Managed IT & Infrastructure

Backup & Business Continuity

Backups that have been restored, recovery objectives that have been tested, and a continuity plan that says who does what at 3am.

Almost every organisation has backups. Far fewer have restores. The gap between the two is where incidents turn into outages, and it is almost always discovered at the worst possible moment.

CDTS runs backup and continuity as an operated service: protection configured to defined recovery objectives, restores tested on a schedule, and results reported whether or not they are flattering.

We pay particular attention to Microsoft 365. Retention is not backup, and the assumption that Microsoft has it covered has cost more than one Australian organisation a mailbox it needed.

What’s included

Scope of the service

The components we deliver and operate under this service. Scope is agreed per engagement — this is the standard shape.

01

Backup design & operation

Protection for servers, endpoints, cloud workloads and SaaS data, built to agreed recovery point and recovery time objectives.

02

Microsoft 365 backup

Independent protection for Exchange Online, SharePoint, OneDrive and Teams data, held separately from the tenancy it protects.

03

Immutable & offsite copies

Retention that a ransomware operator with domain admin cannot delete, held offsite and onshore.

04

Restore testing

Scheduled test restores with documented results — the only evidence that a backup regime works.

05

Disaster recovery planning

Recovery runbooks with named roles, dependencies and sequencing, written to be usable under pressure.

06

Continuity exercises

Tabletop and technical exercises so the first time you run the plan is not during the incident.

Common questions

Does Microsoft back up our Microsoft 365 data?

Not in the way most people assume. Microsoft protects the platform and offers retention and recycle-bin windows, but that is retention, not backup — it will not help you against a malicious deletion discovered months later, or a compromised administrator. Independent protection for Exchange Online, SharePoint, OneDrive and Teams, held outside the tenancy, is a separate control.

How do you protect backups from ransomware?

Immutable retention held offsite and onshore, so a copy exists that an attacker with domain administrator rights cannot delete or encrypt. The credential that can destroy your backups is the credential attackers look for first.

How often do you test restores?

On a defined schedule, with the result documented whether or not it is flattering. Almost every organisation has backups; far fewer have evidence of a successful restore, and that gap is where an incident becomes an outage.

What are RPO and RTO, and who decides them?

Recovery point objective is how much data you can afford to lose; recovery time objective is how long you can afford to be down. They are business decisions, not IT ones — we facilitate the conversation, then design and cost the protection to meet what the business actually agrees to.

Next step

Talk to us about Backup & Business Continuity

Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.