Glossary · Resilience
Recovery beyond the primary site
When the primary site goes down, recovery has to move somewhere else. Quorum Disaster Recovery extends local protection to a secondary location, giving organizations a reliable path to resume operations when a facility, data center, or infrastructure stack becomes unavailable.
One copy restores locally. Two copies ensure survival.
01 The Stakes
Survive site-level failure
A server failure is disruptive. A site failure is existential. Disaster Recovery is designed for the events High Availability alone cannot address.
- Data center outages
- Facility loss
- Power grid failure
- Natural disasters
- Regional network disruption
- Infrastructure-wide failure
- Ransomware events requiring isolation
When the primary environment is unavailable, protected systems must be able to activate somewhere else. Quorum makes that possible through snapshot-based protection, secure replication, and remote activation.
02 The Foundation
High Availability first. Then Disaster Recovery.
Effective Disaster Recovery starts with a protected local foundation. The architecture begins with:
- A primary onQ system providing local High Availability
- Frequent, consistent point-in-time snapshots
- Immutable, encrypted recovery points
- Local activation capability
From there, snapshots replicate to a secondary onQ platform at a remote location. The local copy protects against hardware failure; the remote copy protects against business interruption.
03 The Workflow
How Quorum Disaster Recovery works
onQ creates consistent snapshots of protected systems, stored locally for High Availability and replicated to a secondary onQ platform using independent block replication. If the primary site becomes unavailable:
Activation remains the same. The location changes.
No restore-first workflow. No rebuild delay.
04 The Distinction
DR is not just backup
Backup protects data. Disaster Recovery restores operations. A backup may prove that data exists, but it does not guarantee the business can run when the primary site is down. Disaster Recovery requires:
- A second protected copy
- A secondary activation location
- Defined RTO and RPO
- Replication strategy
- Recovery sequencing
- Tested recovery procedures
If systems cannot run, the business is still offline.
05 HA vs DR
The difference between HA and DR
Same recovery principle — different problems.
| High Availability | Disaster Recovery |
|---|---|
| Protects against localized failure | Protects against site-level failure |
| Runs within the same site | Runs from a secondary location |
| Minimizes downtime locally | Preserves business continuity remotely |
| Uses one recovery platform | Requires two protected recovery locations |
| Best for hardware or component failure | Best for facility or infrastructure loss |
HA keeps systems running when something breaks locally. DR keeps the business running when the primary site is lost.
06 DR vs DRaaS
The difference between DR and DRaaS
Both protect against site-level failure. The difference is infrastructure ownership.
Disaster Recovery
A customer-owned or customer-managed secondary recovery location.
- A secondary onQ appliance
- A remote onQ Flex deployment
- A company-owned data center
- A managed secondary site
Best when you want control over the secondary environment.
DRaaS
Uses Quorum Cloud as the secondary recovery location — no second site to own or maintain.
Best when you do not own or want to maintain a second site.
Both use the same recovery architecture. The difference is where the secondary environment lives.
07 The Mechanism
Independent block replication
Quorum DR uses independent block replication to extend protection from the local onQ platform to a secondary onQ system.
- Deduplication
- Compression
- Encryption
- Block-level efficiency
- Secure communication channels
Replication operates independently of the original protection method — agent-based, image-based, physical, virtual, and hybrid workloads share the same DR replication model. It extends protection geographically; it does not replace the local backup foundation.
08 The Objectives
RTO and RPO in Disaster Recovery
RTO How quickly must systems return?
With Quorum, remote systems activate from protected snapshots, reducing downtime compared to restore-first recovery.
Low RTO requires fast activation.
RPO How much data can we lose?
Local backup frequency defines local granularity. Remote recovery points are shaped by backup frequency and replication cadence.
Low RPO requires frequent protection and efficient replication.
The right DR architecture must align both.
09 Structured Recovery
Policy-based infrastructure recovery
Disaster Recovery is rarely one server at a time. Applications depend on databases, authentication, DNS, file services, and supporting systems. Quorum supports policy-based activation so recovery happens in the right order.
- Multi-server recovery groups
- Application-tier sequencing
- Domain controller alignment
- Database-first activation policies
- Dependency-aware recovery
- Grouped infrastructure bring-up
Recovery becomes structured. Not improvised.
10 Built To Adapt
DR for real-world infrastructure
Production environments change — and recovery architecture has to survive those changes.
What changes
- Hypervisors shift
- Hardware gets refreshed
- Data grows
- Cloud strategies evolve
- Facilities change
- Ransomware risk increases
Flexible deployment
- onQ Appliance at a secondary site
- onQ Flex on supported remote hardware
- Cloud-connected recovery options
- Hybrid recovery topologies
The deployment model can change. The recovery architecture stays consistent.
11 Protected By Design
Security within Disaster Recovery
A remote recovery copy is only useful if it stays protected. Quorum DR preserves recovery integrity across locations.
- Immutable snapshots
- Encryption in transit and at rest
- Logical air gap separation
- Secure replication channels
- Role-based access control
- Automated recovery testing
- Clean Room validation
The remote copy is protected with the same security posture as the local copy. Disaster Recovery should not create a weaker recovery path.
12 The Modern Threat
Disaster Recovery and ransomware
Ransomware often turns a local outage into a broader recovery event — encrypting production data, compromising credentials, targeting backup repositories, or forcing teams to isolate the primary environment. Quorum DR maintains protected copies outside the primary site. In a ransomware event, teams can:
The goal is not just to recover quickly. The goal is to recover safely.
13 Knowing The Fit
When to choose Disaster Recovery
DR is the right fit when the business needs a second protected place to run.
- You require geographic redundancy
- You operate a secondary site
- Continuity must survive facility loss
- Regulations mandate offsite protection
- Downtime tolerance extends beyond hardware
- Infrastructure is centralized
- Ransomware recovery may require isolation
- You want control of the secondary environment
Common Disaster Recovery gaps
Organizations often assume they have DR because they have offsite backups. That is not enough. Common gaps include:
- No secondary activation environment
- Replication without tested recovery
- Unclear RTO and RPO
- Missing dependency mapping
- Manual recovery sequencing
- Unprotected backup repositories
- No ransomware validation workflow
- No regular DR testing
A DR plan should prove one thing clearly: the business can operate when the primary site cannot.
14 The Platform
How Quorum supports Disaster Recovery
- Snapshot-based protection
- Local High Availability foundation
- Independent block replication
- Secondary onQ activation
- Instant workload boot
- Policy-based infrastructure recovery
- Immutable recovery points
- Encrypted replication
- Automated recovery testing
- Clean Room validation
- Flexible Appliance or Flex deployment
A recovery architecture built for real disruption. Not just backup completion.
15 Put It Into Practice
Disaster Recovery checklist
A strong DR strategy should answer:
- Which systems require remote recovery?
- What is the RTO for each critical workload?
- What is the RPO for each critical workload?
- Where will systems run if the primary site is down?
- Is there a second protected copy?
- Is replication encrypted and monitored?
- Are snapshots immutable?
- Are dependencies mapped?
- Can systems activate in the correct order?
- Has remote activation been tested?
- Does the plan account for ransomware isolation?
- Is DRaaS a better fit if no second site exists?
DR works best when architecture, objectives, and testing are aligned.
When Restore Is Not Enough
High Availability protects systems. Disaster Recovery protects the business.
When the primary site is unavailable, organizations need more than backup data — a second protected copy, a secondary place to run, and a tested path back to operations. Quorum delivers it through snapshot-based activation, secure replication, and structured infrastructure recovery.
Right onQ. Off Was Never an Option.
Eliminate Downtime from Recovery
Eliminate Downtime from Recovery
Boot systems directly from snapshots and keep operations running without restore delays.
