Home / Case Studies / Backup Architecture
Case Study · Professional Services · Backup Architecture · Recovery Resilience

An Australian professional services organisation reviewed backup architecture and recovery evidence through a cyber attack-resilience lens

For this engagement, the division operates in a professional services environment where technology supports users, client work, document workflows, Microsoft 365, data access, operational continuity and assurance expectations. Inlight IT supported a single division — not an entire national organisation. The work focused on backup architecture, recoverability, evidence quality, immutability considerations and actionable recovery resilience.

The requirement was not simply to confirm that backups were running. The division needed a clearer view of whether backup architecture, restore evidence, administrative access and recovery assumptions could support a defensible recovery position. The outcome was a more structured backup and recovery view — what was protected, where evidence existed, which recovery assumptions needed validation and which improvement areas should be prioritised.

BUSINESS SYSTEMSREPLICATIONVAULTEVIDENCE REPLICATION / RECOVERY EVIDENCE REPLICATEDIMMUTABLE VAULTEVIDENCE PACK PROFESSIONAL SERVICES / BACKUP ARCHITECTURE ARCHITECTURE / DEFENSIBLE RECOVERY
Engagement at a glance

An Australian professional services organisation — backup architecture and recovery readiness review

A controlled-scope review of whether backup architecture, access and evidence could support a defensible recovery position.

Client
Australian professional services organisation
Scope clarification
A single division — not the broader organisation
Industry
Professional services
Starting point
Backups configured and running, without a clear view of whether the recovery path could survive cyber incident conditions or support scrutiny
Engagement type
Backup architecture and recovery readiness review, conducted at a controlled level
Focus
Review backup architecture and recovery evidence to clarify recoverability, resilience and improvement priorities
Outcome
A clearer backup and recovery position, with evidence quality, immutability considerations, administrative access and remediation priorities identified at a controlled level
Key project stats

One division, one review, a clearer recovery position

1
Australian professional services organisation

The engagement supported a single division — not an entire national organisation.

5
review workstreams

Backup architecture, immutability and resilience, restore evidence, Microsoft 365 and cloud recovery, and remediation priorities.

2
improvement horizons

Findings separated quick-win remediation from longer-term improvement so the division could act in a practical sequence.

M365
cloud recovery in scope

Microsoft 365 backup implications, SharePoint, OneDrive and email recovery awareness included in the review.

Operating context

A backup report says jobs are running — a recovery position shows whether the business can restore what matters

For professional services environments, backup and recovery are tied to continuity, client work, Microsoft 365, document access, data governance, cyber insurance, assurance and operational confidence.

The question is no longer only whether a backup product is configured. The useful question is whether the recovery path can survive cyber incident conditions and whether the evidence is strong enough to support internal and external scrutiny.

For the division, Inlight IT's role was to review backup and recovery posture at a controlled level — architecture, restore evidence, immutability, administrative access, recovery assumptions and practical remediation priorities. This engagement supports a single division and is not a whole-of-organisation case study.

Why this work mattered

The division needed a clearer recovery position, not only confirmation that backups existed

Backup confidence can be misleading when the recovery path has not been tested against cyber incident conditions. Modern cyber attacks can target backup systems, identity, privileged access and dependencies before production systems are encrypted.

01

Backup operation did not automatically prove recoverability

A successful backup job does not prove that the right systems, data and dependencies can be restored in the right order. The review needed to look beyond job status and consider recovery pathway, restore evidence and whether the backup position could support real operational recovery.

02

Immutability needed architectural validation

A backup is genuinely immutable when it cannot be altered, encrypted or deleted during the retention period, even by an account with administrator-level credentials. The engagement needed to consider immutability as architecture, not as a label attached to a backup product.

03

Backup administration and privileged access mattered

Backup admin access is a critical recovery control. If the same credentials or administrative pathways can reach production and backup systems, a destructive cyber event may compromise the recovery path. The review needed to consider administrative access, MFA, credential separation and the practical exposure of backup management.

04

Restore evidence needed to support the recovery position

Restore testing changes the conversation from assumption to evidence. Without dated restore evidence, the organisation may know backups are configured but not whether recovery would work under pressure. The review needed to identify where evidence existed and where further validation would improve confidence.

05

Improvement priorities needed practical sequencing

Backup architecture reviews often identify several improvement areas at once: retention, immutability, Microsoft 365 backup, administrator access, restore testing, documentation and operational ownership. The output needed to separate urgent remediation from longer-term improvement so the division could act in a practical sequence.

What Inlight IT delivered

A backup architecture engagement focused on recoverability, immutability, evidence and sequenced remediation

Inlight IT reviewed the backup and recovery posture through a recovery resilience lens. The engagement considered not only whether backups existed, but whether the recovery architecture could support a defensible recovery position.

01

Backup architecture review

Backup architecture, coverage, retention, access model, repository considerations and recovery dependencies were reviewed at a controlled level, with recovery scope, workload and data coverage, operational ownership and recovery-path visibility considered together.

Included
Recovery scopeWorkload and data coverageRepository considerationsRetention awarenessOperational ownershipRecovery-path visibility
02

Immutability and recovery resilience review

The backup position was reviewed through a cyber attack lens — whether the architecture aligned with immutable backup principles, from storage-layer protection to backup admin access and credential separation.

Included
Immutable backup principlesStorage-layer protectionWORM and Object Lock considerationsRetention lock considerationsBackup admin accessCredential separationCyber attack-path awareness
03

Restore evidence and recoverability review

The engagement considered whether restore evidence, recovery documentation and operational processes could support the backup and recovery position, including critical data and service recovery awareness and evidence gap identification.

Included
Restore evidenceRecovery documentationRestore-path considerationsCritical data and service recoveryRecovery validation considerationsEvidence gap identification
04

Microsoft 365 and cloud recovery considerations

For professional services environments, Microsoft 365 data often sits at the centre of day-to-day work. The engagement considered Microsoft 365 backup implications, cloud retention assumptions and the identity, access and ownership dependencies behind cloud recovery.

Included
Microsoft 365 backup implicationsSharePoint, OneDrive and email recoveryCloud retention assumptionsIdentity and access dependenciesAdministrative control considerationsRecovery ownership
05

Remediation priorities and roadmap

Findings were translated into sequenced improvement areas — which gaps or weaknesses should be addressed first and which improvements could be sequenced into a remediation pathway.

Included
Sequenced improvement areasQuick-win separationLonger-term improvementOwnership considerationsFuture review pathway
Delivery approach

Five stages, sequenced from architecture to evidence to remediation

Select a stage to trace how the review moved from scope to sequenced remediation.

External threat signals

Backup architecture is now part of cyber assurance, not only IT operations

Professional services environments hold commercially sensitive work, client files, correspondence, documents, Microsoft 365 data and internal operational information. Backup and recovery posture affects continuity, client confidence, insurance conversations and internal risk management — and modern cyber attacks commonly target backup infrastructure, backup administration and recovery dependencies before production encryption begins.

54%

Only 54% of organisations affected by a cyber attack used backups to restore data in 2025 (Sophos State of cyber attacks 2025).

6 yrs

That restore rate is the lowest in six years — a sign that backup confidence does not always translate into recovery.

1st

Backup infrastructure, backup administration and recovery dependencies are commonly targeted first, before production encryption begins.

Dated

Cyber insurance, audit, governance and internal risk conversations increasingly expect dated artefacts, not verbal confidence about backup posture.

Sophos State of cyber attacks 2025Inlight IT engagement record
What changed for the client

The division gained a clearer backup and recovery position

The engagement helped the division move from backup confidence toward a more structured understanding of recovery readiness, evidence quality and improvement priorities.

O·01

Backup architecture became clearer

The division gained a more structured view of how backup architecture supported recovery and where further validation or improvement was required.

O·02

Immutability came into focus

Immutable backup was considered as a recovery resilience control, not simply a product feature or configuration label.

O·03

Restore evidence was better understood

Restore evidence, documentation and recovery assumptions could be reviewed against the need for a defensible recovery position.

O·04

Administrative access joined the recovery discussion

Backup admin access, MFA, credential separation and privileged access considerations were connected to recovery resilience.

O·05

Microsoft 365 recovery assumptions were surfaced

Cloud and Microsoft 365 recovery considerations could be reviewed as part of the broader backup posture.

O·06

Remediation became easier to sequence

Findings and improvement areas could be grouped into practical remediation priorities.

Net position

The value was not only reviewing backup configuration. It was clarifying whether backup architecture, access control and evidence quality could support a stronger recovery position.

Project outcomes

A recovery posture judged by what it actually protects

Outcome 01

Scoped divisional engagement

The case relates to a single division, not the full organisation.

Outcome 02

Architecture reviewed

Backup coverage, recovery pathway and supportability considered together.

Outcome 03

Recovery resilience assessed

Immutable backup principles reviewed as part of recovery posture.

Outcome 04

Restore position clarified

Restore evidence and documentation considered as part of recoverability.

Outcome 05

Cloud data considered

Microsoft 365 and cloud recovery assumptions included where relevant.

Outcome 06

Improvement path prioritised

Findings translated into practical remediation priorities.

Technology and service scope

The work connected backup architecture, recovery resilience and restore evidence

Backup architecture

6
  • Backup architecture review
  • Backup and disaster recovery
  • Backup retention considerations
  • Coverage and recovery scope
  • Repository considerations
  • Recovery-path visibility

Recovery resilience

6
  • Immutable backup architecture
  • Recovery resilience review
  • WORM and Object Lock considerations
  • Retention lock considerations
  • Backup admin MFA review
  • Credential separation considerations

Evidence and recoverability

6
  • Restore evidence review
  • Recovery documentation review
  • Recovery validation considerations
  • Evidence gap identification
  • Critical data and service recovery
  • Restore-path considerations

Cloud and remediation

6
  • Microsoft 365 backup considerations
  • Cloud data recovery review
  • SharePoint, OneDrive and email recovery
  • Cloud retention assumptions
  • Remediation prioritisation
  • Future review pathway
Practical next step

Can your backup architecture support a defensible recovery position?

We test whether your backups actually recover, then strengthen the evidence behind them.

Discuss Backup & Disaster Recovery