Cyber Recovery On-Premise
Ransomware destroys backups along with the production environment. The Bunker stands beyond the attack's reach. Physically disconnected from the network after every transfer, with copies that no one can overwrite or encrypt - not a hacker who has been sitting in the network for months, not even an administrator with the highest privileges.
When the production environment goes down, the Bunker remains untouched. You build it on hardware of your choice - we design the architecture. It sits in your server room. It belongs to you.
How the Digital Bunker works
The Bunker sits physically in your data center. Below is the exact data flow: from production backup to a clean, verified copy ready for recovery.
Data Center
01–02
01
Data backed up by your application (NetBackup, CommVault, Avamar) to the production Data Domain array.
02
Backup index catalog copied to the array - preparation for replication over the air-gap.
Air-Gap
03–05
03
The Bunker initiates the connection from its side. The production environment cannot connect on its own.
04
Data replicated one-way through a firewall / data diode to the array in the Bunker.
05
After the transfer, the connection is closed immediately. The Bunker is disconnected from the network again.
Digital Bunker
06–10
06
The Backup Application Server creates a copy of the data inside the Bunker network.
07
Hardware-enforced immutability lock. No one can overwrite, modify, or delete the copy.
08
200+ analyses without recovering the data: signatures, entropy, metadata semantics.
09
The copy is marked as clean or flagged. Alerts are sent to monitoring.
10
The Bunker builds a history of clean copies. In the event of an attack - the last confirmed version.
Recovery runs from the array in the Bunker directly to the production environment. Data leaves the Bunker only in recovery mode - a controlled, authorized process.
Our engineers will answer your questions about integration, RTO/RPO, and fit with your environment.
VIEW
What is the Digital Bunker
Backup protects against hardware failure. Disaster Recovery protects against physical catastrophe. Digital Bunker protects against something else - a deliberate, prolonged attack that targets your backups as its first objective.
Physical and logical separation of data from the production network. The Bunker opens a connection from the inside only for the duration of synchronization, typically 15-40 minutes. After the transfer: full disconnection. The production environment has no knowledge that the Bunker exists.
A WORM (Write Once, Read Many) lock applied at the hardware level to every copy. Once written, data is locked for a defined retention period - 30, 60, or more days. No administrator, no ransomware, and no vendor support can change this.
CyberSense AI scans every copy without recovering it - analyzing file structure, entropy, metadata, and behavioral patterns. 200+ analyses per copy, 99.5% accuracy. After an attack, the company knows exactly which copy is clean and fit for recovery.
Having a Bunker isn't enough. Tested, documented data recovery procedures - carried out regularly, measuring actual RTO and RPO. The company knows how long recovery will take. It doesn't assume - it knows.
Heart of the system
CyberSense doesn't look for viruses - that's what antivirus software is for. CyberSense analyzes whether data is behaving normally. The difference is crucial: antivirus software misses new ransomware variants. CyberSense detects behavioral anomalies, even when the malicious code doesn't yet exist in any database.
Security Analytics
The database of known ransomware and malware signatures is continuously updated. The first layer of detection is instant identification of known threats.
→ Known ransomware signatures
→ File entropy (encryption indicator)
→ Analysis of differences between successive backups
Change monitoring
The system learns what's normal for your environment over several backup cycles - then detects every deviation.
→ Semantic analysis of file metadata
→ Language pattern counting / NLP
→ Detecting hidden background encryption
Machine Learning
Machine learning on historical and simulated data. The system detects threats that aren't yet in any virus database - through behavioral analysis.
→ Machine learning based on behavior patterns
→ Unsupervised learning (unsupervised ML)
→ Trained on simulated attack data
analyses per copy:
content-based and ML combined
damage and infection detection effectiveness
no need to recover data - in-place scanning
We match the technology to the client. Not the other way around.
We build Bunkers on various hardware platforms - depending on the environment's requirements, data volume, budget, and the organization's technology preferences. No lock-in to a single vendor.
Platform A
AI Analyzer
OceanCyber
Drive type
All-Flash NVMe
Interfaces
10/25/100 GbE
Analysis speed
Up to 50 TB/h
Max. expansion
4.2 PB
Data reduction
Up to 72:1
Compatible
Tools
NetBackup, Commvault, DataBackup
Platform B
AI Analyzer
CyberSense
Drive type
HDD (+ SSD Cache)
Interfaces
10/25/100 GbE
Analysis speed
Up to 18-25 TB/h (HDD limit)
Max. expansion
1.5 PB (On-prem)
/ 4.5 PB (Cloud tier)
Data reduction
Up to 65:1
Compatible
Tools
PPDM, NetWorker, NetBackup, Commvault
Platform C
AI Analyzer
CyberSense
Drive type
All-Flash NVMe
Interfaces
10/25/100 GbE (RoCE) / 32-64G FC
Analysis speed
Up to 50 TB/h+ (CPU/CS limit)
Max. expansion
69.3 PB (Raw) / 287 PB (External)
Data reduction
Up to 7:1
Compatible
Tools
Commvault, NetBackup
Different hardware platforms - the same business outcomes. We match the solution to your environment, not to our catalog.
* Due to currently very volatile market prices for infrastructure, pricing may change.
Independence principle
If your organization already has some storage infrastructure in place, we assess whether and how it can be incorporated into the Bunker architecture. We choose the solution that best fits your needs, not our sales preferences.
Minimalism principle
To resume operations after an attack, it's often enough to secure just 30% of the most critical assets - the applications and data without which you can't "restart" at all.
Critical data
Important for daily operations - not all of it needs to be in the Bunker
Vital data → Bunker
Without this data, the company cannot "restart" after an attack
~30%
of volume
Not sure which platform to start with? Our architect will assess your environment and select the optimal configuration - free of charge.
Implementation path
Deploying an on-prem Bunker is an engineering project - it requires analysis, design, configuration, and certification. We're with you at every stage.
Business processes
Identification of vital data, downtime cost analysis, RTO/RPO definition for every system.
Applications
Inventory of systems, dependency mapping, selection of backup tools and their integration with the architecture.
Critical materials and configurations
Bunker network design, air-gap configuration, selection and ordering of the hardware platform.
Deployment and tuning
Hardware installation, WORM and CyberSense configuration, first synchronization cycles and parameter optimization.
Tests and procedures
Recovery testing for all protected areas, documentation for auditors, knowledge transfer to your team.
01
Revenue of PLN 200M+, 500+ employees, an in-house IT department. They have CAPEX budget, staff to run DR infrastructure, and want full control without depending on an external provider. The Bunker fits into their existing security architecture.
02
Energy, gas, water utilities, transport, telecommunications. External cloud is not an option for SCADA/OT systems. Sector regulators require documented recovery capabilities for critical systems within strictly defined RTO/RPO.
03
Ministries, agencies, security services, military. Data may be classified or otherwise specially protected. External cloud is ruled out by regulation. Every purchasing decision is subject to public procurement law - technical documentation is needed for the tender
04
Commercial banks, insurers, investment fund companies. KNF, SWIFT CSP, and DORA requirements. Management bears personal liability for business continuity. They need complete documentation for regulatory and internal auditors - ready without additional preparation.
Talk to an Engave engineer or book a solution demo
On-Prem vs. Cloud.
Two tools for different needs.
The same CyberSense AI technology, the same level of security - a different infrastructure location and cooperation model. The choice depends on your organization's requirements, not on which model is "better."
Model A
CAPEX from PLN 2.5M
one-time investment + upgrades
Location
In your organization - full physical control
Sovereignty
Absolute - not a single byte leaves the organization
Offline
✓ Full - independent of external networks
Regulations
✓ NSC, classified information, internal policies
Deployment
3-6 months
IT team
Your own team to manage the infrastructure
Upgrades
Every 3-5 years, on the organization's side
Model B
OPEX from PLN 8,000/month
no upfront investment
Location
Engave data center - no infrastructure of your own required
Sovereignty
Data in Engave's secure infrastructure
Offline
Requires a connection to Engave's data center
Regulations
Depends on the organization's sector-specific regulations
Deployment
2-4 weeks
IT team
No requirements - Engave manages everything
Upgrades
Automatic - always the latest hardware included in the price
Not sure which model to choose? Our architect will help you pick the right solution with no obligation
ISO certifications are a global standard of excellence, guaranteeing that our company operates effectively, efficiently, and in compliance with regulations.
It's proof that our organization is committed to continuous improvement, taking both quality and customer satisfaction seriously.
Testimonials
We designed and deployed the Digital Bunker for, among others, Zakład Ubezpieczeń Społecznych and a private company in the financial sector. Very different needs - the same protection.
over 1 PB
of data secured in the ZUS Bunker
120 TB
data protected in the Bunker for the financial sector
ZUS is one of the largest and most demanding cybersecurity projects in Polish public administration. The scale of data, regulatory requirements, the need for business continuity, and zero tolerance for downtime - exactly the parameters that shape the architecture of the Digital Bunker.
Recovery tests were carried out for all protected areas. Different hardware platforms - the same business outcomes. We have testimonials and deployment documentation that we can share as part of the procurement process.
✓
15 years on the market
✓
Polish company, Polish capital
✓
Verifiable testimonials
✓
Tender documentation
✓
Recovery tests after implementation
Cybersecurity, IT care, digitalisation - whatever the topic, we're happy to talk. Describe your need and the right specialist will get back to you within 24 business hours.
CONTACT:
biuro@engave.pl
+22 863 13 90
Technical support: +48 604 470 151
16 Czarodzieja St., 03-116 Warsaw, Poland