Cyber Resilience
Cyber Protection

Cyber Recovery On-Premise

Full sovereignty
and your infrastructure

Ransomware destroys backups along with the production environment. The Bunker stands beyond the attack's reach. Physically disconnected from the network after every transfer, with copies that no one can overwrite or encrypt - not a hacker who has been sitting in the network for months, not even an administrator with the highest privileges.

When the production environment goes down, the Bunker remains untouched. You build it on hardware of your choice - we design the architecture. It sits in your server room. It belongs to you.

see how the Digital Bunker works in practice

In 2025, the full cost of a ransomware attack averages approx. PLN 1.5M, and in one out of three cases PLN 2.5-5M
the biggest cost is downtime and lost orders, not the ransom

Solution architecture

The Bunker sits physically in your data center. Below is the exact data flow: from production backup to a clean, verified copy ready for recovery.

Digital Bunker architecture

Data Center

01–02

01

Backup on the production Data Domain

Data backed up by your application (NetBackup, CommVault, Avamar) to the production Data Domain array.

02

Backup catalog copied

Backup index catalog copied to the array - preparation for replication over the air-gap.

Air-Gap

03–05

03

Air-Gap opening

The Bunker initiates the connection from its side. The production environment cannot connect on its own.

04

Replication to the Bunker

Data replicated one-way through a firewall / data diode to the array in the Bunker.

05

Air-Gap Closure

After the transfer, the connection is closed immediately. The Bunker is disconnected from the network again.

Digital Bunker

06–10

06

Copy in an isolated environment

The Backup Application Server creates a copy of the data inside the Bunker network.

07

WORM lock (Compliance)

Hardware-enforced immutability lock. No one can overwrite, modify, or delete the copy.

08

CyberSense AI scanning

200+ analyses without recovering the data: signatures, entropy, metadata semantics.

09

Report and copy tagging

The copy is marked as clean or flagged. Alerts are sent to monitoring.

10

Daily automated cycle

The Bunker builds a history of clean copies. In the event of an attack - the last confirmed version.

Recovery runs from the array in the Bunker directly to the production environment. Data leaves the Bunker only in recovery mode - a controlled, authorized process.

Have questions about the architecture?

Our engineers will answer your questions about integration, RTO/RPO, and fit with your environment.

VIEW

a presentation explaining
how the Digital Bunker works

What is the Digital Bunker

Cyber Recovery is not backup. A four-pillar architecture

Backup protects against hardware failure. Disaster Recovery protects against physical catastrophe. Digital Bunker protects against something else - a deliberate, prolonged attack that targets your backups as its first objective.

1. ISOLATION

Physical and logical separation of data from the production network. The Bunker opens a connection from the inside only for the duration of synchronization, typically 15-40 minutes. After the transfer: full disconnection. The production environment has no knowledge that the Bunker exists.

2. IMMUTABILITY

A WORM (Write Once, Read Many) lock applied at the hardware level to every copy. Once written, data is locked for a defined retention period - 30, 60, or more days. No administrator, no ransomware, and no vendor support can change this.

3. VERIFICATION

CyberSense AI scans every copy without recovering it - analyzing file structure, entropy, metadata, and behavioral patterns. 200+ analyses per copy, 99.5% accuracy. After an attack, the company knows exactly which copy is clean and fit for recovery.

Cybersense AI

4. PROCEDURES

Having a Bunker isn't enough. Tested, documented data recovery procedures - carried out regularly, measuring actual RTO and RPO. The company knows how long recovery will take. It doesn't assume - it knows.

DR Procedures
The only effective defense against destructive ransomware is the ability to restore full business functionality quickly and completely.
The Digital Bunker concept - core principle

Heart of the system

CyberSense - AI Engine,
that "understands" file structure.

CyberSense doesn't look for viruses - that's what antivirus software is for. CyberSense analyzes whether data is behaving normally. The difference is crucial: antivirus software misses new ransomware variants. CyberSense detects behavioral anomalies, even when the malicious code doesn't yet exist in any database.

Security Analytics

Verification of ransomware attack statistics

The database of known ransomware and malware signatures is continuously updated. The first layer of detection is instant identification of known threats.

→ Known ransomware signatures

→ File entropy (encryption indicator)

→ Analysis of differences between successive backups

Change monitoring

Detecting changes in content and metadata

The system learns what's normal for your environment over several backup cycles - then detects every deviation.

→ Semantic analysis of file metadata

→ Language pattern counting / NLP

→ Detecting hidden background encryption

Machine Learning

A system trained for multiple attack vectors

Machine learning on historical and simulated data. The system detects threats that aren't yet in any virus database - through behavioral analysis.

→ Machine learning based on behavior patterns

→ Unsupervised learning (unsupervised ML)

→ Trained on simulated attack data

200+

analyses per copy:
content-based and ML combined

99,5%

damage and infection detection effectiveness

no need to recover data - in-place scanning

Technological independence

We match the technology to the client. Not the other way around.

We build Bunkers on various hardware platforms - depending on the environment's requirements, data volume, budget, and the organization's technology preferences. No lock-in to a single vendor.

Platform A

Huawei OceanProtect 

AI Analyzer

OceanCyber

Drive type

All-Flash NVMe

Interfaces

10/25/100 GbE

Analysis speed

Up to 50 TB/h

Max. expansion

4.2 PB

Data reduction

Up to 72:1

Compatible
Tools

NetBackup, Commvault, DataBackup

Platform B

Dell PowerProtect DD

AI Analyzer

CyberSense

Drive type

HDD (+ SSD Cache)

Interfaces

10/25/100 GbE

Analysis speed

Up to 18-25 TB/h (HDD limit)

Max. expansion

1.5 PB (On-prem)
/ 4.5 PB (Cloud tier)

Data reduction

Up to 65:1

Compatible
Tools

PPDM, NetWorker, NetBackup, Commvault

Platform C

Hitachi VSP 5600

AI Analyzer

CyberSense

Drive type

All-Flash NVMe

Interfaces

10/25/100 GbE (RoCE) / 32-64G FC

Analysis speed

Up to 50 TB/h+ (CPU/CS limit)

Max. expansion

69.3 PB (Raw) / 287 PB (External)

Data reduction

Up to 7:1

Compatible
Tools

Commvault, NetBackup

Different hardware platforms - the same business outcomes. We match the solution to your environment, not to our catalog.
* Due to currently very volatile market prices for infrastructure, pricing may change.

Independence principle

We work with your infrastructure

If your organization already has some storage infrastructure in place, we assess whether and how it can be incorporated into the Bunker architecture. We choose the solution that best fits your needs, not our sales preferences.

🎯

Minimalism principle

You don't protect 100% of your data. You protect vital data.

To resume operations after an attack, it's often enough to secure just 30% of the most critical assets - the applications and data without which you can't "restart" at all.

Critical data

Important for daily operations - not all of it needs to be in the Bunker

Vital data → Bunker

Without this data, the company cannot "restart" after an attack

~30%

of volume

Not sure which platform to start with? Our architect will assess your environment and select the optimal configuration - free of charge.

Five stages. Three to six months of implementation

Deploying an on-prem Bunker is an engineering project - it requires analysis, design, configuration, and certification. We're with you at every stage.

01

Business processes

Identification of vital data, downtime cost analysis, RTO/RPO definition for every system.

02

Applications

Inventory of systems, dependency mapping, selection of backup tools and their integration with the architecture.

03

Critical materials and configurations

Bunker network design, air-gap configuration, selection and ordering of the hardware platform.

04

Deployment and tuning

Hardware installation, WORM and CyberSense configuration, first synchronization cycles and parameter optimization.

05

Tests and procedures

Recovery testing for all protected areas, documentation for auditors, knowledge transfer to your team.

Who it's for
Digital Bunker On-Prem?

01

Large private corporations with their own IT

Revenue of PLN 200M+, 500+ employees, an in-house IT department. They have CAPEX budget, staff to run DR infrastructure, and want full control without depending on an external provider. The Bunker fits into their existing security architecture.

GDPR

ISO 27001

NIS2

SOC inside

02

Critical infrastructure operators

Energy, gas, water utilities, transport, telecommunications. External cloud is not an option for SCADA/OT systems. Sector regulators require documented recovery capabilities for critical systems within strictly defined RTO/RPO.

KSC

NIS2

URE

OT/SCADA

03

Central public institutions and government agencies

Ministries, agencies, security services, military. Data may be classified or otherwise specially protected. External cloud is ruled out by regulation. Every purchasing decision is subject to public procurement law - technical documentation is needed for the tender

Classified info

KSC

PZP

CERT Polska

04

Banks and financial institutions

Commercial banks, insurers, investment fund companies. KNF, SWIFT CSP, and DORA requirements. Management bears personal liability for business continuity. They need complete documentation for regulatory and internal auditors - ready without additional preparation.

KNF

SWIFT CSP

DORA

NIS2

Does your organization fit one of these segments?

Talk to an Engave engineer or book a solution demo

Model comparison

On-Prem vs. Cloud.
Two tools for different needs.

The same CyberSense AI technology, the same level of security - a different infrastructure location and cooperation model. The choice depends on your organization's requirements, not on which model is "better."

Model A

On-Prem Bunker

CAPEX from PLN 2.5M

one-time investment + upgrades

Location

In your organization - full physical control

Sovereignty

Absolute - not a single byte leaves the organization

Offline

✓ Full - independent of external networks

Regulations

✓ NSC, classified information, internal policies

Deployment

3-6 months

IT team

Your own team to manage the infrastructure

Upgrades

Every 3-5 years, on the organization's side

Model B

Cloud Bunker

OPEX from PLN 8,000/month

no upfront investment

Location

Engave data center - no infrastructure of your own required

Sovereignty

Data in Engave's secure infrastructure

Offline

Requires a connection to Engave's data center

Regulations

Depends on the organization's sector-specific regulations

Deployment

2-4 weeks

IT team

No requirements - Engave manages everything

Upgrades

Automatic - always the latest hardware included in the price

Not sure which model to choose? Our architect will help you pick the right solution with no obligation

ISO Certificates

ISO certifications are a global standard of excellence, guaranteeing that our company operates effectively, efficiently, and in compliance with regulations.

It's proof that our organization is committed to continuous improvement, taking both quality and customer satisfaction seriously.

OUR CLIENTS

Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient

The largest project of its class in Poland

We designed and deployed the Digital Bunker for, among others, Zakład Ubezpieczeń Społecznych and a private company in the financial sector. Very different needs - the same protection.

over 1 PB

of data secured in the ZUS Bunker

120 TB

data protected in the Bunker for the financial sector

ZUS is one of the largest and most demanding cybersecurity projects in Polish public administration. The scale of data, regulatory requirements, the need for business continuity, and zero tolerance for downtime - exactly the parameters that shape the architecture of the Digital Bunker.

Recovery tests were carried out for all protected areas. Different hardware platforms - the same business outcomes. We have testimonials and deployment documentation that we can share as part of the procurement process.

15 years on the market

Polish company, Polish capital

Verifiable testimonials

Tender documentation

Recovery tests after implementation

Testimonials

What our clients say about us

"Given Engave S.A.'s high level of professionalism, we can wholeheartedly recommend their IT services to other companies. Throughout our cooperation, the company's employees have proven to be top-class, well-organized specialists. The quality of the services provided, along with their understanding of our needs, directly contributed to a significant improvement in our operations."

- HUBIX SP. Z O.O.

"Over the course of eighteen months of cooperation, Engave proved to be a reliable, flexible and results-oriented partner. We had the opportunity to get to know Engave's competencies and working methods over an extended period, both at the process management and operational level. That is why we confidently recommend them as a trustworthy partner for delivering complex organizational and technological projects."

- Medical University of Łódź

"Working with Engave gave us reliable, comprehensive insight into the state of our IT infrastructure. The audit was carried out professionally, and its results were presented in well-substantiated documentation that now serves as our roadmap for further development. Engave is a partner able to translate complex technical issues into the language of business benefits. We recommend their services to any organization for which IT security is a priority."

- ApartHotel Termy Uniejów

"Man Truck BUS Polska Sp. z o.o. commissioned Engave S.A. to supply, deploy, and configure a ManageEngine solution for monitoring networks, servers, and database virtualization across its IT systems, as well as for mobile device management. The scope of the contract was completed and delivered on time and with due diligence."

- MAN TRUCK BUS POLSKA

"The International Institute of Molecular and Cell Biology in Warsaw confirms that Engave supplied and deployed, with due diligence, computer hardware for a shared next-generation DNA sequencing platform. The order was completed on time and properly."

- International Institute of Molecular and Cell Biology

"The Digital Bunker at ZUS is a project that is changing the way public administration thinks about data protection - shifting from reactive response to proactive resilience. In delivering this implementation, Engave S.A. proved that Polish technological expertise can meet the most demanding security standards of public institutions. ZUS confirms the contract was properly performed."

- Zakład Ubezpieczeń Społecznych

"We hereby confirm that Engave S.A. delivered to Fujitsu Technology Solutions spółka z o.o. IT hardware and software licenses along with support. We recommend Engave S.A. as a trusted and proven partner."

- FUJITSU TECHNOLOGY SOLUTIONS

"Engave S.A. provided a service covering the deployment of VMware virtualization software, installation and configuration of the virtualization platform, reconfiguration of the LAN and security layers, installation, configuration and maintenance of the backup environment, repairs to the backup system, deployment of DR mechanisms, and more. All work was carried out with due diligence and with a very high level of commitment from the contractor."

- PGW Wody Polskie and the Institute of Meteorology and Water Management

"The IT Department of Miejskie Zakłady Autobusowe Sp. z o.o. confirms that, as part of the modernization of the central backup system, Engave supplied and deployed a data protection management system. The delivery was carried out in accordance with the contract. The entire scope of the contract was completed with due diligence and within the specified deadline."

- Miejskie Zakłady Autobusowe SP. Z O.O.

"The order carried out by Engave was completed on time, in full, with due diligence, and in compliance with all requirements set out in the contract."

- IT Department of the Capital City of Warsaw

"The service delivered by Engave S.A. was completed on time and with due diligence, with tremendous commitment and professionalism on the part of the contractor. The reliability and accuracy of the valuation and documentation prepared (...) was confirmed by a team of researchers in computer science and economics."

- Narodowy Fundusz Zdrowia

"All work was carried out properly, in accordance with the agreed scope, on time, and with due diligence. We have no reservations about the quality of the services provided."

- ENAMOR SP. Z O.O.

"Engave provided the mounting, installation, and commissioning of the array in a way that enabled full native-mode interoperability with all servers. Tests were carried out confirming the correct operation of the expanded arrays and the correct connection to the client's environment. The upgraded environment was brought back to full functionality as it was before the expansion. All work was carried out correctly and in accordance with the terms of the contract."

- Narodowy Fundusz Zdrowia

WE WORK WITH THE BEST

Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient
Klient

Contact us
with Engave

Cybersecurity, IT care, digitalisation - whatever the topic, we're happy to talk. Describe your need and the right specialist will get back to you within 24 business hours.

CONTACT:

biuro@engave.pl
+22 863 13 90
Technical support: +48 604 470 151
16 Czarodzieja St., 03-116 Warsaw, Poland

The controller of your personal data is Engave S.A., headquartered in Warsaw. Information on data processing principles is available in the Privacy Policy. Consent may be withdrawn at any time, without affecting prior processing, by contacting: biuro@engave.pl