Brisbane, QLD ·
Immutability is the control that stops the worst case
Modern ransomware operators look for the backup system first. If your backups sit on a share reachable with domain administrator credentials, they are part of the attack surface, not the recovery plan.
At least one copy should be immutable or genuinely offline, with separate credentials that are not used anywhere in daily administration.
Measure your real recovery time
Most organisations quote a recovery time objective they have never tested. Restore one meaningful system from backup, time it end to end including data validation, and write the number down. That is your actual objective.
We run restore rehearsals quarterly for managed clients and report the measured result, because a backup only counts once it has been restored.
Recovery order beats recovery speed
Restoring the file server first when your identity provider and line-of-business database are still down wastes the window in which stakeholders are patient. Document the dependency order before you need it: identity, network, core application, data, then endpoints.
Notification obligations run in parallel
Australian organisations covered by the Notifiable Data Breaches scheme must assess whether an eligible data breach has occurred and notify affected individuals and the OAIC where serious harm is likely. That assessment starts during the incident, not after recovery, so name the responsible person in advance.
In short
Immutable or offline copies, a measured recovery time, a documented recovery order and a named person for breach assessment are the four things that separate a bad week from a business-ending event.
