Data at a primary storage system is encrypted and remote copied to a
secondary storage system. A Remote Copy Configuration Information (RCCI)
is created that identifies the encryption mechanism, keys, data source
volume, and target volume for the remote copy. The RCCI is backed up on a
trusted computer system. In one embodiment, the secondary storage system
is an off-site data storage system managed by a third party. Upon
detection of a failure in the primary storage system, the encrypted data
and RCCI are transferred to a tertiary server, which is optionally
created upon detection of the failure, and operations of the failed
primary server are resumed by the tertiary server. In one embodiment, the
failure is detected by loss of a heart beat signal transmitted from the
primary storage system to a management server that initiates the
transfers to the tertiary server.