An Australian professional services organisation reviewed backup architecture and recovery evidence through a cyber attack-resilience lens
For this engagement, the division operates in a professional services environment where technology supports users, client work, document workflows, Microsoft 365, data access, operational continuity and assurance expectations. Inlight IT supported a single division — not an entire national organisation. The work focused on backup architecture, recoverability, evidence quality, immutability considerations and actionable recovery resilience.
The requirement was not simply to confirm that backups were running. The division needed a clearer view of whether backup architecture, restore evidence, administrative access and recovery assumptions could support a defensible recovery position. The outcome was a more structured backup and recovery view — what was protected, where evidence existed, which recovery assumptions needed validation and which improvement areas should be prioritised.
- Client
- Australian professional services organisation
- Scope clarification
- A single division — not the broader organisation
- Industry
- Professional services
- Starting point
- Backups configured and running, without a clear view of whether the recovery path could survive cyber incident conditions or support scrutiny
- Engagement type
- Backup architecture and recovery readiness review, conducted at a controlled level
- Focus
- Review backup architecture and recovery evidence to clarify recoverability, resilience and improvement priorities
- Outcome
- A clearer backup and recovery position, with evidence quality, immutability considerations, administrative access and remediation priorities identified at a controlled level
An Australian professional services organisation — backup architecture and recovery readiness review
A controlled-scope review of whether backup architecture, access and evidence could support a defensible recovery position.
One division, one review, a clearer recovery position
The engagement supported a single division — not an entire national organisation.
Backup architecture, immutability and resilience, restore evidence, Microsoft 365 and cloud recovery, and remediation priorities.
Findings separated quick-win remediation from longer-term improvement so the division could act in a practical sequence.
Microsoft 365 backup implications, SharePoint, OneDrive and email recovery awareness included in the review.
A backup report says jobs are running — a recovery position shows whether the business can restore what matters
For professional services environments, backup and recovery are tied to continuity, client work, Microsoft 365, document access, data governance, cyber insurance, assurance and operational confidence.
The question is no longer only whether a backup product is configured. The useful question is whether the recovery path can survive cyber incident conditions and whether the evidence is strong enough to support internal and external scrutiny.
For the division, Inlight IT's role was to review backup and recovery posture at a controlled level — architecture, restore evidence, immutability, administrative access, recovery assumptions and practical remediation priorities. This engagement supports a single division and is not a whole-of-organisation case study.
The division needed a clearer recovery position, not only confirmation that backups existed
Backup confidence can be misleading when the recovery path has not been tested against cyber incident conditions. Modern cyber attacks can target backup systems, identity, privileged access and dependencies before production systems are encrypted.
Backup operation did not automatically prove recoverability
A successful backup job does not prove that the right systems, data and dependencies can be restored in the right order. The review needed to look beyond job status and consider recovery pathway, restore evidence and whether the backup position could support real operational recovery.
Immutability needed architectural validation
A backup is genuinely immutable when it cannot be altered, encrypted or deleted during the retention period, even by an account with administrator-level credentials. The engagement needed to consider immutability as architecture, not as a label attached to a backup product.
Backup administration and privileged access mattered
Backup admin access is a critical recovery control. If the same credentials or administrative pathways can reach production and backup systems, a destructive cyber event may compromise the recovery path. The review needed to consider administrative access, MFA, credential separation and the practical exposure of backup management.
Restore evidence needed to support the recovery position
Restore testing changes the conversation from assumption to evidence. Without dated restore evidence, the organisation may know backups are configured but not whether recovery would work under pressure. The review needed to identify where evidence existed and where further validation would improve confidence.
Improvement priorities needed practical sequencing
Backup architecture reviews often identify several improvement areas at once: retention, immutability, Microsoft 365 backup, administrator access, restore testing, documentation and operational ownership. The output needed to separate urgent remediation from longer-term improvement so the division could act in a practical sequence.
A backup architecture engagement focused on recoverability, immutability, evidence and sequenced remediation
Inlight IT reviewed the backup and recovery posture through a recovery resilience lens. The engagement considered not only whether backups existed, but whether the recovery architecture could support a defensible recovery position.
01Backup architecture review
Backup architecture, coverage, retention, access model, repository considerations and recovery dependencies were reviewed at a controlled level, with recovery scope, workload and data coverage, operational ownership and recovery-path visibility considered together.
02Immutability and recovery resilience review
The backup position was reviewed through a cyber attack lens — whether the architecture aligned with immutable backup principles, from storage-layer protection to backup admin access and credential separation.
03Restore evidence and recoverability review
The engagement considered whether restore evidence, recovery documentation and operational processes could support the backup and recovery position, including critical data and service recovery awareness and evidence gap identification.
04Microsoft 365 and cloud recovery considerations
For professional services environments, Microsoft 365 data often sits at the centre of day-to-day work. The engagement considered Microsoft 365 backup implications, cloud retention assumptions and the identity, access and ownership dependencies behind cloud recovery.
05Remediation priorities and roadmap
Findings were translated into sequenced improvement areas — which gaps or weaknesses should be addressed first and which improvements could be sequenced into a remediation pathway.
Five stages, sequenced from architecture to evidence to remediation
Select a stage to trace how the review moved from scope to sequenced remediation.
Backup architecture is now part of cyber assurance, not only IT operations
Professional services environments hold commercially sensitive work, client files, correspondence, documents, Microsoft 365 data and internal operational information. Backup and recovery posture affects continuity, client confidence, insurance conversations and internal risk management — and modern cyber attacks commonly target backup infrastructure, backup administration and recovery dependencies before production encryption begins.
Only 54% of organisations affected by a cyber attack used backups to restore data in 2025 (Sophos State of cyber attacks 2025).
That restore rate is the lowest in six years — a sign that backup confidence does not always translate into recovery.
Backup infrastructure, backup administration and recovery dependencies are commonly targeted first, before production encryption begins.
Cyber insurance, audit, governance and internal risk conversations increasingly expect dated artefacts, not verbal confidence about backup posture.
The division gained a clearer backup and recovery position
The engagement helped the division move from backup confidence toward a more structured understanding of recovery readiness, evidence quality and improvement priorities.
Backup architecture became clearer
The division gained a more structured view of how backup architecture supported recovery and where further validation or improvement was required.
Immutability came into focus
Immutable backup was considered as a recovery resilience control, not simply a product feature or configuration label.
Restore evidence was better understood
Restore evidence, documentation and recovery assumptions could be reviewed against the need for a defensible recovery position.
Administrative access joined the recovery discussion
Backup admin access, MFA, credential separation and privileged access considerations were connected to recovery resilience.
Microsoft 365 recovery assumptions were surfaced
Cloud and Microsoft 365 recovery considerations could be reviewed as part of the broader backup posture.
Remediation became easier to sequence
Findings and improvement areas could be grouped into practical remediation priorities.
The value was not only reviewing backup configuration. It was clarifying whether backup architecture, access control and evidence quality could support a stronger recovery position.
A recovery posture judged by what it actually protects
Scoped divisional engagement
The case relates to a single division, not the full organisation.
Architecture reviewed
Backup coverage, recovery pathway and supportability considered together.
Recovery resilience assessed
Immutable backup principles reviewed as part of recovery posture.
Restore position clarified
Restore evidence and documentation considered as part of recoverability.
Cloud data considered
Microsoft 365 and cloud recovery assumptions included where relevant.
Improvement path prioritised
Findings translated into practical remediation priorities.
The work connected backup architecture, recovery resilience and restore evidence
Backup architecture
6- Backup architecture review
- Backup and disaster recovery
- Backup retention considerations
- Coverage and recovery scope
- Repository considerations
- Recovery-path visibility
Recovery resilience
6- Immutable backup architecture
- Recovery resilience review
- WORM and Object Lock considerations
- Retention lock considerations
- Backup admin MFA review
- Credential separation considerations
Evidence and recoverability
6- Restore evidence review
- Recovery documentation review
- Recovery validation considerations
- Evidence gap identification
- Critical data and service recovery
- Restore-path considerations
Cloud and remediation
6- Microsoft 365 backup considerations
- Cloud data recovery review
- SharePoint, OneDrive and email recovery
- Cloud retention assumptions
- Remediation prioritisation
- Future review pathway
Can your backup architecture support a defensible recovery position?
We test whether your backups actually recover, then strengthen the evidence behind them.
Discuss Backup & Disaster Recovery