When a major fire affected one of India's leading data centres in 2026, the immediate attention was understandably focused on the incident itself.
What caused the fire? How extensive was the damage? Which customers were affected? How long would recovery take?
These were important questions.
But they were not the questions that interested me most.
Long after the headlines faded, one question continued to trouble me.
If the data centre itself becomes unavailable, where exactly is my data?
Not my applications. Not my servers. Not my storage.
My data.
That simple question, surprisingly, has become one of the most difficult questions I ask organisations during Cyber Recovery (CR) test, Business Continuity (BC), Disaster Recovery (DR) and Operational Resilience (OR) engagements.
Very few organisations can answer it with confidence.
The Comfort of 99.99%
Every major data centre provider proudly talks about availability.
99.9%.
99.99%.
99.999%.
The numbers are impressive. The infrastructure is world-class. The certifications inspire confidence. The Service Level Agreements appear reassuring.
There is absolutely nothing wrong with these commitments. They are valuable. But they answer only one question.
"How available is my service likely to be?"
They do not answer another question that may become far more important during a crisis.
"If your entire Data Centre becomes unavailable tomorrow morning, how do I recover my data?"
Availability and Recoverability are related. They are not the same.
One attempts to prevent interruption. The other determines survival after interruption.
A Question I Have Been Asking for Years
For many years I have asked clients a simple question.
"Have you actually seen the Disaster Recovery architecture of your cloud or data centre provider?"
Most organisations reply confidently.
"We have DR."
"Our contract/ SLA is for 99.999%."
"They are a Tier III facility."
Then I ask another question.
"Can I see the contract?"
Surprisingly, I have almost never had the opportunity.
Not because organisations are unwilling. Because very few have ever asked the provider for those details.
The assumption is simple. "If they operate a world-class data centre, they must also have world-class recoverability."
Perhaps. Perhaps not.
The point is this.
Recoverability should never depend upon assumption. It should depend upon demonstrated capability.
The Questions Every Customer Should Ask
The discussions following the data centre fire reminded us of something important.
Every customer—not just technology teams—should be asking questions such as:
- Where is my production data physically located?
- Where is my recoverable copy stored?
- Is it in a different geography?
- Is there an immutable or offline copy?
- Who controls the encryption keys?
- Can I restore my own data independently?
- When was the last successful full restoration?
- Has that restoration been demonstrated?
- If your entire facility became unavailable tomorrow morning, what exactly would happen to my business?
These are not technical questions. They are governance questions.
Boards should ask them. Risk Committees should ask them. Auditors should ask them.
Customers should certainly ask them.
The Difference Between Backup and Recoverability
One of the misconceptions I encounter most frequently is that backup automatically means recoverability.
It does not.
A backup is a copy.
Recoverability is a demonstrated capability.
A backup can exist without ever having been restored. A recovery strategy proves that restoration actually works.
That distinction may appear subtle. During a major disruption, it becomes critical.
The objective is not to create more backups. The objective is to create confidence that business operations can actually be restored.
Recoverability Is an Engineering Discipline
At itSimple, we gradually reached an important conclusion.
Recoverability should not be treated as an operational activity.
It should be engineered.
That philosophy led us to adopt what we describe as a Four-Stage Data Protection Journey.
Stage One (Production Data – Original Copy)
The operational copy supporting day-to-day business.
This enables normal operations.
This itself is the first backup.
Stage Two (Recoverable Backup - Geographically Separated)
A second recoverable copy maintained in a different geographical location. This is itSimple DC.
If the primary site becomes unavailable, recovery can continue from an independent environment. For Zero RTO, RPO – there needs to be online-realtime replication between the DC and the DR.
Stage Three (Disaster Recovery Copy – Geographically Separated from DC)
This is itsimple DR. This third copy is over and above the Client's Primary Production Data and itSmiple's DC.
Stage Four (Immutable Copy – Geographically Separated from all)
This copy provides protection against ransomware, accidental deletion, malicious activity, and catastrophic infrastructure failures.
It is the tape copy we hope never to use.
Which is precisely why it is so valuable.
At itSimple, we practice what we preach. This is the architecture that we follow for our clients, ensuring Your Data Is Safe With Us!
Could There Be More Copies?
Certainly.
Some organisations maintain four copies. Others maintain five.
Some combine multiple cloud providers. Others incorporate immutable storage or long-term archival strategies.
There is no universal formula.
Preparedness is ultimately a balance between:
Business criticality. Recovery objectives. Cyber resilience. Regulatory expectations. Investment. Risk appetite.
The objective is not maximum redundancy.
The objective is appropriate recoverability.
The Real Lesson
Whatever the final technical findings of the 2026 data centre incident may ultimately reveal, the broader lesson extends far beyond any single organisation.
The incident reminded us that confidence and preparedness are not always the same.
A professionally managed data centre deserves confidence. A highly available cloud platform deserves confidence. A sophisticated backup solution deserves confidence.
But recoverability deserves evidence.
Every organisation should know—not assume—where its last recoverable copy resides.
Every organisation should understand—not hope—how recovery will occur.
Every organisation should validate—not merely trust—its Disaster Recovery capability.
Because during a crisis, the question will no longer be,
"How many nines of availability did we purchase?"
The question will be,
"Can we recover our business?"
That is the question that matters.
And that is the question we believe every organisation should answer before the next unexpected event, not after it.
About itSimple
At itSimple, we believe that data protection is not measured by the number of backups created but by the 100% confidence with which organisations can recover when the unexpected occurs. Driven by Founder Kamal's father line "Family is Biggest Backup"
Our approach combines 100% focus on Backup, consistent trainings ( 200+ certifications by OEMs), fastest customer issue response, 24X7 support, resilient backup strategies, geographically separated Disaster Recovery, offline protection, and governance-led recoverability, 100% MII tool ( iBART, Indian Backup Archival Audit for restoration Testing) for organisation level Data Sovereignty and Cyber Recovery planning to help organisations ensure that their most critical asset—their data—remains recoverable when it matters most, proven by 98% Restoration record.
Because your business does not recover from uptime. It recovers from recoverability.