1Security + Veeam

Veeam brings the data back. 1Security tells you who could reach it.

Veeam Backup for Microsoft 365 keeps an immutable copy of Exchange, SharePoint, OneDrive and Teams and restores any of it down to a single item. 1Security answers the questions that arrive with every restore: who could open that data before the incident, who actually did in the week before, which sharing links were live, and what to close so it does not happen again. Together you get the data back and the answers with it.

  • 10 min
    to know every file, site and mailbox an account could reach
  • 3 years
    of activity history on standard Microsoft 365 licenses
  • Same day
    from read-only consent to first findings

What Veeam does

Recovery you can count on.

When something is encrypted, deleted or overwritten, Veeam is the layer that decides how bad it stays.

  • The whole tenant, backed up

    Exchange Online, SharePoint Online, OneDrive and Microsoft Teams, backed up to storage you choose - local disk, SMB shares, Amazon S3, Azure Blob, IBM Cloud or Wasabi.

  • Immutable copies

    On object storage with immutability enabled, backed-up data cannot be changed or deleted inside the immutability period. The incident cannot rewrite the copy you will restore from.

  • Restore down to the item

    Veeam Explorers bring back a single mail, file or Teams message, and the Restore Portal lets people recover their own data without a ticket.

The questions that come with a restore

The data is back. Now who could reach it, and who did?

A restore closes one question and opens three. The finance library is back to Tuesday - but which accounts could open it on Tuesday? Was the anyone link that exposed it still live? And was the account that encrypted it reading four times its usual volume the week before, and would anyone have noticed?

A backup is a copy of content. It is very good at bringing content back. The access side of the incident - who could reach what, since when, and what they actually did - lives in permissions and activity, not in the copy, and it is exactly what a regulator, an insurer or your own post-incident review will ask for.

1Security keeps that side of the story: the live permission graph of every user, guest, app and AI agent and what each can open, plus up to three years of attributed activity. When the data comes back, the answers come with it.

What 1Security adds

The access record next to the backup.

Every identity in Microsoft 365, what it could reach, and what it actually did - three years back, one click from any restore decision.

  1. 01

    Know who could reach the restored data

    Open the restored site or mailbox in 1Security and see every account, guest, app and agent that could open it - through direct grants, sharing links, nested groups and inheritance. In a typical tenant an ordinary account reaches hundreds of thousands of files; this is where you find out which ones.

  2. 02

    Read the week before

    Activity logs for the affected account, filtered to the days before the incident: files opened, downloaded, shared, from which device and city, with the account's own baseline next to it. "340 downloads on Monday against a usual 12" is a lookup, not an investigation.

  3. 03

    Restore what matters first

    Sort the affected sites by sensitive files and by how many people can reach them. Restore order stops being alphabetical and starts being risk-based - the payroll site before the archive nobody has opened in a year.

  4. 04

    Close what let it happen

    Expire the anyone links, remove the guest, revoke the sessions, disable the account - staged behind a 72-hour review window with owner review, and every action logged in one place for the report.

How the two fit together

One keeps the copy. The other keeps the access record.

Veeam keeps the immutable copy of Exchange, SharePoint, OneDrive and Teams on storage you control and restores it down to the item. 1Security connects to the same tenant with read-only consent - no agents, standard Microsoft 365 licenses, first findings the same day - and keeps the permission graph of who can reach what plus three years of who actually did. When an incident hits, Veeam restores the data while 1Security scopes what was reachable, shows what happened before, and stages the fixes - revoked access, expired links, disabled accounts - each behind a human decision.

DORA in practice

Recovery and incident record, side by side.

DORA asks financial entities for two things at once. Articles 11 and 12 cover response and recovery: backup policies, restoration procedures, the ability to bring the entity back. Article 17 covers the incident record: detect, log and classify every ICT-related incident, with the facts to back the classification.

Veeam is the recovery half: immutable backups of Exchange, SharePoint, OneDrive and Teams, restorable down to the item. 1Security is the record half for Microsoft 365: baselines that flag the unusual account, a permission graph that scopes the incident in minutes, and three years of activity to classify it against.

One regulation, two obligations, and a supervisor who can be shown both the restore and the record from the same afternoon.

Bring the data back. Bring the answers with it.

Keep the immutable copy with Veeam. Connect 1Security read-only and see who could reach that data, who did, and what to close - the same day.

Or explain the incident from the backup alone.