Backup & Disaster Recovery
Plan for the worst. Trust that you'll recover.
Overview
While you can't predict unexpected events, we'll ensure the right precautions are in place to minimise downtime and keep you moving in the right direction. Modern, tested, regularly verified.
A backup you have not restored is a hypothesis
The most common finding when we audit a new environment is a backup regime reporting success for months that cannot complete a restore. Jobs run, dashboards stay green, and nobody has taken a real system and brought it back. Verification is the whole point of the service.
We test restores on a schedule and document the result. On a full disaster recovery arrangement that extends to failover testing, so the recovery time objective in your plan is a measured number rather than an aspiration.
Ransomware changed the requirement
Modern ransomware targets the backup infrastructure first, because encrypting production is only leverage if recovery is unavailable. That makes immutability the central design requirement. Copies have to be genuinely unalterable for their retention period, including by an administrator whose credentials have been compromised.
We design around immutable local copies, off site replication to Australian data centres, and separated credentials so a single compromised account cannot reach both production and backup. Veeam and Barracuda cover the software led designs, with appliance based protection where that is the better fit.
Defining RTO and RPO honestly
Recovery time objective is how long you can be down. Recovery point objective is how much data you can afford to lose. Both are business decisions with a cost attached, and the conversation is more useful per system than across the board.
We work through it system by system, price the options and let you choose. Writing four hours into a plan when the infrastructure cannot beat twenty four helps nobody, so the documented figures are the ones we can meet.
Beyond the technology
Business continuity is broader than backup. Who declares an incident, how staff are contacted when email is unavailable, where people work if a site is inaccessible, and which processes run manually in the interim. We document that alongside the technical recovery plan.
What's included
Immutable Backups
Ransomware-resistant backup copies you can always restore from.
Off-site & Cloud Vaulting
Geographic redundancy across Australian data centres.
Disaster Recovery Plans
RTO/RPO defined, documented, and regularly drilled.
Failover Testing
Quarterly DR tests so you know it works before you need it.
Business Continuity
Plans that go beyond IT, people, process and premises.
Rapid Restore
Critical workloads back online within agreed RTO windows.
What you get
- Tested, not theoretical
- Resilient to ransomware
- Documented and audit-ready
Common questions
How often should backups be tested?
Restore verification should be continuous or daily, which modern platforms automate through screenshot verification. Full recovery testing, meaning standing a system up and confirming it works, should happen at least quarterly. Annual testing is too infrequent to catch a regime that has drifted.
What does immutable backup mean?
Backup data that cannot be modified or deleted for a defined retention period, including by an administrator account. It matters because ransomware operators target backup infrastructure first, using stolen admin credentials. Immutability is what keeps a recovery option available after the credentials are gone.
How quickly can we recover after a major failure?
It depends on the design you have paid for. Appliance based protection with instant virtualisation can bring critical systems back in minutes by running them on the backup appliance. Restoring to replacement hardware from off site copies takes longer. We set the target per system and then test whether we hit it.
Is Microsoft 365 data backed up automatically?
No, and this is one of the most common and costly misunderstandings we encounter. Microsoft replicates for availability and provides limited retention, but it does not protect you against deletion, malicious insiders or ransomware in the tenant. Separate third party backup for Microsoft 365 is a genuine requirement.
Where is our backup data stored?
On Australian infrastructure. Local copies stay on your premises for fast recovery, with replicated copies in Australian data centres for site loss scenarios. We can document data location and retention for audit, insurance or board reporting.
