Before the restore
1Security + Veeam. Recovery for the data, memory for the access.
Veeam Backup for Microsoft 365 is the last line: Exchange Online, SharePoint Online, OneDrive and Teams, backed up to storage you control, immutable, restorable down to the item. 1Security is the line before it: who could reach that data, who actually touched it, and what changed in the days before the incident. Together, you can bring the data back - and answer for it.
- 12h → 10 mina blast-radius investigation, before and after
- 3 yearsof activity memory - without a SIEM contract
- Same dayfrom read-only consent to first findings
The last line
What Veeam does well.
When the worst has already happened, one layer decides how bad it stays - and Veeam takes that layer seriously.
The whole tenant, backed up
Exchange Online, SharePoint Online, OneDrive for work or school and Microsoft Teams, backed up to storage you choose - from local disk and SMB shares to Amazon S3, Azure Blob, IBM Cloud or Wasabi.
Immutable means immutable
On object storage with immutability, backed-up data cannot be modified or deleted within the immutability period - compliance mode by default, and once enabled, immutability can’t be switched off. The copy an incident can’t rewrite.
Restore down to the item
Veeam Explorers bring back a single mail, file or Teams item - and the Restore Portal lets end users recover their own data without opening a ticket.
The question before
The gap Veeam isn’t designed to close.
Veeam’s scope is recovery, and it holds that scope deliberately: when data is encrypted, deleted or corrupted, an immutable copy exists somewhere the incident can’t rewrite, and it comes back - down to the single item. That is exactly what the last line of defense should be.
But a backup is a photograph of content, not of access. It can put every file back; it was never meant to say who could reach those files before the incident, which sharing links were live, or which account was reading four times its usual volume the week before.
Recovery answers “can we get it back?”. The incident’s other questions - what was reachable, by whom, since when - belong to a different instrument.
The memory
What 1Security adds.
A permission-centric decision engine for Microsoft 365 - every identity, what it could reach, and what it actually did, three years back.
- 01
Every identity, mapped
Human, app, AI agent, device - 1Security maps what each one can reach and what it actually did. The access side of the incident stops being a reconstruction and becomes a record.
- 02
Blast radius in minutes
Every file, site and mailbox an account can reach - direct grants, sharing links, groups, inheritance - resolved in minutes. When you know what was reachable, you know what to check - and what to restore first.
- 03
The week before, on record
Three years of activity history without a SIEM contract, per-identity baselines and anomaly episodes with an alert line you position yourself - so “what changed before the incident” is a lookup, not an archaeology project.
- 04
From found to fixed
Revoke the access, expire the links, sever the sessions - automations with grace periods and review queues, so nothing irreversible happens without a human decision.
Joint architecture
The copy and the memory.
Veeam keeps the immutable copy: the tenant’s content - Exchange, SharePoint, OneDrive, Teams - backed up to storage you control and restorable down to the item. 1Security connects to the same tenant with read-only consent - no agents, standard Microsoft licenses, first findings the same day - and keeps the memory: the permission graph of who can reach what, and three years of who actually did. When an incident hits, Veeam brings the data back while 1Security scopes what was reachable and closes what let it happen - revoked access, expired links, severed sessions, each behind a human decision.
DORA in practice
Response and recovery, both halves.
DORA’s ICT risk-management framework splits an incident in two. Articles 11 and 12 demand response and recovery: backup policies and procedures, restoration and recovery methods that bring the entity back. Article 17 demands the other half: an incident management process that detects, records and classifies every ICT-related incident.
Veeam is the recovery half made real: immutable backups of Exchange, SharePoint, OneDrive and Teams, restoration down to the item, on storage the incident can’t rewrite. 1Security is the detection-and-record half for Microsoft 365: baselines that flag the anomaly, a permission graph that scopes it in minutes, and three years of activity to classify it against.
One regulation, two obligations, two instruments - and a financial entity that can show its supervisor both the restore and the record.
Restore the data. Answer for the access.
Keep the immutable copy with Veeam. Keep the memory of who could reach it - and who did - with 1Security.
Or explain the incident from the backup alone.