“We have backups” and “we can prove we restored a specific file to how it looked on a specific date” are very different claims. Compliance cares about the second one.
A Malta-based professional services office needed to bring its backups up to the standard its clients and regulators now expect. The bar has moved. It is no longer enough to have a copy of the data somewhere. A firm increasingly has to demonstrate that records are retained for a defined period, that they can be recovered to a point in time, and that the backup itself can’t be quietly tampered with or destroyed, including by ransomware or a disgruntled insider. As Malta’s only Synology Platinum Partner and a long-standing Eaton power partner, Sirap specified a compact, redundant backup appliance and, around it, the policies that turn storage into evidence.
The challenge
The office was relying on ad-hoc copies to a single external drive: no versioning, no redundancy, and no protection if the power dropped mid-copy. For a firm handling client records that left two gaps that mattered. It couldn’t prove a clean, point-in-time copy existed for any given date, and a single drive or power-supply failure could take the only backup with it. They needed retention they could stand behind in an audit, and hardware that wouldn’t itself become the weak link.
What “compliance” actually demands of a backup
Compliance is often treated as a vague pressure, so it helps to be concrete about what it asks of a backup, because each requirement maps to a specific technical control. Under the GDPR, an organisation has to be able to restore the availability of personal data in a timely manner after an incident, and to keep it only as long as it has a lawful reason to. The EU’s NIS2 directive, now being transposed across member states including Malta, pushes the same expectations harder for a growing set of organisations: demonstrable resilience, tested recovery, and accountability for it. None of that is satisfied by “there’s a copy on a drive in the cupboard.” It calls for defined retention, protection against tampering, verified restores, and a record that the controls are actually running. We designed the deployment backwards from those requirements rather than forwards from the hardware.
The hardware: why redundant power was the starting point
We deployed a Synology RS822RP+, a 4-bay 1U rackmount NAS built around an AMD Ryzen V1500B quad-core processor with ECC memory. The defining choice for a backup role is the RP, the redundant power supply. A backup appliance that dies mid-window because a single PSU failed is worse than useless: it fails precisely when you’re depending on it. Dual hot-swappable supplies remove the most common single point of failure on a rackmount unit, so a failed PSU is a service call, not a missed backup. The ECC memory matters for the same reason: it guards against the bit-level errors that can silently poison a backup set as it’s written. We chose the rackmount form factor deliberately too; even in a small office, a unit fixed in a rack with proper power and cooling is far less likely to be unplugged, knocked, or “tidied away” than a desktop box under someone’s desk.
Versioning isn’t the same as immutability
The instinct is to reach for snapshots and call it done. Snapshots are the right foundation. On Btrfs they’re near-instant and low-overhead, and they let the office restore a file, folder or share to exactly how it looked on a chosen day. But for compliance and ransomware resilience, ordinary snapshots have a hole: anyone with administrator access can delete them, and that’s exactly what modern ransomware does before it encrypts.
Immutable (WriteOnce) snapshots: the control auditors actually want
On DSM 7.2 with Btrfs, snapshots can be made immutable using WriteOnce (WORM) technology, locked for a defined retention period during which no one, not even an administrator or a compromised admin account, can alter or delete them. This is the difference between a backup you hope survives an incident and one that is guaranteed to. It’s worth separating from simple snapshot “locking,” which only stops the automatic retention policy from pruning a snapshot early; immutability is the stronger control, designed to withstand a malicious actor with full access. For a firm that has to evidence a tamper-proof retention chain, that distinction is the whole point.
Designing the retention policy, not just enabling it
Retention is where good intentions usually fall apart, because the defaults rarely match any real obligation. We mapped the schedule to the firm’s actual requirements: how frequently recovery points are captured, how long each tier is kept, and when older versions roll off. A typical structure keeps frequent short-term points for everyday “I deleted the wrong thing” recovery, plus longer-spaced points held for the months or years the firm is required to retain them. The aim is a retention chain that is both provable and defensible: long enough to meet the obligation, deliberate enough that you can explain in an audit why each point exists and when it expires. Storage is finite, so designing this properly is also what keeps the appliance from silently filling up.
A backup you haven’t restored is a guess
The most common and most dangerous failure in backup is the one nobody notices until it’s too late: the job ran green for two years and then didn’t actually restore. Compliance regimes increasingly expect tested recovery for exactly this reason. We validated restores as part of handover, confirming that real files come back intact and usable, not just that the backup reports success. We also set up DSM’s notifications so the office is told when a job fails or a drive reports trouble, rather than discovering it during an incident. Synology’s logging gives the firm the audit trail to show backups ran and restores were tested, which is itself part of what an auditor wants to see.
Access control and encryption: closing the obvious doors
A compliance backup is also a concentrated copy of sensitive data, so how it’s accessed matters as much as how it’s stored. We enabled encryption so that data is protected in transit to the appliance and the volume is encrypted at rest, meaning a stolen drive isn’t a readable copy of client records. Administrative access is restricted and protected with two-factor authentication, and account roles are separated so day-to-day users can’t reach the backup configuration. These are unglamorous controls, but they are exactly the ones a data-protection review asks about, and immutability does its best work behind them.
Catching corruption before it reaches the restore
A backup is only useful if the data inside it is intact, and storage degrades silently over time, the “bit rot” that surfaces only when you finally try to restore. Because the volume runs on Btrfs, we scheduled regular data scrubbing: the system reads every block, compares it against a stored checksum, and where it finds a mismatch repairs it from RAID redundancy. Running this on a defined schedule, quarterly at a minimum and set during quiet hours, means corruption is found and corrected while a good copy still exists, not discovered on the day it’s needed.
The honest part: one appliance is not a backup strategy
We’re explicit with clients about this. A single device on one site, however well configured, is one copy in one place. The widely used 3-2-1 principle, three copies on two types of media with one offsite, exists because fire, theft and flood don’t care how good your NAS is. This RS822RP+ is the resilient on-site anchor of that strategy. We designed it to extend cleanly to an offsite or cloud copy via Synology Hyper Backup as the next step, and to take on endpoint and server backups through the license-free Active Backup for Business if the office wants to consolidate workstation, file-server and email protection onto the same appliance. That last point is worth weighing: many offices discover their laptops, where a lot of working data actually lives, were never backed up at all, and one appliance can close that gap too. The deployment is a strong foundation, described as a foundation rather than oversold as a complete answer.
Power protection with Eaton
A backup appliance is only as trustworthy as its last completed job, so we paired the RS822RP+ with an Eaton UPS. As Malta’s Eaton power partner since 1988, we sized the unit to keep the NAS running through brief outages and to trigger a clean, automatic shutdown during longer ones, so a power cut can never leave a half-written backup or a damaged volume behind. With the unit’s redundant supplies, power stops being a route to data loss.
Backed by SirapCare – support that goes beyond the warranty
Hardware is only as good as the support behind it. Every Synology system we supply can be backed by SirapCare, our dedicated support programme built around four pillars:- Advanced replacement — a replacement unit is dispatched before the faulty one is returned, so you’re not waiting on logistics while your business waits on you.
- Warranty extensions — protect your investment well beyond the standard cover, with predictable costs and no surprises down the line.
- Preventive maintenance — scheduled health checks that catch ageing drives, capacity ceilings and configuration drift before they cause an outage.
- Configuration support — as your environment grows and changes, our engineers are on hand to reconfigure, expand and tune your storage.
The outcome
The office now has a dedicated, redundant backup appliance with versioned, point-in-time recovery it can demonstrate to an auditor, protected against drive failure, power loss, silent corruption and accidental deletion, and hardened against ransomware by immutable retention. Restores have been tested rather than assumed, access is locked down and encrypted, backups complete reliably inside their window, and there’s a clear, costed path to the offsite copy that completes the picture. One local partner is accountable for keeping all of it true. Talk to us about compliance backup with Synology →Related guides
- High-availability and air-gapped backup.
- UPS and power protection: a backup or HA system is only safe while it stays powered.
- Securing networked infrastructure for NIS2 and DORA.
Featured Products in this article
-

Synology FlashStation FS200T Compact 6-bay All-Flash NAS
Read more -

Synology PAS7700 Active-Active NVMe Enterprise Storage
Read more -

Synology RackStation RS4826xs+ 12-Bay Rackmount NAS
Read more -

Synology RackStation RS3626xs+ 12-Bay Rackmount NAS
Read more -

Synology RackStation RS1626xs+ 4-Bay Rackmount NAS
Read more -

Synology RackStation SA3200D 12-Bay Dual Controller Rackmount NAS
Read more -

Synology RackStation RS2825RP+ 16-Bay Rackmount NAS
Read more -

Synology ActiveProtect Applicance DP7200
Read more -

Synology RackStation SA3400D 12-Bay Dual Controller Rackmount NAS
Read more -

Synology RackStation RS4021xs+ 16-Bay Rackmount NAS
Read more -

Synology RackStation RS1619xs+ 4-Bay Rackmount NAS
Read more -

Synology RackStation RS1221+ & RS1221RP+ 8-Bay Rackmount NAS
Read more
Kurt Paris
With an MSc in Software Engineering, and over 15 years in IT Management, Kurt Paris leads technology strategy at Sirap. Zebra Technologies, Domino and Cisco-certified, he helps Maltese businesses build resilient storage & backup infrastructure, Machine Vision & AutoID Automation

