, for example your company logo. Joskos can customise on behalf of the customer, or the customers own in-house IT staff would also be able to do it.
Scaling
- Independence of resources
- As a SaaS platform, N-Able Cove utilises a cloud-first architecture purpose-built for resource independence. While Joskos provides expert remote management via our National Response Centre, the technical guarantee of performance rests with N-Able’s backend management. Their proprietary TrueDelta technology eliminates redundancies, ensuring that frequent data protection tasks do not place undue demand on shared resources or affect other users. This unified, multi-tenant model ensures consistent performance across the global user base, managed independently by the technology vendor.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- N-able Solutions ULC and N-able Technologies Ltd
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Data can be exported upon request.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- All service level agreements are as per the ones supplied by N-Able, and published by them. VPS installations are guaranteed for 97% uptime, private/hybrid cloud instances have a 100% network uptime guarantee. Any downtime during working hours is credited on a pro-rata basis.
- Approach to resilience
- Hosted by N-Able, they have multiple locations and replication
- Outage reporting
- Outages are reported via email alerts and also website updates.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- We restrict access to management interfaces and support channels using layered controls. Administrative consoles are limited to approved IP ranges, VPN connections or trusted network locations. Access is authenticated using SSO or federated identities, supported by MFA for all privileged accounts. Role-based access controls ensure users only see the functions and data required for their role. ACLs are applied across systems, APIs and support tools to prevent unauthorised access. All activity within management interfaces is logged and monitored, and support channels require verified user authentication before any changes, queries or actions are carried out.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate a comprehensive Information Security Management System (ISMS) aligned to ISO 27001, which provides the framework for all our security policies, controls and operational processes. Our ISMS is formally certified and audited through both annual surveillance audits by our certification body and regular internal audits led by an independent third-party security consultant.
Our policies cover core areas including access control, data classification and handling, asset management, secure configuration, supplier management, business continuity, incident response, vulnerability management, change control, and staff security screening. These policies define mandatory requirements for all staff and contractors, supported by role-based training and regular compliance checks.
Operationally, our processes include risk assessment and treatment, secure system administration, logging and monitoring, patch and update management, backup and recovery routines, and formal procedures for onboarding, offboarding, and privilege management. All processes follow recognised good practice and are reviewed on a scheduled basis to ensure they remain effective.
We use a security-by-design approach for service delivery, embedding controls throughout the lifecycle from planning through to ongoing operation. Governance is overseen by senior leadership, with risks, incidents, and audit findings tracked through our ISMS improvement cycle to maintain continuous alignment with ISO 27001 requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We use a controlled configuration and change-management process aligned to our internal ISO-based service standards. All service components are tracked throughout their lifecycle in our configuration repository, including version, ownership, change history and deployment status. Any proposed change is logged, risk-assessed and approved through our change-control workflow. As part of this, we explicitly assess potential security impacts, including dependency changes, access implications and data-handling risks. Security-related changes follow an enhanced review and require sign-off from our technical leads. All approved changes are tested in a controlled environment before release to ensure stability and protect service integrity.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We have a Vulnerability Management process that implements the following: Receives information about zero day threats from the National Cyber Security Center; subscribe to newsletters from vendors and used products, in contact with special interest groups; Technical vulnerabilities are handled either using the Incident management process or the Change management process; Patches are tested following the Installation of software on operational systems.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- All devices run our monitoring agent, which continuously checks performance, security status, and early signs of failure. Any anomaly is automatically reported to our service desk, where it is triaged and prioritised. We operate an internal four-hour SLA for initiating remedial action, ensuring issues are addressed promptly. The severity of each incident is assessed as soon as it is detected so that high-priority or service-affecting problems receive an immediate response. This approach allows us to resolve risks early, reduce downtime, and maintain stable, reliable service for users across the estate.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a defined Incident Management Process with standard workflows for common events, enabling quick triage and resolution. Users report incidents through our service desk via phone, email, or the ticketing portal, where issues are logged and prioritised. Our engineers gather relevant system logs and evidence, apply a fix, patch, or workaround, and document all actions taken. Each incident is reviewed to determine whether improvements or control changes are needed to prevent recurrence. We provide incident reports on request or for major incidents, summarising root cause, impact, actions taken, and recommended preventative measures. Periodic trend reviews ensure continual improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We can provide a 30 day free trial of all of the BaaS features.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 4%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Thursday 28 March 2024
- What the ISO/IEC 27001 doesn’t cover
- We are fully covered by ISO27001:2022 and includes all aspects of information security
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Centre for Assessment
- ISO 9001 accreditation date
- Friday 28 February 2003
- What the ISO 9001 doesn’t cover
- We are fully covered by ISO 9001:2015
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6c1e4683-a09c-4f3a-9565-5e0d03893e08
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 6ecf48af-af04-49be-bd9e-3df16ca6910c
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-