Backup & Business Continuity
Backups that have been restored, recovery objectives that have been tested, and a continuity plan that says who does what at 3am.
Almost every organisation has backups. Far fewer have restores. The gap between the two is where incidents turn into outages, and it is almost always discovered at the worst possible moment.
CDTS runs backup and continuity as an operated service: protection configured to defined recovery objectives, restores tested on a schedule, and results reported whether or not they are flattering.
We pay particular attention to Microsoft 365. Retention is not backup, and the assumption that Microsoft has it covered has cost more than one Australian organisation a mailbox it needed.
Scope of the service
The components we deliver and operate under this service. Scope is agreed per engagement — this is the standard shape.
Backup design & operation
Protection for servers, endpoints, cloud workloads and SaaS data, built to agreed recovery point and recovery time objectives.
Microsoft 365 backup
Independent protection for Exchange Online, SharePoint, OneDrive and Teams data, held separately from the tenancy it protects.
Immutable & offsite copies
Retention that a ransomware operator with domain admin cannot delete, held offsite and onshore.
Restore testing
Scheduled test restores with documented results — the only evidence that a backup regime works.
Disaster recovery planning
Recovery runbooks with named roles, dependencies and sequencing, written to be usable under pressure.
Continuity exercises
Tabletop and technical exercises so the first time you run the plan is not during the incident.
Common questions
Does Microsoft back up our Microsoft 365 data?
Not in the way most people assume. Microsoft protects the platform and offers retention and recycle-bin windows, but that is retention, not backup — it will not help you against a malicious deletion discovered months later, or a compromised administrator. Independent protection for Exchange Online, SharePoint, OneDrive and Teams, held outside the tenancy, is a separate control.
How do you protect backups from ransomware?
Immutable retention held offsite and onshore, so a copy exists that an attacker with domain administrator rights cannot delete or encrypt. The credential that can destroy your backups is the credential attackers look for first.
How often do you test restores?
On a defined schedule, with the result documented whether or not it is flattering. Almost every organisation has backups; far fewer have evidence of a successful restore, and that gap is where an incident becomes an outage.
What are RPO and RTO, and who decides them?
Recovery point objective is how much data you can afford to lose; recovery time objective is how long you can afford to be down. They are business decisions, not IT ones — we facilitate the conversation, then design and cost the protection to meet what the business actually agrees to.
What we have written about this
Retention is not backup — what Microsoft 365 does not protect
Microsoft protects the platform. Protecting your data in it is your responsibility, and the gap only becomes obvious at the worst possible moment.
What a real disaster recovery test looks like
A backup job reporting success proves the job ran. It proves nothing about whether you can recover, how long it takes, or whether the data is usable.
Services that usually go with this
Cloud & Infrastructure
Azure, Microsoft 365 and sovereign Australian hosting — designed, migrated and operated, including what is left on-premises.
ExploreCyber Security & Essential Eight
Assessment, uplift and controls designed to help you meet the ACSC Essential Eight, the ISM and the PSPF.
ExploreManaged IT & Service Desk
Your IT department, or the half of it you are missing. 24×7 service desk, proactive monitoring, patching and vendor management under one agreement.
ExploreTalk to us about Backup & Business Continuity
Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.