Disaster Recovery & Backups

27 - Recovery

Disaster Recovery
& Backups

Make sure your business can recover when systems fail. Backups are only useful if they can be restored when they're needed. RTCS reviews, tests and improves Disaster Recovery and backup arrangements - confirming what's backed up, how quickly it can be restored, how much data could be lost, and whether recovery has actually been tested.

  • Disaster Recovery planning, review and documentation
  • Backup strategy and coverage assessment
  • Recovery Time Objective and Recovery Point Objective review
  • Backup and restore testing review
  • Ransomware recovery readiness review
  • Immutable, isolated and offline backup review
  • Microsoft 365, SharePoint, OneDrive and Exchange Online recovery
  • Cloud workload, storage, database and VM backup review
  • Executive recovery reporting and improvement roadmap
Discuss This Service
Scenarios
Ransomware - accidental deletion - cloud outage - hardware failure - supplier failure - major disruption
Platforms
Microsoft 365 - Azure - AWS - Google Cloud - on-prem - SaaS - third-party backup products
Engagement Types
DR review - backup assessment - RTO/RPO review - restore testing - ransomware recovery
Outputs
Recovery gap register - DR plan updates - risk-rated findings - remediation roadmap - executive summary
ISO 22301 SOCI Act Essential Eight NIST CSF
RTO
Recovery Time Objective
RPO
Recovery Point Objective
3-2-1
Backup Resilience Review
AU
Onshore Delivery
01 / Context

A backup is not a recovery plan.

Disaster Recovery is the process of restoring technology systems after a major disruption - servers, cloud services, databases, applications, identity platforms, network services, file storage and business-critical systems. A backup review checks whether your arrangements are suitable, secure and actually recoverable. RTCS helps close the gap between having backups and being able to recover.

02 / Common Gaps

Most organisations assume backups work until they need to restore them.

G1

Critical systems not included in backup scope

G2

Backups failing without anyone noticing

G3

Restore processes not being tested

G4

Backup accounts having excessive privileges

G5

Backups accessible from compromised admin accounts

G6

Cloud and SaaS data not being backed up properly

G7

Recovery priorities not documented

G8

RTO and RPO targets not matching business needs

G9

Backup retention settings too short

G10

No clear recovery process during ransomware

03 / RTO & RPO

Recovery planning needs clear targets.

Recovery Time Objective (RTO)

How quickly a system or service needs to be restored after disruption. RTCS reviews RTO targets for critical systems and compares them against your actual recovery capabilities - so the targets are realistic and the gaps are visible.

Recovery Point Objective (RPO)

How much data loss the organisation can tolerate. An RPO of four hours means data should be recoverable to within four hours of the incident. RTCS reviews RPO targets against backup frequency, retention and the actual recoverable state.

04 / Ransomware Recovery

Can you recover when ransomware reaches the backups?

Ransomware affects production systems, backups, identity platforms and recovery processes. RTCS reviews whether your backup and DR arrangements are resilient enough to actually support recovery.

Backup isolation Immutable backup options Offline backup options Backup administrator access Recovery account protection Restore testing Recovery prioritisation Clean recovery environment Incident response alignment

Pair with Incident Response Readiness for the response side, and Crisis Management for the executive and BCP layer above the technical recovery.

05 / Cloud & SaaS Backup

Cloud platforms still need recovery planning.

RTCS reviews backup and recovery arrangements across cloud and SaaS environments such as Microsoft 365, Azure, AWS, Google Cloud and other business platforms.

Microsoft 365 data recovery SharePoint & OneDrive recovery Exchange Online recovery Cloud storage backup Database backup Virtual machine backup SaaS export & recovery options Cloud retention & deletion Third-party backup products

For configuration, identity and exposure review of the same cloud environments, see Cloud Security.

Understand to Improve

A practical, staged engagement that confirms recovery capability against the business outcomes that actually matter.

01
Understand

Identify critical systems, data, business processes, recovery requirements and current backup arrangements.

02
Assess

Review backup coverage, retention, restore processes, access controls, recovery documentation and ransomware resilience.

03
Test

Where included, support or review restore testing to confirm whether systems and data can be recovered.

04
Prioritise

Identify gaps based on business impact, recovery priority and operational risk.

05
Improve

Provide practical recommendations to strengthen backups, recovery processes and DR planning.

06 / Who It's For & What You Receive

Who It's For & What You Receive

Who This Service Is For

  • Need to confirm backups are working
  • Need to improve Disaster Recovery planning
  • Need ransomware recovery readiness
  • Have not tested restores recently
  • Use Microsoft 365, Azure, AWS or Google Cloud
  • Need clearer RTO and RPO targets
  • Need to protect critical business systems
  • Need recovery evidence for audits or insurance
  • Want practical recovery planning without complexity

Typical Deliverables

  • Disaster Recovery review
  • Backup strategy review
  • Backup coverage assessment
  • RTO and RPO review
  • Critical system recovery map
  • Backup access control findings
  • Ransomware recovery readiness findings
  • Restore testing observations
  • Recovery gap assessment
  • DR plan updates
  • Backup improvement roadmap
  • Executive summary & prioritised actions
07 / Related Services

Where recovery connects to the rest of the program.

Crisis Management

BCP, tabletop exercises and executive decision-making during the disruption your DR plan is restoring from.

Incident Response Readiness

Technical incident handling and ransomware response that runs in parallel with recovery.

Cloud Security

Identity, exposure and configuration review of the cloud platforms hosting the workloads you're recovering.

Identity & Access Management

Protect the backup admin accounts and recovery identities that ransomware specifically targets.

Detection & Response Readiness

SIEM, EDR and identity monitoring so backup-targeting activity is caught before it impacts recovery.

Governance, Risk & Compliance

Recovery evidence and reporting that supports audits, cyber insurance and SOCI-style obligations.

Supply Chain Risk

Supplier and SaaS recovery dependencies that often sit outside your own backup scope.

vCISO & Security Advisory

Executive-level oversight of recovery posture and integration into the broader security roadmap.

The middle of an outage is the wrong time to find out backups are incomplete or recovery steps are unclear. Talk to us about a Disaster Recovery review, backup assessment, ransomware recovery readiness review or restore testing engagement.

Common Questions

What is the difference between backups and Disaster Recovery?

Backups are copies of data or systems. Disaster Recovery is the process used to restore services after a major disruption. Backups support recovery, but they do not replace a Disaster Recovery plan.

Why do backups need to be tested?

Backups can fail, be incomplete or take longer to restore than expected. Restore testing confirms whether data and systems can actually be recovered.

What is RTO?

Recovery Time Objective is the target time for restoring a system or service after disruption.

What is RPO?

Recovery Point Objective is the maximum amount of data loss the organisation can tolerate. For example, an RPO of four hours means the organisation should be able to recover data to within four hours of the incident.

Can you review ransomware recovery readiness?

Yes. RTCS can review whether backups are protected, isolated, recoverable and suitable for ransomware recovery scenarios.

Do we need backups for Microsoft 365?

Microsoft 365 has retention and recovery features, but organisations still need to understand their recovery requirements. In some cases, third-party backup may be needed to meet business, compliance or ransomware recovery expectations.

Can you help update our Disaster Recovery plan?

Yes. RTCS can review, update or develop Disaster Recovery documentation, including recovery priorities, roles, restore steps, communication paths and testing recommendations.

Do you perform restore testing?

RTCS can support restore testing, review restore evidence and document gaps. Testing is scoped carefully to avoid business disruption.