Disaster Recovery

Disaster Recovery

Glossary · Resilience

Recovery beyond the primary site

When the primary site goes down, recovery has to move somewhere else. Quorum Disaster Recovery extends local protection to a secondary location, giving organizations a reliable path to resume operations when a facility, data center, or infrastructure stack becomes unavailable.

HAHigh Availability protects systems locally.
DRDisaster Recovery protects the business remotely.

One copy restores locally. Two copies ensure survival.

01 The Stakes

Survive site-level failure

A server failure is disruptive. A site failure is existential. Disaster Recovery is designed for the events High Availability alone cannot address.

  • Data center outages
  • Facility loss
  • Power grid failure
  • Natural disasters
  • Regional network disruption
  • Infrastructure-wide failure
  • Ransomware events requiring isolation

When the primary environment is unavailable, protected systems must be able to activate somewhere else. Quorum makes that possible through snapshot-based protection, secure replication, and remote activation.

02 The Foundation

High Availability first. Then Disaster Recovery.

Effective Disaster Recovery starts with a protected local foundation. The architecture begins with:

  • A primary onQ system providing local High Availability
  • Frequent, consistent point-in-time snapshots
  • Immutable, encrypted recovery points
  • Local activation capability

From there, snapshots replicate to a secondary onQ platform at a remote location. The local copy protects against hardware failure; the remote copy protects against business interruption.

03 The Workflow

How Quorum Disaster Recovery works

onQ creates consistent snapshots of protected systems, stored locally for High Availability and replicated to a secondary onQ platform using independent block replication. If the primary site becomes unavailable:

Select the protected snapshot
Activate at the remote location
Boot protected systems immediately
Reconnect users and applications
Restore or return to production when ready

Activation remains the same. The location changes.

No restore-first workflow. No rebuild delay.

04 The Distinction

DR is not just backup

Backup protects data. Disaster Recovery restores operations. A backup may prove that data exists, but it does not guarantee the business can run when the primary site is down. Disaster Recovery requires:

  • A second protected copy
  • A secondary activation location
  • Defined RTO and RPO
  • Replication strategy
  • Recovery sequencing
  • Tested recovery procedures

If systems cannot run, the business is still offline.

05 HA vs DR

The difference between HA and DR

Same recovery principle — different problems.

High AvailabilityDisaster Recovery
Protects against localized failureProtects against site-level failure
Runs within the same siteRuns from a secondary location
Minimizes downtime locallyPreserves business continuity remotely
Uses one recovery platformRequires two protected recovery locations
Best for hardware or component failureBest for facility or infrastructure loss

HA keeps systems running when something breaks locally. DR keeps the business running when the primary site is lost.

06 DR vs DRaaS

The difference between DR and DRaaS

Both protect against site-level failure. The difference is infrastructure ownership.

Disaster Recovery

A customer-owned or customer-managed secondary recovery location.

  • A secondary onQ appliance
  • A remote onQ Flex deployment
  • A company-owned data center
  • A managed secondary site

Best when you want control over the secondary environment.

DRaaS

Uses Quorum Cloud as the secondary recovery location — no second site to own or maintain.

Best when you do not own or want to maintain a second site.

Both use the same recovery architecture. The difference is where the secondary environment lives.

07 The Mechanism

Independent block replication

Quorum DR uses independent block replication to extend protection from the local onQ platform to a secondary onQ system.

  • Deduplication
  • Compression
  • Encryption
  • Block-level efficiency
  • Secure communication channels

Replication operates independently of the original protection method — agent-based, image-based, physical, virtual, and hybrid workloads share the same DR replication model. It extends protection geographically; it does not replace the local backup foundation.

08 The Objectives

RTO and RPO in Disaster Recovery

RTO How quickly must systems return?

With Quorum, remote systems activate from protected snapshots, reducing downtime compared to restore-first recovery.

Low RTO requires fast activation.

RPO How much data can we lose?

Local backup frequency defines local granularity. Remote recovery points are shaped by backup frequency and replication cadence.

Low RPO requires frequent protection and efficient replication.

The right DR architecture must align both.

09 Structured Recovery

Policy-based infrastructure recovery

Disaster Recovery is rarely one server at a time. Applications depend on databases, authentication, DNS, file services, and supporting systems. Quorum supports policy-based activation so recovery happens in the right order.

  • Multi-server recovery groups
  • Application-tier sequencing
  • Domain controller alignment
  • Database-first activation policies
  • Dependency-aware recovery
  • Grouped infrastructure bring-up

Recovery becomes structured. Not improvised.

10 Built To Adapt

DR for real-world infrastructure

Production environments change — and recovery architecture has to survive those changes.

What changes

  • Hypervisors shift
  • Hardware gets refreshed
  • Data grows
  • Cloud strategies evolve
  • Facilities change
  • Ransomware risk increases

Flexible deployment

  • onQ Appliance at a secondary site
  • onQ Flex on supported remote hardware
  • Cloud-connected recovery options
  • Hybrid recovery topologies

The deployment model can change. The recovery architecture stays consistent.

11 Protected By Design

Security within Disaster Recovery

A remote recovery copy is only useful if it stays protected. Quorum DR preserves recovery integrity across locations.

  • Immutable snapshots
  • Encryption in transit and at rest
  • Logical air gap separation
  • Secure replication channels
  • Role-based access control
  • Automated recovery testing
  • Clean Room validation

The remote copy is protected with the same security posture as the local copy. Disaster Recovery should not create a weaker recovery path.

12 The Modern Threat

Disaster Recovery and ransomware

Ransomware often turns a local outage into a broader recovery event — encrypting production data, compromising credentials, targeting backup repositories, or forcing teams to isolate the primary environment. Quorum DR maintains protected copies outside the primary site. In a ransomware event, teams can:

Identify a clean snapshot
Activate remotely if the primary site is compromised
Validate systems before reconnecting
Use Clean Room testing where isolation is required
Restore production when the environment is trusted

The goal is not just to recover quickly. The goal is to recover safely.

13 Knowing The Fit

When to choose Disaster Recovery

DR is the right fit when the business needs a second protected place to run.

  • You require geographic redundancy
  • You operate a secondary site
  • Continuity must survive facility loss
  • Regulations mandate offsite protection
  • Downtime tolerance extends beyond hardware
  • Infrastructure is centralized
  • Ransomware recovery may require isolation
  • You want control of the secondary environment

Common Disaster Recovery gaps

Organizations often assume they have DR because they have offsite backups. That is not enough. Common gaps include:

  • No secondary activation environment
  • Replication without tested recovery
  • Unclear RTO and RPO
  • Missing dependency mapping
  • Manual recovery sequencing
  • Unprotected backup repositories
  • No ransomware validation workflow
  • No regular DR testing

A DR plan should prove one thing clearly: the business can operate when the primary site cannot.

14 The Platform

How Quorum supports Disaster Recovery

  • Snapshot-based protection
  • Local High Availability foundation
  • Independent block replication
  • Secondary onQ activation
  • Instant workload boot
  • Policy-based infrastructure recovery
  • Immutable recovery points
  • Encrypted replication
  • Automated recovery testing
  • Clean Room validation
  • Flexible Appliance or Flex deployment

A recovery architecture built for real disruption. Not just backup completion.

15 Put It Into Practice

Disaster Recovery checklist

A strong DR strategy should answer:

  • Which systems require remote recovery?
  • What is the RTO for each critical workload?
  • What is the RPO for each critical workload?
  • Where will systems run if the primary site is down?
  • Is there a second protected copy?
  • Is replication encrypted and monitored?
  • Are snapshots immutable?
  • Are dependencies mapped?
  • Can systems activate in the correct order?
  • Has remote activation been tested?
  • Does the plan account for ransomware isolation?
  • Is DRaaS a better fit if no second site exists?

DR works best when architecture, objectives, and testing are aligned.

When Restore Is Not Enough

High Availability protects systems. Disaster Recovery protects the business.

When the primary site is unavailable, organizations need more than backup data — a second protected copy, a secondary place to run, and a tested path back to operations. Quorum delivers it through snapshot-based activation, secure replication, and structured infrastructure recovery.

Right onQ. Off Was Never an Option.

Eliminate Downtime from Recovery

Eliminate Downtime from Recovery

Boot systems directly from snapshots and keep operations running without restore delays.