Backup & continuity
A backup is a claim. A restore is evidence. We test yours on a schedule and send you the result, so the first time anybody performs a recovery is not the worst day of the year.
Microsoft does not back up your Microsoft 365 data
This is stated plainly in Microsoft's own shared responsibility model, and it still surprises people in the room. Microsoft guarantees the availability of the service. The data inside it is yours to protect.
Retention policies and the recycle bin are not backup. They expire, they can be changed by an administrator — including a compromised one — and they will not help you when a mailbox has been maliciously purged, a SharePoint site deleted, or a ransomware payload synchronised through OneDrive to every device that had it open.
The second assumption we test is the one about your servers: that the job reported success. Success means data was written. It does not mean the data can be read back into a working system inside the time your business can survive without it.
What we protect, and how far back
Retention is set from your actual obligations — record-keeping requirements, contracts and insurance — not from a default in a console.
- Microsoft 365
- Exchange Online, SharePoint, OneDrive and Teams — including chat, channel content and the files behind both. Point-in-time restore to the item level, so recovering one mailbox folder does not require restoring the mailbox.
- Servers & virtual machines
- Image-level backup for on-premises, co-located and Azure workloads, with local copies for speed and offsite copies for survivability. Bare-metal and instant recovery where the platform supports it.
- Endpoints
- Laptop and desktop protection for the data that never made it to OneDrive. Frequently the difference between an inconvenient reimage and a lost fortnight of work.
- Immutability & isolation
- Backup copies that cannot be altered or deleted within their retention window, held in a separate security domain with separate credentials — because modern ransomware looks for your backups first and encrypts them second.
- Documented RTO & RPO
- Recovery time and recovery point objectives agreed per system, in writing, and proven achievable by testing. A target nobody has ever measured is an aspiration.
- Disaster recovery runbook
- The written sequence for a total loss event: who declares it, in what order systems come back, what depends on what, who is called, and how staff are told — kept somewhere that is still reachable when your network is not.
Restores are scheduled, not hypothetical
The Essential Eight requires restore testing to reach maturity. We would do it anyway, because it is the only backup metric that means anything.
| What is tested | How often | What you receive |
|---|---|---|
| File & mailbox item restore | Monthly | Restore log with elapsed time, in the monthly report |
| Full server restore to isolated network | Quarterly | Test report with measured RTO against target |
| Microsoft 365 tenant-level restore | Quarterly | Sample restore across Exchange, SharePoint and Teams |
| Disaster recovery walkthrough | Annually | Tabletop exercise with your leadership, and a revised runbook |
Scroll the table sideways to see every column.
When a test fails — and occasionally one does — it appears in your report with the cause and the remediation. A restore testing programme that has never reported a failure is not being run.
What people ask
How long should we retain backups?
Long enough to cover your record-keeping obligations and long enough to outlast a slow-burn compromise. Seven years is common for financial records; twelve months of daily points with monthly archives is a reasonable operational default. We set it from your obligations rather than a template.
Where is the data stored?
Australian data centres by default, with the specific region named in your service schedule. If you have a contractual or regulatory requirement for a particular location or sovereignty arrangement, tell us during the assessment and we will design to it.
What is a realistic RTO?
For a single virtual machine with instant recovery: under an hour. For a full site rebuild from offsite copies: measured in days, not hours, and dependent on your bandwidth. Anyone quoting a four-hour full-site RTO without having tested it in your environment is quoting a brochure.
Do we still need this if we are fully in the cloud?
More than ever. Cloud removes hardware failure as a cause; it does not remove accidental deletion, malicious insiders, compromised administrator accounts, ransomware synchronised through OneDrive, or a SaaS vendor's own outage. The failure modes changed. The need did not.
When was your last successful restore
If the answer is “the backup reports say it is fine”, that is the answer we hear most often — and it is the one worth checking.