Computer-implemented system for restoring data in the event of a computer network failure

The system addresses data recovery challenges by creating a secure, isolated digital workspace using a fallback tenant and emergency switch, ensuring rapid and secure data restoration during network failures, thereby minimizing operational disruptions.

DE202023003000U1Active Publication Date: 2025-07-03PANIK BUTTON HLDG BV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE202023003000
Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2023-11-01
Publication Date
2025-07-03
Estimated Expiration
2033-11-30

AI Technical Summary

Technical Problem

Existing systems are ineffective in quickly and securely restoring data in the event of a computer network failure, such as a ransomware attack or power outage, leading to significant financial and operational disruptions due to the lack of robust backup and recovery mechanisms.

Method used

A computer-implemented system comprising a fallback tenant with backup servers, a sandbox environment, and an emergency switch that allows for the rapid establishment of a separate and secure digital workspace based on predefined backup data, isolated from the compromised network, enabling quick access to essential data and operations.

Benefits of technology

Enables rapid resumption of business operations with minimal disruption by providing a secure, isolated digital workspace that prevents lateral movement of infections and ensures quick data recovery, reducing downtime to hours compared to weeks in traditional recovery processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A computer-implemented system for recovering data in the event of a computer network failure, comprising: - at least one customer computer network, the computer network comprising at least one data server and at least one client device configured to connect to the data server, - at least one fallback tenant associated with the customer, comprising: ◯ at least one backup server configured to store, in at least one secure data container, predefined backup data initially stored on the data server, and ◯ at least one non-transitory computer-readable program storage device that stores workspace installation instructions that, when executed, cause at least one processor to automatically build a new digital workspace for the customer based on and / or providing access to at least part of the backup data stored on the backup server, - at least one sandbox environment located between the customer's computer network and the fallback tenant for examining the security of backup data and transferring security-assured backup data to at least one fallback tenant for storing the security-assured backup data on at least one backup server of the at least one fallback tenant, and - at least one emergency switch, controllable by the customer and / or the customer's computer network, in particular in the event of a customer's computer network failure and / or in the event of a customer's data server failure, configured to execute the workspace installation instructions of the customer's at least one fallback tenant, which cause the at least one processor of the fallback tenant to automatically build a customer-accessible new digital workspace based on at least part of the backup data stored on the backup server and / or granting customers access to it, wherein the new digital workspace is separate and independent of the customer's at least one computer network.
Need to check novelty before this filing date? Find Prior Art

Description

The invention relates to a computer-implemented system for recovering data in the event of a computer network failure, for example in the event of a ransomware attack and / or a power failure. Also disclosed is a computer-implemented method for restoring data in the event of a computer network failure, preferably using the computer-implemented system according to the invention. The invention further relates to a non-transitory computer readable program storage device comprising computer readable instructions executable by one or more processors for performing the computer implemented method.One type of malicious software (malware) that today concerns computers is known as ransomware. This type of software, if access to a computer system is granted, may apply encryption to the contents of a data server (possibly including network files). Once encrypted, the original data may no longer be accessible by its legal user. As such, a system user(s) that lacks decryption code / s) will no longer be able to readily access his or her data. Once the original data has been encrypted and the unencrypted version deleted, a system user may be contacted with a request from a malicious party who has violated system security with ransomware. Often, the malicious party requests that the user pay an amount in cryptocurrency, such as Bitcoins, to have the user's files decrypted so that they are accessible again. Typically, if the user does not pay, then the files may remain encrypted and inaccessible. Unless the user has a good backup system, large amounts of data may be lost, often resulting in significant financial damage, commercial damage, call damage, and a disruption in business continuity. In addition, even if a backup system is present, data may still be lost because files encrypted by ransomware may be automatically backed up in encrypted form. Depending on data retention schemes, a backup of unaffected clean data may even be overwritten by ransomware-encrypted data. Thus, consumers and small companies can be met particularly strongly by ransomware, as these entities often do not have good data backup policies. Even if backup data exists, replacing the entire contents of a hard disk or other storage device may be a slow process. For a company, replacing lost data from the backup in the event that the backup is not involved and, where possible under the given circumstances (which is not always the case), may also mean to adjust or reduce actions while the data is being restored. Therefore, unexamined ransomware has a great potential to be destructive and to degrade system operating time and productivity. Detecting ransomware activities at an early stage, however, may allow their effects to be attenuated or prevented. Unfortunately, most users today are still vulnerable to ransomware attacks.It is a first object of the invention to provide an improved computer implemented system for recovering data in the event of a computer network failure, such as a ransomware attack or power failure.It is a second object of the invention to provide an improved computer-implemented system for relatively quickly recovering data in the event of a computer network failure, such as a ransomware attack or power failure.It is a third object of the invention to provide an improved computer-implemented system for relatively quickly recovering data in the event of a data server failure due to a ransomware attack.It is a fourth object of the invention to provide an improved computer implemented system for relatively quickly and securely recovering data in the event of a computer network failure, such as a ransomware attack or power failure.At least one of these objects can be achieved by providing a computer-implemented system according to the invention comprising:at least one computer network of a client, the computer network comprising at least one data server and at least one client device configured to connect to the data server,at least one fallback tenant associated with the customer comprising:◯ at least one backup server configured to store in at least one secure data container predefined backup data initially stored on the data server,◯ preferably at least one processor, and◯ at least one non-transitory computer readable program storage device storing operating environment installation instructions which, when executed, cause at least one processor, preferably of the fallback tenant and / or at least one, preferably authorized, external processor, to automatically build a new digital operating environment for the client based on and / or granting access to at least a portion of the backup data stored on the backup server,preferably at least one sandbox environment located between the customer's computer network and the fallback tenant for examining the security of backup data and for transmitting security-acknowledged backup data to at least one fallback tenant for storing the security-acknowledged backup data on at least one backup server of the at least one fallback tenant, andat least one emergency switch controllable by the customer and / or the computer network of the customer, in particular in the event of a computer network failure of the customer and / or in the event of a data server failure of the customer, configured to execute the working environment installation instructions of the at least one fallback tenant of the customer, which cause the at least one processor of the fallback tenant to automatically build a new customer-accessible digital working environment based on and / or granting access to at least a part of the backup data stored on the backup server.The computer-implemented system according to the invention uses a non-functional backup server containing all (predefined) data needed to build after switching or activating the emergency switch, typically in the event of an emergency of a new digital working environment for the client. Therefore, switching or activating the emergency switch represents a prerequisite for creating, creating or building the new digital working environment. This causality leads to several advantages, as described below. The new digital working environment may be a fully functional environment, but also a simple working environment with simple functionality for continuing business at a simple level, while preferably re-creating a fully functional environment in the background. A simple working environment can also be built with (very) simple, predefined backup data, such as backup data relating to user profiles or even without predefined backup data. Because the new digital operating environment does not exist before switching the emergency switch and is therefore non-functional and non-accessible, malicious parties cannot access this new digital operating environment and cannot encrypt it. Moreover, the new digital work environment may be separate and / or independent from the customer's computer network and / or positioned at a digital distance, i.e., spaced from the customer's computer network, and is preferred. In other words, the new digital working environment is preferably isolated from the customer's computer network. The new digital work environment may be located on a separate and / or independent network infrastructure with respect to the network infrastructure of the customer's computer network. For example, at least a portion of the new digital operating environment may be located on and / or supported by a cloud-based infrastructure. At least a portion of the cloud-based infrastructure may be non-existent until the instant the emergency switch is activated. It is conceivable that the cloud-based infrastructure is generated substantially completely from reason to after switching the emergency switch, in particular at least partially driven by computer-executable instructions (computer code). This may result in a minimization of the risk, in particular preventing lateral network movement of the customer's computer network to the new digital working environment. Lateral movement is the process by which attackers propagate from an entry point in or on the customer's computer (network) to the rest of the network. This preferably prevents the new digital working environment from being compromised and ensures that this new digital working environment is clean and remains in the event of a ransomware attack or other permanent failure. In particular, in case the new digital working environment is not a complete copy or replica of the computer network of the customer, but rather a possibly slender (lean), preferably separated and distanced new digital working environment, undesired lateral movement can be prevented. Since all data stored on backup server(s) are checked and secured in a sandbox environment, the data stored on backup server(s) is clean and not compromised. It is conceivable that not all data of a computer network of a customer, but rather predefined backup data, are stored on at least one backup server of the fallback tenant. At least a portion of the predefined backup data can be stored as a flat file on at least one backup server of the fallback tenant. This may reduce the risk of lateral movement. Not only the storing of flat files, but storing of flat files can prevent infected data sets from being processed that can cause an infection of the new customer's computer network. It is also conceivable that data records are stored on at least one backup server of the fallback tenant, wherein the data records are made flat before providing access to the predefined backup data. By storing all predefined data in such a way that the new working environment can be created and set up relatively quickly (e.g. within 1 hour), the business interruption for the customer can be kept to a negligible minimum.Thus, the new working environment allows the customer to relatively quickly continue at least a portion of the business activities on the new digital working environment in the event of a computer network failure, for example, due to a cyber attack. The-typically temporary-new working environment grants the customer (again) access to at least part of his data, but can also be configured as a communication platform and / or collaboration platform. In the case of a ransomware attack or other permanent failure, the impaired data server(s) is / are preferably cleaned and / or replaced to restore the original, fully operational working environment, which may last several weeks, typically 10 to 12 weeks.According to a preferred embodiment of the present invention, the customer's computer network has substantially no rights to access and / or modify and / or create data within the new digital work environment. As such, the new digital working environment is built and operated completely separately from the customer's computer network. The new digital working environment can be built completely independently and separately from the (already infected) computer network of the customer. This provides the enormous advantage that lateral movements can be eliminated. As briefly indicated above, lateral movement can be understood as the method typically used by cybercriminers to explore and / or infect a computer network to find vulnerabilities. Thus, if the new digital work environment would exist at the time the customer's computer network is infected, the new digital work environment has a high probability of also being infected. The latter risks also occur if the customer's computer network has access to the new digital working environment in some way. Lateral movement can also be understood as infected software and / or data which are moved from the infected network / infrastructure / s to an uninfected network. The present invention therefore provides a solution which allows this to be prevented. The customer's computer network according to the present invention is therefore preferably not involved in creating the new digital working environment. Preferably, the new digital work environment is based on a different and independent infrastructure compared to the customer's computer network. Thus, the new digital working environment is preferably not a (complete) replica or a (complete) copy of the customer's computer network, but instead a separate and independent new digital working environment in response to activation of the emergency switch. The new digital work environment provides a customer with the ability to continue simple business operation while the customer's computer network is compromised. To continue (some) business activities, the new working environment is not required to include any software applications or virtual machines. However, the new digital operating environment may include at least one software application or at least one virtual machine for providing further functionalities to the new digital operating environment. In this manner, the present invention is capable of providing significant improvement in cybersecure in terms of business continuity during a cyber attack. In particular, since the new digital working environment was not existent, there is no possibility that the cyber crimulator has already infected the new digital working environment. Not only this, but since it is completely independent and separate from the customer's computer network, the new digital working environment can provide a secure operating platform for continuing (at least simple) business operation. The new digital working environment may be initially built substantially without any data from the customer's computer network. The new digital working environment may be accessible to the customer and may also be used by the customer as a (temporary) substitute for the computer network of his customers. In this way, business continuity can be ensured. Thus, the new digital working environment is not a new instance of an application running on the customer's computer network, but is actually a fully newly created working environment that is not associated with the customer's computer network and that is usable by the customer, and wherein the creation of the new working environment is triggered by the switching of the emergency switch. It may be preferred that the new digital working environment constitutes a single independent working environment.The customer's computer network may include one or more data servers and one or more client devices, such as computers (PCs), tablets, smart phones, etc. Each client device is preferably configured to connect to one or more of the data servers. This customer's computer network is typically connected to the Internet and may be at least partially cloud-based. The customer's computer network is normally protected by a firewall forming part of the computer network. The customer's computer network is preferably (completely) isolated from the fallback tenant. However, the fallback tenant is periodically, e.g. daily, filled and updated with new predefined data originating from at least one data server of the customer's computer network and studied and acknowledged by the sandbox environment. Thus, the sandbox environment is normally located between the customer's computer network and the fallback tenant. The sandbox environment, also referred to as clean room, may be a cloud-based environment and / or typically uses one or more virtual servers to test data in an isolated environment. In the sandbox environment, all incoming data is sandboxed, which means that the security of the data is examined in an isolated environment. Thus, the sandbox environment represents a secure and isolated environment that is decoupled from the surrounding infrastructure and operating system and therefore decoupled from the customer's computer network as well as from the fallback tenant, with the aim of testing data, in particular testing code and analyzing malware. It aims to prevent a potential threat from invading the fallback tenant and is commonly used to examine unknown or non-secure code. Sandboxing limits the script to a test environment and prevents it from infecting or damaging the host device or operating system. As the name implies, this limited test environment acts as what is a "sandbox" in which one can experiment with various variables to see how the system is operating. It is also a secure environment where everything going skew may not damage directly to the host machines of the customer's computer network and / or the fallback tenant(s).The customer is typically a company, but may also be a private person. The customer is called a customer because the customer normally buys, leases, uses and / or subscribes to the fallback tenant and / or an associated service offered by a normally external service provider. Depending on the situation, the customer may also be referred to as an enterprise entity, an enterprise, an enterprise party, a legal person, a natural person, and / or a private person.The fallback tenant is considered a restricted environment associated with the customer and preferably only with that customer. The backup server of the fallback tenant may also be referred to as a single-tenant backup server. Thus, preferably each customer has its own or multiple backup servers. The backup server may be a physical server and / or virtual server. It is envisioned that the hardware components of the tenant environment include components such as processors and storage media including physical servers that are simultaneously used to operate a plurality of tenants each associated with a plurality of the clients. Each fallback tenant may comprise one or more processors and / or may be configured to cooperate and / or communicate with at least one external processor, in particular at least one authorized external processor.Preferably, the system, more preferably the customer's computer network, comprises at least one processor and at least one non-transitory computer readable program storage device storing predefined backup data instructions associated with backup data to be stored on at least one backup server of at least one customer's fallback tenant, which, when executed, cause the at least one processor to copy and transmit at least a portion of the predefined backup data to / to the at least one sandbox environment. The at least one non-transitory computer readable program storage device storing predefined backup data instructions may also be stored at a location a distance from the customer's computer network and may be accessible, for example, by one or more authorized users and / or consultants of the customer, preferably using one or more, optionally authorized, client devices. Preferably, the backup data instructions are stored on a preparation server that is separated from the data server. The preparation server is considered as an example of a non-transitory computer readable program storage device. The preparation server may be an on-site server or a cloud-based server. The preparation server may be a physical server or a virtual server. Preferably, at least one client device and / or at least one user of the customer's computer network has controlled access to at least a portion of the preparation server, preferably based on a prior user authentication, which may be multi-factor authentication.It is conceivable that at least a part of the new working environment is already installed on the backup server without the emergency switch(s) having been switched. In this latter case, the pre-installed working environment is preferably a non-functional and / or non-accessible working environment in order to shield this working environment as robust as possible from unauthorized persons. The predefined backup data and / or backup data stored on at least one backup server preferably comprise data for setting up and / or installing at least one operating system (OS) and / or at least one virtual machine (VM) that emulates at least one operating system. In the new working environment to be built, such an operating system as Microsoft Windows, Apple macOS, Google's Android OS et cetera is usually required to access other data such as applications and user files. Preferably, the predefined backup data and / or the backup data stored on at least one backup server comprise data for constructing and / or installing at least one user application, as well as, for example, word processing software, a spreadsheet, a presentation program, a personal information manager, a personal task manager, a personal contact manager, an email client, at least one web browser and / or anti-malware software.Preferably, the predefined backup data and / or backup data stored on at least one backup server comprises user files. The user files may be stored in a predefined folder structure, which may correspond to a folder structure used on the original data server of the customer's computer network. Individual user files may be assigned access rights. These file-related permissions may also match the permissions specified for the original files stored on the client's computer network data server(s).In a preferred embodiment, the client computer network comprises a plurality of client devices, wherein the predefined backup data and / or backup data stored on at least one backup server comprises access-related client device data that determines access rights of the plurality of client devices for accessing the new digital working environment once established. This access-related client device data results in a client device level authorisation structure. This allows specific client devices (or device types) to grant or deny specific access rights to specific files, folders or servers.Preferably, one or more of the aforementioned permissions may be adjusted and / or specified by one or more authorized users of the customer's computing environment.Preferably, the client computer network comprises a plurality of client devices associated with different users of the computer network, wherein the predefined backup data and / or the backup data stored on at least one backup server comprises data for creating at least one digital communication space that allows at least two of the different users to digitally communicate with each other. At least one of these rooms can be configured as a (crisis) war room, wherein preferably only selected key persons of the customer can be granted access to this war room. This facilitates the quick communication between the key persons to resolve an actual crisis as efficiently as possible.Preferably, the predefined backup data and / or the backup data stored on at least one backup server comprises data for creating at least one fallback website associated with the customer.It is conceivable that the predefined backup data and / or the backup data stored on at least one backup server comprise data associated with at least one user profile of the customer's computer network. In particular, data associated with at least one user profile that requires access to the new digital operating environment.The predefined backup data and / or the backup data stored on at least one backup server preferably comprise data comprising the working environment installation instructions. In this case, the backup server is considered a non-transitory computer readable storage device.In order to save storage space and costs, at least a portion of the backup data is preferably stored in a compressed form. Preferably, at least a portion of the backup data is stored in encrypted form. Preferably, all backup data sent from the customer's computer network to the fallback tenant(s) via the sandbox environment is transported in an encrypted form. This results in an additional level of protection that makes it more difficult for unauthorized malicious persons (to intercept and abuse) data. It is conceivable that the backup data sent from the customer's computer network, optionally via the sandbox environment, to the new customer's computer network is transported at least partially via a data pipeline. The data pipeline is preferably set up only after switching the emergency switch. This data pipeline is preferably free of any network capabilities. This can prevent any malicious person, such as a cybercrimulator, from infecting the network pipeline for the required data. It is conceivable that the predefined backup data comprise flat files, preferably essentially exclusively flat files. This can significantly reduce the chances of infected code or records being placed on the new customer's computer network. Copying of entire data sets entails a significant risk for lateral movement, which should therefore preferably be avoided as far as possible.At least a portion of the at least one emergency switch is a physical switch, in particular a physical button that can be pressed, for switching or activating the switch. Additionally or alternatively, at least a portion of the at least one emergency switch may be a virtual switch. The virtual switch may be switched by the customer and / or the computer network of the customer and / or an authorized external service provider, optionally upon request of the customer.Preferably, switching the switch to activate the fallback tenant to establish the new working environment, and possibly to be disconnected from the current data server(s) and / or from the sandbox environment, is subject to a specific protocol to prevent inadvertent and / or unintentional switching of the switch. Such a protocol may be based on, for example, a multi-level protocol, wherein each level should optionally be executed in a predefined order before the switch is actually switched. A preferred protocol in this case may be a so-called "break glass" protocol which requires a combination of at least two access tokens and / or at least two operators to break the glass and switch the switch, speaking pictorially. Here, for example, a key for switching an emergency switch may be made of two parts. One key part is used by the customer and the other key part can be stored, for example, in a secure storage container to which the customer and / or the computer network of the customer and / or an authorized service provider has access or can receive access. Preferably, the system comprises at least one first digital break glass access token stored in at least one break glass file, preferably in a customer's computer network, and required for switching the emergency switch. Preferably, the system comprises at least one first digital break glass access token stored in at least one break glass file, preferably in a customer's computer network, and required for switching the emergency switch. At least one, preferably each emergency switch is programmed to be switched when subjected to at least two predefined activation steps. Preferably, at least one predefined activation step is defined by exposing the switch to at least one first digital break glass access token. Preferably, at least one predefined activation step is defined by receiving at least one second digital break glass access token that is stored and / or held by the customer, preferably at a distance from a first digital break glass access token and that is required to activate the switch. It is additionally or alternatively also conceivable that at least one predefined activation step is defined by physically switching the physical switch (if applied) by at least one user, preferably at least one authorized user.In addition or alternatively to the above embodiment, wherein the fallback tenant(s) can / can be activated by manually and / or automatically switching at least one emergency switch, it is conceivable that the fallback tenant(s) can / can be activated and / or opened, optionally without using the switch, by executing an emergency protocol and / or a "break glass protocol" (other) that requires a plurality of operations and / or tokens to force access to and / or activation of the fallback tenant. These operations may require action from a plurality of persons. Generally, the tokens may be stored and / or generated at different locations and / or may be controlled by different persons, for example both by the customer and by at least one authorised service provider.It is conceivable that at least one secure data container of at least one backup server is initially digitally closed and can only be accessed by switching at least one emergency switch. Such a closure can be formed, for example, by a firewall which shields the backup server / servers.The computer-implemented system according to the invention is primarily directed to fast and secure data recovery in the event of failure and / or inextension of the data server(s) (or one or more other critical parts of the customer's computer network), for example due to a ransomware attack. In this case, it is preferred that the computer network of the customer and / or at least one emergency switch is programmed to disconnect the data server(s) and / or from the sandbox environment, after switching at least one emergency switch to activate the fallback tenant to establish the new working environment. However, in the event of a rather non-dangerous failure, such as a power failure, such a data server decoupling may be omitted. It is conceivable that the system comprises at least one switch for use in case of a ransomware attack and at least one other switch for use in a rather harmless failure, such as a power failure. It is also conceivable that different protocols may be applied to the same switch, wherein a ransomware attack protocol results in the disconnection of the data server(s) and / or from the sandbox environment, while a rather general emergency protocol does not result in the disconnection of the data server(s) and / or from the sandbox environment.Preferably, the system, in particular the computer network of the customer, is programmed to issue at least one warning message to users of the computer network of the customer and / or to at least one predefined external party, such as an (authorized) service provider, as soon as the emergency switch is switched. Typically, this encourage the involved persons and parties to take adequate actions as soon as possible, with respect to partial data recovery, full environmental recovery, business continuity, risk reduction, etc.In a preferred embodiment, the system, in particular the computer network of the customer, comprises at least one current security information and event management (SIEM) service and / or at least one current security operation centre (SOC) service for observing unusual network activity on and / or in the periphery of the computer network of the customer and / or within the newly created working environment (built after activation of the fallback tenant). The SIEM service and / or SOC service may be installed on or within the customer's computer network and / or the newly created work environment. Additionally or alternatively, the SIEM service and / or SOC service may be an external (externally hosted) service, for example hosted by an authorized service provider, wherein the external service(s) is / are configured to observe the computer network of the customer and / or the re-created environment (once created). Preferably, at least one SIEM service and / or at least one SOC service is / are configured to detect and stop insider cyber security threats, preferably one or more threats selected from the group consisting of: compromised user login information, anomalous privilege extension, malware, compromised user accounts, and encryption of large amounts of data by ransomware. Preferably, at least one SIEM service and / or at least one SOC service is / are configured to issue a warning message to at least one predefined user of the customer's computer network and / or to at least one external party in the event of a detected cyber security threat. Preferably, at least one SIEM service and / or at least one SOC service is / are configured to generate and / or issue at least a portion of an access token required for switching at least one emergency switch.Security Information and Event Management (SIEM) is a general purpose security management protocol that combines security information management (SIM) and security event management (SEM). SIEM uses both historical and real-time correlation software to track security data logs, allowing the customer and / or the customer's computer network to remedy errors in historical threats and also to identify new security issues as they occur. Typically, data logs document any unusual activity occurring in a network. Since all network activity is normally collected in the data log, it is one of the most effective tools for detecting threats that it might have created to creep through the conventionally used defense lines. SIEM SOCs are often grouped together. While SIEM is a type of technology that allows security analyzers to discover suspect threats and respond to suspect threats, an SOC includes not only the technology, but also the users and processes involved in observing the customer's computer network, searching for threats, and responding to incidents. As indicated above, in case of the SIEM and / or SOC detecting unusual behaviour, which preferably exceeds a predefined threshold deviation, an access token may be generated and / or issued, which as such may activate (switch) an emergency switch and / or which may be combined with at least one other access token or activation step to activate (switch) an emergency switch.It is conceivable that, in addition or alternatively to the embodiments presented above, at least one emergency switch is programmed to be controlled by an external party, such as an authorized service provider, preferably after an authenticated request of the customer.Disclosed is further a computer implemented method for recovering data in the event of a computer network failure, preferably using a system according to the present invention, comprising the steps of: A) pre-defining backup data of data stored on at least one data server of a computer network of a customer, B) optionally examining the security of the predefined backup data in a sandbox environment, C) copying the predefined backup data, which is preferably examined and security confirmed in step B), to at least one backup server of at least one fallback tenant, D) providing at least one emergency switch, E) allowing, preferably conditioned, the customer and / or the computer network of the customer to switch at least one emergency switch, F) Following switching of at least one emergency switch, executing operating environment installation instructions stored on at least one non-transitory computer readable program storage device of the fallback tenant to cause at least one processor of the fallback tenant to automatically establish a new digital operating environment for the customer, preferably based at least in part on the predefined backup data stored on at least one backup server, wherein the new digital operating environment is preferably established separately and preferably independently of the computer network of the customer, and G) provides the customer access to the new digital operating environment, preferably one or more client devices of the customer.Advantages and embodiments of the computer-implemented method have already been described above in a detailed form. Further embodiments are presented below. It is conceivable that the method may be performed without applying steps A), B) and C).Preferably, during step A), predefined backup data instructions associated with backup data to be stored on at least one backup server of at least one customer's fallback tenant are stored on at least one non-transitory computer readable program storage device, preferably the customer's computer network, which, when executed, cause the at least one processor to copy and transmit at least a portion of the predefined backup to the at least one sandbox environment. More preferably, during step A), the backup data instructions are stored on a preparation server that is separate from the data server. Preferably, during step A), at least one client device and / or at least one user of the customer's computer network has controlled access to at least a portion of the preparation server, preferably based on a prior user authentication.Preferably, the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises data for establishing and / or installing at least one operating system (OS) and / or at least one virtual machine (VM) that emulates at least one operating system. Preferably, the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises data for constructing and / or installing at least one user application, such as word processing software, spreadsheet, presentation program, personal information manager, personal task manager, personal contact manager, email client, at least one web browser, and / or anti-malware software. Preferably, the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprise user files.Preferably, the client computer network comprises a plurality of client devices, wherein the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises access-related client device data that determines access rights of the plurality of client devices for accessing the new digital working environment once established. Preferably, the client computer network comprises a plurality of client devices associated with different users of the computer network, wherein the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises data for creating at least one digital communication space that allows at least two of the different users to digitally communicate with each other. Preferably, the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises data for creating a fallback website associated with the customer.In a preferred embodiment, during step C), at least a portion of the backup data is stored in a compressed and / or encrypted form.Preferably, at least a part of the at least one emergency switch provided during step D) is a physical switch, in particular a physical button, and / or wherein at least a part of the at least one emergency switch provided during step D) is a virtual switch.The system preferably comprises at least one first digital break glass access token stored in at least one break glass file and / or break glass database, preferably in a customer's computer network, and required for switching the emergency switch during step E).During step E), preferably at least one, and preferably each, emergency switch is programmed to be switched when subjected to at least two predefined activation steps. More preferably, at least one predefined activation step is defined by exposing the switch to at least one first digital break glass access token.Preferably, at least one predefined activation step is defined by receiving at least one second digital break glass access token that is stored and / or held by the customer, preferably at a distance from a first digital break glass access token and that is required to activate the switch. Preferably, at least one predefined activation step is defined by physically switching the switch by at least one user, preferably by at least one authorized user. Preferably, at least one secure data container of at least one backup server is initially digitally locked, preferably during step C), and is only accessible by switching at least one emergency switch during step E).In a preferred embodiment of the computer-implemented method, switching the emergency switch during step E) is at least partially triggered by observed unusual behavior of and / or on the data server, such as a ransomware attack on the data server and / or a power failure of the data server.Preferably during or after step E), one or more client devices of the customer are disconnected from the data server, in particular in case of detecting a ransomware attack, and / or watching by the customer and / or the computer network of the customer and / or an authorized service provider.Preferably, the customer's computer network is programmed to issue, during and / or after step E), at least one alert to users of the customer's computer network and / or to at least one predefined external party once the emergency switch is switched.In a preferred embodiment, the method comprises step H) comprising detecting insider cyber security threats and / or unusual network activity on the computer network of the customer, in particular on and / or from the data servers, by means of at least one security information and event management (SIEM) service and / or at least one security operation centre (SOC) service, preferably running on the computer network of the customer and / or hosted, for example, by an authorized service provider, wherein preferably one or more observed threats is / are selected from the group consisting of: compromised user login information, abnormal privilege extension, malware, Compromised User Accounts and Encryption of Large Amounts of Data by Ransomware. Preferably, during step H), at least one SIEM service and / or at least one SOC service issue an alert message to at least one predefined user of the customer's computer network and / or to at least one external party in the event of a detected cyber security threat. Preferably, during step H), at least one SIEM service and / or at least one SOC service generates and / or issues at least a portion of an access token required to switch at least one emergency switch in step E).The invention further relates to a non-transitory computer readable program storage device (NPSD) comprising computer readable instructions executable by one or more processors for performing the computer implemented method and / or for use in the computer implemented system according to the invention. The NPSD may include magnetic disks (fixed, floppy, and removable) and tapes, optical media such as CD-ROMs and digital video disks (DVDs), and semiconductor memory devices such as electrically programmable read-only memory (EPROM) and electrically erasable programmable read-only memory (EEPROM). Memory and storage may be used to secure instructions or code of computer programs organized into one or more modules and written in any computer programming language. When executed by a processor, such computer program code may implement one or more of the methods or processes described herein. A power source of the NPSD may comprise a rechargeable battery (e.g., a lithium-ion battery or the like) or other electrical connection to a power supply, e.g., a mains power source, used to manage and / or provide electrical power to the electronic components and associated circuitry of the electronic device.The invention is further illustrated by means of the following non-limiting clause. 1. a computer-implemented system for recovering data in the event of a computer network failure, comprising:at least one computer network of a client, the computer network comprising at least one data server and at least one client device configured to connect to the data server,at least one fallback tenant associated with the customer comprising:◯ at least one backup server configured to store in at least one secure data container predefined backup data initially stored on the data server,◯ preferably at least one processor, and◯ at least one non-transitory computer readable program storage device storing operating environment installation instructions which, when executed, cause at least one processor, preferably the fallback tenant, to automatically establish a new digital operating environment for the customer based on and / or granting access to at least a portion of the backup data stored on the backup server,at least one sandbox environment located between the customer's computer network and the fallback tenant for examining the security of backup data and for transmitting security-acknowledged backup data to at least one fallback tenant for storing the security-acknowledged backup data on at least one backup server of the at least one fallback tenant, andat least one emergency switch, controllable by the customer and / or the computer network of the customer, in particular in the event of a computer network failure of the customer and / or in the event of a data server failure of the customer, configured to execute the working environment installation instructions of the at least one fallback tenant of the customer, which cause the at least one processor of the fallback tenant to automatically build a new customer-accessible digital working environment, which is based on and / or grants access to at least a part of the backup data stored on the backup server, wherein preferably the new digital working environment is separated and / or independent of the at least one computer network of the customer.2. The computer-implemented system of clause 1, wherein the customer's computer network comprises at least one processor and at least one non-transitory computer-readable program storage device storing predefined backup data instructions associated with backup data to be stored on at least one backup server of at least one customer's fallback tenant, which, when executed, cause the at least one processor to copy and transmit at least a portion of the predefined backup data to the at least one sandbox environment. 3. the computer-implemented system of clause 2, wherein the backup data instructions are stored on a preparation server that is separate from the data server. 4. the computer-implemented system of clause 3, wherein at least one client device and / or at least one user of the client's computer network has controlled access to at least a portion of the preparation server, preferably based on a prior user authentication. 5. the computer-implemented system of any of the preceding clause, wherein the predefined backup data and / or the predefined backup data stored on at least one backup server comprises data for establishing and / or installing at least one operating system (OS) and / or at least one virtual machine (VM) that emulates at least one operating system. 6.The computer-implemented system according to any of the preceding clause, wherein the predefined backup data and / or the backup data stored on at least one backup server comprises data for building and / or installing at least one user application, such as word processing software, spreadsheet, presentation program, personal information manager, personal task manager, personal contact manager, e-mail client, at least one web browser and / or anti-malware software. 7. the computer-implemented system of any of the preceding clause, wherein the predefined backup data and / or the predefined backup data stored on at least one backup server comprises user files. 8 The computer-implemented system of any preceding clause, wherein the customer's computer network comprises a plurality of client devices, wherein the predefined backup data and / or the predefined backup data stored on at least one backup server comprises access-related client device data that determines access rights of the plurality of client devices to access the new digital operating environment once established. 9. the computer-implemented system of any of the preceding clause, wherein the customer's computer network comprises a plurality of client devices associated with different users of the computer network, wherein the predefined backup data and / or the backup data stored on at least one backup server comprises data for creating at least one digital communication space that allows at least two of the different users to digitally communicate with each other. 10. the computer-implemented system of any preceding clause, wherein the predefined backup data and / or the backup data stored on at least one backup server comprises data for creating a fallback website associated with the customer. 11 The computer-implemented system of any preceding clause, wherein the predefined backup data and / or the backup data stored on at least one backup server comprises data comprising the operating environment installation instructions. 12th The computer-implemented system of any preceding clause, wherein at least a portion of the backup data is stored in a compressed form. 13.The computer-implemented system of any preceding clause, wherein at least a portion of the backup data is stored in an encrypted form. 14. computer-implemented system according to any of the preceding clause, wherein at least a portion of the at least one emergency switch is a physical switch, in particular a physical button. 15. The computer-implemented system of any of the preceding clause, wherein at least a portion of the at least one emergency switch is a virtual switch. 16.The computer-implemented system according to any of the preceding clause, wherein the system comprises at least one first digital break glass access token stored in at least one break glass file, preferably in a customer's computer network, and required for switching the emergency switch. 17. computer-implemented system according to any of the preceding clause, wherein at least one, preferably each, emergency switch is programmed to be switched when subjected to at least two predefined activation steps. 18. The computer-implemented system of clause 16 or 17, wherein at least one predefined activation step is defined by exposing the switch to at least one first digital break glass access token. 19.The computer-implemented system of clause 17 or 18, wherein at least one predefined activation step is defined by receiving at least one second digital break-glass access token that is stored and / or held by the customer, preferably at a distance from a first digital break-glass access token and that is required to activate the switch. 20.The computer-implemented system of any of clause 17-19, wherein at least one predefined activation step is defined by physically switching the physical switch by at least one user, preferably by at least one authorized user. 21st The computer-implemented system according to any of the preceding clause, wherein at least one secure data container of at least one backup server is initially digitally locked and is only accessible, by switching at least one emergency switch. 22.The computer-implemented system of any of the preceding clause, wherein the system, in particular the customer's computer network, is programmed to disconnect the data server and / or the sandbox environment after switching at least one emergency switch. 23.The computer-implemented system according to any of the preceding clause, wherein the system, in particular the computer network of the customer, is programmed to issue at least one warning message to users of the computer network of the customer and / or to at least one predefined external party, once the emergency switch is switched. 24 The computer-implemented system of any of the preceding clause, wherein the system, in particular the computer network of the customer, comprises at least one current security information and event management (SIEM) service and / or at least one current security operation centre (SOC) service for observing unusual network activity. 25.The computer-implemented system of clause 24, wherein at least one SIEM service and / or at least one SOC service is / are configured to detect and stop insider cyber security threats, preferably one or more threats selected from the group consisting of: compromised user login information, anomalous privilege augmentation, malware, compromised user accounts, and encryption of large amounts of data by ransomware. 26. The computer-implemented system of clause 24 or 25, wherein at least one SIEM service and / or at least one SOC service is / are configured to issue a warning message to at least one predefined user of the customer's computer network and / or to at least one external party in the event of a detected cyber security threat. 27. computer-implemented system according to any of clause 24-26, wherein at least one SIEM service and / or at least one SOC service is / are configured to generate and / or issue at least a portion of an access token required to switch at least one emergency switch. 28. computer-implemented system according to any of the preceding clause, wherein at least one emergency switch is programmed to be controlled by an external party, preferably after an authenticated request from the customer. 29. computer-implemented system according to any of the preceding clause, wherein the customer's computer network and the fallback tenant are isolated from each other.Not part of the invention, but helpful to understand it, are the following clause:30. A computer-implemented method for recovering data in the event of a computer network failure, preferably using a system according to any of the preceding clause, comprising the steps of: A) pre-defining backup data of data stored on at least one data server of a computer network of a customer, B) examining the security of the predefined backup data in a sandbox environment, C) copying the predefined backup data examined and security confirmed in step B) to at least one backup server of at least one fallback tenant, D) providing at least one emergency switch, E) allowing, preferably due to the customer and / or the computer network of the customer switching at least one emergency switch, F) Following switching of at least one emergency switch, executing operating environment installation instructions stored on at least one non-transitory computer readable program storage device of the fallback tenant to cause at least one processor of the fallback tenant to automatically establish a new digital operating environment for the customer, preferably based at least in part on the predefined backup data stored on at least one backup server, wherein the new digital operating environment is preferably established separately and independently of the computer network of the customer, and G) permit the customer access to the new digital operating environment, preferably one or more client devices of the customer.31. The computer-implemented method of clause 30, wherein during step A), predefined backup data instructions associated with backup data to be stored on at least one backup server of at least one customer's fallback tenant are stored on at least one non-transitory computer readable program storage device, preferably the customer's computer network, that, when executed, cause the at least one processor to copy and transmit at least a portion of the predefined backup to the at least one sandbox environment.32. The computer-implemented method of clause 31, wherein during step A), the backup data instructions are stored on a preparation server that is separate from the data server.33. The computer-implemented method of clause 32, wherein during step A), at least one client device and / or at least one user of the client's computer network has controlled access to at least a portion of the preparation server, preferably based on prior user authentication.34. The computer-implemented method of any of clause 30-33, wherein the backup data predefined during step A) and / or stored on at least one backup server during step C) comprises data for establishing and / or installing at least one operating system (OS) and / or at least one virtual machine (VM) that emulates at least one operating system.35. The computer-implemented method of any of clause 30-34, wherein the backup data predefined during step A) and / or stored on at least one backup server during step C) comprises data for constructing and / or installing at least one user application, such as word processing software, spreadsheet, presentation program, personal information manager, personal task manager, personal contact manager, email client, at least one web browser, and / or anti-malware software.36. The computer-implemented method of any of clause 30-35, wherein the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises user files.37. The computer-implemented method of any of clause 30-36, wherein the customer's computer network comprises a plurality of client devices, wherein the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises access-related client device data that determines access rights of the plurality of client devices to access the new digital operating environment once established.38. The computer-implemented method of any of clause 30-37, wherein the customer's computer network comprises a plurality of client devices associated with different users of the computer network, wherein the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises data for creating at least one digital communication space that allows at least two of the different users to digitally communicate with each other.39. The computer-implemented method of any of clause 30-38, wherein the backup data predefined during step A) and / or the backup data stored on at least one backup server during step C) comprises data for creating a fallback website associated with the customer.40. The computer-implemented method of any of clause 30-39, wherein during step C) at least a portion of the backup data is stored in a compressed and / or encrypted form.41. The computer-implemented method of any of clause 30-40, wherein at least a portion of the at least one emergency switch provided during step D) is a physical switch, in particular a physical button, and / or wherein at least a portion of the at least one emergency switch provided during step D) is a virtual switch.42. The computer-implemented system according to any of the preceding clause, wherein the system comprises a first digital break glass access token stored in at least one break glass file and / or break glass database, preferably in a customer's computer network, and required for switching the emergency switch during step E) and / or for activating the fallback tenant during step F), wherein step F) optionally takes place without the previous step E) taking place.43. The computer-implemented method of any of clause 30-42, wherein during step E) at least one, preferably each, emergency switch is programmed to be switched and / or wherein during step F) at least one fallback tenant is activated to establish the new working environment when subjected to at least two predefined activation steps.44. The computer-implemented method of clause 42 or 43, wherein at least one predefined activation step is defined by exposing the switch to at least one first digital break glass access token.45. The computer-implemented method of clause 43 or 44, wherein at least one predefined activation step is defined by receiving at least one second digital break-glass access token that is stored and / or held by the customer, preferably at a distance from a first digital break-glass access token and that is required to activate the switch.46. The computer-implemented method according to any of the clause 43-45, at least one predefined activation step is defined by physically switching the physical switch by at least one user, preferably by at least one authorized user.47. The computer-implemented method of any of clause 43-46, wherein at least one secure data container of at least one backup server is initially digitally locked, preferably during step C), and is only accessible by switching at least one emergency switch during step E).48. The computer-implemented method of any of clause 30-47, wherein switching the emergency switch during step E) is at least partially triggered by observing unusual behavior from and / or on the data server, such as a ransomware attack on the data server and / or a power failure of the data server.49. The computer-implemented method of any of clause 30-47, wherein during or after step E), the one or more client devices of the client are disconnected from the data server and / or from the sandbox environment.50. The computer-implemented method of any of clause 30-48, wherein the customer's computer network is programmed to issue, during and / or after step E), at least one alert to users of the customer's computer network and / or to at least one predefined external party once the emergency switch is switched.51. The computer-implemented method according to any of the clause 30-49, wherein the method comprises step H) comprising detecting insider cyber security threats and / or unusual network activity on the customer's computer network, in particular on and / or from the data server, and / or in the newly established working environment according to step F), by means of at least one security information and event management (SIEM) service and / or at least one security operation centre (SOC) service. Preferably running on the customer's computer network, wherein preferably one or more observed threats is / are selected from the group consisting of:The problem is that compromised user login information, anomalous privilege extension, malware, compromised user accounts, and large amount of data are encrypted by ransomware.52. The computer-implemented method of clause 51, wherein during step H) at least one SIEM service and / or at least one SOC service issues a warning message to at least one predefined user of the customer's computer network and / or to at least one external party in the event of a detected cyber security threat.53. The computer-implemented method of any of clause 51-52, wherein during step H) at least one SIEM service and / or at least one SOC service generates and / or issues at least a portion of an access token required to switch at least one emergency switch during step E).54. A non-transitory computer readable program storage device comprising computer readable instructions executable by one or more processors to perform the computer implemented method of any of clause 30-53 and / or for use in a computer implemented system of any of clause 1-29.The invention is further illustrated by several non-limiting embodiments according to the present invention, wherein:FIG. 1 shows a block diagram of an exemplary computer-implemented system according to the present invention;FIG. 2 shows a block diagram of an example of components of an exemplary computer-implemented system according to the present invention; andFIG. 3 shows a block diagram of an example of a computer-implemented method for recovering data.FIG. 1 shows a block diagram of an example of a computer-implemented system 1 according to the present invention. Figure 1 shows a natural situation where a customer 2 has access to the computer network of the customer 3. The customer's computer network 3 may allow the exchange of data between customers. It is also conceivable that the client's computer network 3 allows resources to be shared between connected client devices. The customer's computer network 3 has a data server storing backup data. This backup data is predefined data, such as important business data and / or valuable assets. The backup data is copied from the customer's computer network 3 to a fallback tenant 4. It is conceivable that the backup data is encrypted during transport from the customer's computer network 3 to the fallback tenant 4. a sandbox environment 5 is located between the customer's computer network 3 and the fallback tenant 4. the sandbox environment 5 examines the security of the backup data copied from the customer's computer network 3 to the fallback tenant 4. As a result, the sandbox environment 5 transmits backup security-acknowledged data to the fallback tenant 4. Preferably, the sandbox environment 5 only transmits backup security-acknowledged data to the fallback tenant 4. The fallback tenant 4 comprises a non-functional backup server configured to store the backup security-acknowledged data. The fallback tenant 4 may further comprise at least one processor and / or is configured to cooperate (communicate) with at least one external processor. Preferably, the fallback tenant 4 comprises at least one non-transitory computer readable program storage device, such as a server configured to store operating environment installation instructions. The computer-implemented system 1 further has an emergency switch 6. the emergency switch 6 is controllable by the customer 2 and / or the computer network 3 of the customer. The emergency switch 6 is configured to execute the working environment installation instructions of the program storage device of the fallback tenant 4. This new working environment 8 is based on the backup data received from the backup server of the fallback tenant 4. This means that after switching the emergency switch 6, the non-functional backup server becomes functional in order to supply the fallback tenant 4 with backup data. It is conceivable that this new working environment 8 is set up within one hour. The customer 2 is granted access to the new digital working environment 8 via at least one access token 7.FIG. 2 shows a block diagram of an example of a computer-implemented system 200 for recovering data during a computer network failure. In a natural situation, as described in Figure 1, a customer 202 has access to his computer network 203. The customer's computer network 203 has a data server that stores backup data. The backup data is copied from the customer's computer network 203 to a fallback tenant 204. A sandbox environment 205 is located between the customer's computer network 203 and the fallback tenant 204. The sandbox environment 205 examines the security of the backup data copied from the customer's computer network 203, and transmits security-acknowledged backup data to the fallback tenant 204.The fallback tenant 204 comprises a backup server configured to store the backup security-acknowledged data. The fallback tenant 204 further includes at least one processor and a non-transitory computer readable program storage device configured to store operating environment installation instructions. Figure 2 shows a situation where the customer's computer network 203 is attacked, for example by a ransomware attack 209. As a consequence of this attack, a computer network failure occurs. In response, a protocol may be launched to activate the fallback tenant 204 to establish a new working environment 208. Various options are conceivable to activate the fallback tenant 204. For example, it is conceivable that the fallback tenant 204 is activated by manually and / or automatically switching at least one emergency switch 206. Manual switching of at least one emergency switch 206 may be performed by the customer 202 and / or by an authorized service provider, preferably by an authorized service provider hosting the fallback tenant 204. Switching of the switch 206 may be subject to a so-called "break glass" protocol that requires a plurality of operations and / or tokens to be able to switch the switch 206. Alternatively or additionally, the fallback tenant 204 may also be activated without using the switch and by executing an emergency protocol and / or a break glass protocol (other) that requires a plurality of operations and / or tokens to force access to the fallback tenant. These operations may require action from a plurality of persons. The tokens may be stored and / or generated in different locations and / or may be controlled by different persons, for example both by the client and by at least one authorised service provider. The protocol starts with the activation Ac of the emergency switch 206 by the customer 202. The emergency switch 206 may be manually activated Ac by the customer 202. It is also conceivable that the emergency switch 206 is activated automatically, for example by an SIEM and / or SOC service, which preferably runs on the customer's computer network 203 and / or is hosted by an external service provider, and / or which is activated by observed malicious code in the backup data observed by the sandbox environment 205. The emergency switch 206 may be a physical switch, such as a button. It is also conceivable that the emergency switch 206 is a virtual switch. The customer 202 activates Ac the emergency switch 206 by exposing the emergency switch 206 to at least one first digital break glass access token. This first break glass access token may be stored in a break glass file, for example. In this example, a second digital break glass access token is received At. This second break glass token may be stored and / or maintained by the customer 202, preferably at a distance from a first digital break glass access token required to activate the emergency switch 206. One digital break glass access token is used by the customer 202, and the other digital break glass access token may be stored, for example, in a secure storage container to which the customer 202 and / or the computer network of the customer 203 and / or an authorized service provider 207 may have access or obtain. This "break glass" protocol includes two operations for switching the emergency switch 206. As a result, the fallback tenant 204 is activated to establish the new working environment 208. To build the new working environment 208, the working environment installation instructions of the program storage device of the fallback tenant 204 are activated on account of the switching of the emergency switch 206. This causes the processor of the fallback tenant 204 to establish a new working environment 208. The customer 202 consequently receives access to the new working environment 208. This new working environment 208 is based on backup data received from the backup server of the fallback tenant 204. To build a new working environment 208 without malicious code or infected data, the backup data is no longer copied from the customer's computer network 203 to the fallback tenant 204. Instead, after switching the emergency switch 206, the customer's computer network 203 and / or the emergency switches 206 and / or the fallback tenant 204 and / or an authorized external service provider system are programmed to disconnect the tenant / s and / or the sandbox environment 205, as well as to activate the fallback tenant 204 to establish the new working environment 208 in isolation. The new operating environment 208 may be a fully operable environment, but may also be a simple operating environment with simple functionality to continue business at a simple level while preferably re-creating a fully operable environment in the background. This latter background process may last weeks, typically between 10 and 12 weeks. The new working environment 208 is preferably a temporary working environment 208 and is deactivated and / or removed and / or cleaned once the original working environment of the customer has been fully cleaned and restored and is fully functional again. Once the original environment is restored and fully operational, the customer typically switches from the (temporary) work environment back to the restored original computer network. After this switchback, the working environment established by the fallback tenant may be deleted and / or cleared and / or removed and / or deactivated.Creating a simple working environment saves memory space and thus costs, and also typically saves time to build / create this simple environment compared to a fully operable environment.FIG. 3 shows a block diagram of an example of components of an example computer-implemented method 300 for recovering data in the event of a computer network failure. The method starts with predefining backup data A) of data stored on a data server of the client's computer network 303. The backup data is optionally copied in encrypted form into a sandbox environment 305. It is conceivable that during step A) predefined backup data instructions associated with backup data are stored on at least one non-transitory computer readable program storage device of fallback tenant 304. It is conceivable that a processor, preferably a processor of the customer's computer network and / or an (authorized) external processor, causes copying and transferring at least a part of the predefined backups to the sandbox environment 305. The sandbox environment 305 examines the security of the predefined backup data during step B). The sandbox environment 305 comprises a "so-called" clean room. The clean room examines the backup data for malicious code. It is conceivable that sandbox environment 305 removes unwanted code from the backup data. After examining the backup data, the security-acknowledged backup data are copied to a backup server of the fallback tenant 304 during step C). It is conceivable that during step C) the data is stored in compressed and / or encrypted form. The method further includes providing at least one emergency switch 306 during step D). This emergency switch 306 may be a physical switch such as a button. However, it is also conceivable that the emergency switch 306 is a virtual switch. In the event of a network failure and / or ransomware attack, the customer and / or the customer's computer network 303 is allowed to switch the emergency switch 306 during step E). It is conceivable that a digital break glass access token is required to switch the emergency switch 306 during step E). This break glass access token may be stored, for example, in a break glass file and / or break glass database in the customer's computer network 303. The emergency switch 306 may be programmed to be switched when subjected to at least two predefined activation steps, as shown in FIG. 2. It is further conceivable that an SIEM service and / or an SOC service runs on the computer network 303 of the customer and / or the computer network 303 of the customer is observed by an external SIEM service and / or external SOC service, which issues a warning message to a predefined user of the computer network 303 of the customer and / or to at least one external third party, for example, in the case of a detected cyber security threat. The SIEM and / or SOC service could also generate and / or issue, for example, an access token required to switch the emergency switch 306 during step E). The secure data container 310 of the backup server of the fallback tenant 304 can be initially digitally locked during step C). The secure data container 310 may become accessible by switching at least one emergency switch 306 during step E). Further, during or after step E), client device(s) may / may be disconnected from the data server, in particular in the case of a ransomware attack being detected and / or observed, from the customer and / or computer network 303 of the customer and / or an authorized service provider. Following the switching of the emergency switch 306, a series of processes are followed to establish a new working environment 308 during step F). During step F), the working environment installation instructions are executed. These operating environment installation instructions are stored on at least one non-transitory computer readable program storage device, such as a backup server or an alternative storage medium of fallback tenant 304. Execution of the work environment installation instructions causes at least one processor of the fallback tenant 304 to automatically build a new digital work environment 308 for the customer. This new operating environment 308 is based at least in part on the predefined backup data stored on at least one backup server. Finally, in step G), the customer, preferably one or more client devices of the customer, is granted access to the new digital working environment 308. It is conceivable that the backup data predefined in step A) and / or the backup data stored in step C) on at least one backup server comprise data for establishing and / or installing at least one operating system (OS) and / or at least one virtual machine (VM) that emulates at least one operating system. It is further conceivable that the backup data include data for constructing and / or installing user application(s) user files, communication spaces allowing different users to digitally communicate, and / or a fallback website.The inventive concepts described above are illustrated using several illustrative embodiments. It is conceivable that individual inventive concepts are applied without also applying other details of the described example. It is not necessary to exemplify all possible combinations of the inventive concepts described above, as one skilled in the art will understand that numerous inventive concepts may be (re)combined to arrive at a specific application. It is expressly pointed out that all mathematical combinations are possible between the features mentioned above and referred to and the claims filed, as long as the combination obtained in each case does not contain conflicting characteristics. In this way, this application thus also constitutes a reservoir of possibilities for claimed subject matter.It will be obvious that the invention is not limited to the working examples shown and described herein, but that numerous variants are possible within the scope of the appended claims, which will be obvious to a person skilled in the art.The verb "comprise" and its conjugates used in this patent publication are not only to be understood as "comprise", but are also to be understood as meaning the terms "contain", "consist essentially of", "formed by" and their conjugates.

Claims

A computer-implemented system for recovering data in the event of a computer network failure, comprising: - at least one computer network of a customer, the computer network comprising at least one data server and at least one client device configured to connect to the data server, - at least one fallback tenant associated with the customer comprising: ◯ at least one backup server configured to store, in at least one secure data container, predefined backup data initially stored on the data server, and ◯ at least one non-transitory computer-readable program storage device storing working environment installation instructions which, when executed, cause at least one processor to automatically build a new digital working environment for the customer based on at least a portion of the backup data, which are stored on the backup server and / or grants access thereto, - at least one sandbox environment, which is located between the computer network of the customer and the fallback tenant, for examining the security of backup data and for transmitting security-acknowledged backup data to at least one fallback tenant for storing the security-acknowledged backup data on at least one backup server of the at least one fallback tenant, and - at least one emergency switch, which can be controlled by the customer and / or the computer network of the customer, in particular in the case of a computer network failure of the customer and / or in the case of a data server failure of the customer, Configured to execute the working environment installation instructions of the at least one fallback tenant of the client that cause the at least one processor of the fallback tenant to automatically build a client-accessible new digital working environment based on and / or grant access to at least a portion of the backup data stored on the backup server, wherein the new digital working environment is separated and independent of the at least one computer network of the client.The computer-implemented system of claim 1, wherein the customer's computer network comprises at least one processor and at least one non-transitory computer-readable program storage device storing predefined backup data instructions associated with backup data to be stored on at least one backup server of at least one customer's fallback tenant, which, when executed, cause the at least one processor to copy and transmit at least a portion of the predefined backup data to the at least one sandbox environment, preferably wherein the backup data instructions are stored on a preparation server separated from the data server.The computer-implemented system of any preceding claim, wherein the predefined backup data and / or the backup data stored on at least one backup server comprises data for establishing and / or installing at least one operating system, OS, and / or at least one virtual machine, VM, that emulates at least one operating system.The computer-implemented system of any preceding claim, wherein the system comprises at least one first digital break glass access token stored in at least one break glass file and required for switching the emergency switch.The computer-implemented system according to any of the preceding claims, wherein at least one, preferably each emergency switch is programmed to be switched when subjected to at least two predefined activation steps.The computer-implemented system according to any one of the preceding claims, wherein at least one secure data container of at least one backup server is initially digitally locked and is only accessible by switching at least one emergency switch.The computer-implemented system according to any of the preceding claims, wherein the system is programmed to disconnect the data server and / or the sandbox environment after switching at least one emergency switch, and / or wherein the system, in particular the customer's computer network, is programmed to issue at least one alert message to users of the customer's computer network and / or to at least one predefined external party once the emergency switch is switched.The computer-implemented system according to any one of the preceding claims, wherein the system, in particular the computer network of the customer comprises at least one current security information and event management, SIEM, service and / or at least one current security operation centre, SOC, service for observing unusual network activity, and / or wherein at least one SIEM service and / or at least one SOC service is / are configured for detecting and stopping insider cyber security threats.The computer-implemented system of any preceding claim, wherein the customer's computer network and the fallback tenant are isolated from each other.A non-transitory computer readable program storage device comprising computer readable instructions executable by one or more processors for use in a computer implemented system according to any of claims 1-9.