Home / Case Studies / Recovery Readiness
Case Study · Healthcare · Recovery Readiness Assessment

An Australian healthcare group assessed recovery readiness across its clinic environment to build a more defensible recovery position

The group operates a multi-clinic dental environment where technology supports patient communication, appointments, practice management, Microsoft 365, endpoint access, backup, imaging and day-to-day clinic continuity.

Inlight IT supported the group with a recovery readiness assessment focused on evidence, recovery architecture, backup posture, identity recovery, clinic system dependencies, Cyber Recovery Time and practical remediation priorities.

CLINIC SYSTEMSRECOVERYVAULTEVIDENCE RECOVERY / EVIDENCE PATH RESTORE TESTEDIMMUTABLE VAULTEVIDENCE PACK HEALTHCARE / RECOVERY READINESS RECOVERY POSITION / EVIDENCE-BASED
Engagement at a glance

An Australian healthcare group — recovery readiness across a multi-clinic environment

An evidence-led assessment of whether the clinic environment could recover from a cyber incident scenario.

Client
Australian healthcare group
Industry
Healthcare
Environment
Australian healthcare group — patient communication, appointments, practice management, Microsoft 365, endpoint access, backup, imaging and day-to-day clinic continuity
Engagement type
Recovery Readiness Assessment
Focus
Backup posture, identity recovery, clinic system dependencies, Cyber Recovery Time and recovery evidence
Themes
Recovery readiness, healthcare continuity, Microsoft 365 and identity, insurance and governance evidence
Outcome
A clearer recovery position with evidence-based remediation priorities
Key project stats

One assessment, an evidence-based recovery position

4
core deliverables

Architecture Gap Report, Cyber Recovery Time model, Insurance Evidence Pack and 90-day Remediation Roadmap.

5
operational layers

Recovery scope, backup posture, identity recovery, Cyber Recovery Time and remediation connected in one assessment.

90
day roadmap

Practical remediation priorities sequenced into 30, 60 and 90-day tranches.

M365
identity in scope

Microsoft 365, Entra ID, MFA and privileged access included in the recovery model.

Operating context

A dental clinic cannot treat recovery as an abstract IT exercise — if systems are unavailable, operations feel it immediately

For an Australian healthcare group, recovery readiness is not only an IT issue. It affects appointment access, clinical administration, patient communication, staff coordination, finance processes, supplier communication and the ability for clinics to keep operating safely after a disruptive cyber incident.

Healthcare environments depend on technology being available, recoverable and supportable. Even smaller clinics typically operate several interdependent systems: endpoint access, Microsoft 365, practice management workflows, imaging, appointment access, communication, finance and backup.

The group needed recovery readiness evidence across that environment — not a general statement that backups were running.

Why this work mattered

Backup confidence is not the same as recovery readiness — the difference matters when systems are unavailable

A multi-clinic healthcare environment has a different recovery profile from a single office. Systems, users, locations, access pathways, clinical dependencies and support expectations all need to be understood before recovery confidence is meaningful.

01

Clinic continuity depended on more than file recovery

Recovery readiness needed to address the systems that support day-to-day clinic operations: communication, appointments, practice workflows, user access, endpoint access and administrative coordination. Restoring files alone would not prove the clinics could return to a usable operating state.

02

Backups needed to be assessed as a recovery path, not as configured jobs

The assessment needed to test whether backup coverage, access separation, restore evidence and recovery process were strong enough to support a cyber incident scenario. The question was not "do backups run?" It was "could the business recover, and could that recovery position be evidenced?"

03

Identity recovery had to sit inside the recovery model

If identity is compromised, restored systems may not be usable until clean authentication is available. For a healthcare environment using Microsoft 365 and identity-led access, recovery needed to address identity sequencing, MFA, administrative access and account hygiene — not as separate controls, but as part of the recovery path.

04

Clinic system dependencies needed to be visible

Clinic systems depend on each other. A restored application may still need identity, endpoints, network access, cloud services, storage, imaging pathways or user access before it becomes useful. The assessment needed to identify practical dependency relationships affecting recovery sequence and recovery time.

05

Evidence was needed for insurance and governance conversations

Cyber insurance and internal governance conversations increasingly ask for dated evidence rather than verbal assurance. Restore tests, architecture details, backup posture and recovery process needed to be documented in a way that could support decision-making.

What Inlight IT delivered

Five operational layers connecting recovery scope, backup posture, identity recovery, Cyber Recovery Time and remediation

The Recovery Readiness Assessment is structured around four core deliverables: Architecture Gap Report, Cyber Recovery Time model, Insurance Evidence Pack and 90-day Remediation Roadmap. For the group, those deliverables were applied in a healthcare context, where clinical continuity, user access and system dependencies needed practical attention.

01

Recovery scope and clinic dependency review

The assessment started with what the clinics actually needed to recover. The operating context behind recovery was reviewed: clinics, users, core systems, Microsoft 365, backup, endpoint access and recovery dependencies.

Included
Critical services identifiedMicrosoft 365 dependencies mappedCommunication dependenciesEndpoint and device dependenciesRecovery sequence context
02

Backup architecture and restore evidence

Backups were assessed as recovery evidence, not only as configured jobs. The review covered backup coverage, restore evidence, retention, access separation and the ability to support recovery under cyber incident conditions.

Included
Backup coverageRestore evidenceRetention and access separationBackup administration accessImmutability reviewedMicrosoft 365 backup posture
03

Identity and access recovery

Recovery depends on clean access, not only restored data. Identity and access were treated as part of the recovery model, reviewed against recovery scenarios rather than as separate controls.

Included
Identity recovery sequenceEntra ID and Microsoft 365 accessMFA and privileged accessUser and group dependenciesAdministrative access separation
04

Cyber Recovery Time and recovery sequencing

Cyber Recovery Time was modelled as a practical recovery position under cyber incident conditions, rather than relying only on policy RTO statements. Critical services were sequenced in the order clinics would actually need them back.

Included
Cyber Recovery Time modelCritical services sequencedClinic operation impactRestore-and-validate pathwayPriority services identified
05

Evidence pack and remediation roadmap

Findings were translated into evidence and practical next actions, with insurance evidence positioned to support renewal discussions and remediation priorities sequenced into 30, 60 and 90-day tranches.

Included
Insurance evidence pack30, 60 and 90-day tranchesOwnership and support documentedFuture readiness review pathwayPractical next actions
Delivery approach

From recovery scope to evidence review, dependency mapping, recovery modelling and remediation planning

Select a stage to trace how the assessment moved from clinic context to a prioritised remediation roadmap.

External threat signals

Healthcare cyber attack activity is rising in the Australian threat environment

Healthcare and dental organisations face a different threat profile than other sectors. Patient communication, clinical administration, imaging and appointment systems carry continuity expectations that make cyber attack unusually disruptive, and recent Australian threat data confirms the sector is increasingly targeted.

Cyber attack incidents against the Australian healthcare sector doubled in FY2024-25 compared to FY2023-24 (ASD Annual Cyber Threat Report 2024-25).

FY24-25

The reporting period in which healthcare incident volume doubled — creating operational risk for patient-facing healthcare environments and destabilising health systems.

Dated

Cyber insurance and internal governance conversations increasingly ask for dated evidence rather than verbal assurance.

90

The group's remediation priorities were sequenced into 30, 60 and 90-day tranches so findings became actionable.

ASD Annual Cyber Threat Report 2024-25Inlight IT engagement record
What changed for the client

The group moved from general recovery confidence to a structured understanding of recoverability, evidence quality and remediation priorities

The engagement gave the group a clearer evidence-based view of recovery readiness across the clinic environment. The outcome was not a single answer about whether the business was "ready" — it was a structured position on what was protected, what required improvement and which remediation actions should be prioritised first.

O·01

Recovery position became clearer

The group gained a more evidence-based view of how the clinic environment would recover from a cyber incident scenario, rather than relying on general confidence about backups.

O·02

Backup readiness was better understood

Backup coverage, restore evidence, access separation and recovery-path considerations could be assessed against cyber incident conditions, not only against ordinary backup operation.

O·03

Clinic dependencies became more visible

Systems, users, Microsoft 365, endpoint access and operational dependencies could be sequenced into the recovery order rather than treated as independent.

O·04

Identity recovery was brought into scope

Identity, MFA, privileged access and Microsoft 365 access were considered as part of recoverability, not as separate controls in another workstream.

O·05

Insurance and governance evidence improved

The group gained a clearer evidence position to support cyber insurance, governance and internal risk conversations.

O·06

Remediation became more actionable

Findings were sequenced into practical improvement work across backup, identity, recovery testing, documentation and supportability — designed for execution by Inlight IT, the internal team or another capable provider.

Net position

The outcome was not a single answer about whether the business was "ready" — it was a structured position on what was protected, what required improvement and which remediation actions should be prioritised first.

Project outcomes

The shape of the recovery position that emerged

Outcome 01

Multi-clinic scope reviewed

Recovery readiness reviewed across a multi-clinic healthcare operating environment.

Outcome 02

Tested against incident conditions

Backups, restore evidence and recovery assumptions reviewed under cyber incident conditions.

Outcome 03

Identity inside the recovery model

Microsoft 365, Entra ID, MFA and privileged access included in the recovery model.

Outcome 04

Dependencies and ordering surfaced

Clinic system dependencies and recovery ordering surfaced as part of recovery time.

Outcome 05

Recovery time linked to services

Cyber Recovery Time assumptions linked to critical services and recovery sequence.

Outcome 06

Findings made actionable

Findings translated into prioritised, actionable remediation work.

Technology and service scope

The work connected recovery readiness, backup and identity review and Cyber Recovery Time modelling

Recovery readiness

6
  • Recovery Readiness Assessment
  • Architecture Gap Report
  • Insurance Evidence Pack
  • 90-day Remediation Roadmap
  • Recovery scope review
  • Critical service identification

Backup and restore

6
  • Backup and disaster recovery review
  • Restore evidence
  • Retention and access separation
  • Immutability review
  • Microsoft 365 backup considerations
  • Backup administration access

Identity and access

6
  • Identity recovery considerations
  • Entra ID and Microsoft 365 access
  • MFA and privileged access
  • Administrative access separation
  • User and group dependencies
  • Account hygiene

Recovery modelling

6
  • Cyber Recovery Time modelling
  • Recovery sequencing
  • Clinic dependency mapping
  • Restore-and-validate pathway
  • Priority services
  • Future readiness review pathway
Practical next step

Could your clinics recover from cyber attacks, with evidence?

We test whether you could actually recover from a major cyber incident, then close the gaps.

Book a Recovery Readiness Assessment