Every business backs up something. Far fewer could say how long it would take to get working again if the office server died this morning, or if ransomware encrypted everything it could reach. This guide covers how backup and disaster recovery fit together, what good looks like in 2026 and how to test that yours would work.
The short answer
Keep three copies of your data on two kinds of storage, with one offsite and one that cannot be deleted, agree how quickly each system must be back, and test a restore every quarter. Backups you have never restored from are a hope, not a plan.
Backup, disaster recovery and business continuity
The three terms are often used as if they mean the same thing. They do not.
| What it is | The question it answers | |
|---|---|---|
| Backup | A copy of your data, kept somewhere safe | Do we still have the data? |
| Disaster recovery | The plan and tools for restoring systems from backup | How quickly can we get IT running again? |
| Business continuity | The plan for keeping the business working while IT is restored | How do we keep trading in the meantime? |
Disaster recovery is the IT part of business continuity. Our business continuity plan template covers the rest: people, premises, suppliers and communication.
Two numbers that decide everything
Recovery point objective (RPO) is how much data you can afford to lose, measured in time. If you back up nightly, a failure at 4pm loses the day’s work, so your RPO is up to 24 hours.
Recovery time objective (RTO) is how quickly a system must be working again. If invoicing can stop for a day but the phones cannot stop for an hour, those systems need different recovery setups.
Agree both numbers for each important system with the people who run that part of the business, then check your backups can meet them. The most common gap we find is a business that assumes a three hour recovery when a full restore of its server would take three days.
The 3-2-1 rule, and what to add
- Three copies of your data: the live copy and at least two backups.
- Two types of storage, so one failure cannot take out both, for example a local backup device and cloud storage.
- One copy offsite, so a fire, flood or theft at the office does not take your backups with it.
- One copy that cannot be changed, often called an immutable backup. Ransomware now looks for backups and tries to delete them first, so at least one copy must be locked against deletion for a set period.
What to back up
- Servers, whole, so you can restore the server and not only the files on it.
- Microsoft 365: email, OneDrive, SharePoint and Teams. Microsoft keeps deleted items for a limited time, which is not the same as a backup you control.
- Line of business systems, including cloud ones. Check what the vendor backs up, how long it keeps it and how you would get a copy of your data out.
- Settings for firewalls, switches and phone systems, which take days to rebuild from memory.
- Laptops, if staff save work locally. Better still, move that work into OneDrive or SharePoint, which is then covered by the Microsoft 365 backup.
What the Essential Eight expects
Regular backups are one of the eight strategies in ASD’s Essential Eight. At Maturity Level One, backups of data, applications and settings are taken and kept according to how critical they are, synchronised so everything can be restored to the same point in time, and stored in a secure and resilient way. Restores are tested as part of disaster recovery exercises, and everyday user accounts cannot see, change or delete other people’s backups. Our Essential Eight checklist turns each requirement into a yes or no question.
Disaster recovery options
| Option | How it works | Typical recovery time | Suits |
|---|---|---|---|
| Restore from backup | Rebuild the system, then restore data from the backup | Hours to days, depending on size | Systems the business can do without for a day or two |
| Local recovery | Start the backed up server on a backup device in the office | Minutes to hours | A failed server, when the office itself is fine |
| Recovery in a data centre | Start copies of your servers in a data centre and connect staff to them | Minutes to hours | Critical servers, and a closed or damaged office |
| Cloud first systems | Move the workload to Microsoft 365 or a cloud server, so there is no office server to lose | Depends on the provider | Most businesses, over time |
A disaster recovery plan in six steps
- List your systems and agree the RPO and RTO for each.
- Match each system to a backup and recovery method that meets those numbers.
- Write down the restore order: sign in and identity first, then email and phones, then the systems each critical function needs.
- Record who does what, how to reach them after hours and where the recovery instructions are kept, including a copy offline.
- Test a restore every quarter and run a full walkthrough once a year.
- Review the plan after any incident, office move, new system or change of IT provider.
Testing: the step most businesses skip
A backup job that reports success every night tells you the job ran. It does not tell you the data can be restored, that the restore will finish in time or that the person doing it knows how. A useful test restores a real system, times it and records the result. Keep the records: insurers, auditors and Essential Eight assessors all ask for them.
Where Austin Technology fits
We run backup and disaster recovery for businesses of 10 to 500 staff, with immutable copies, Microsoft 365 backup and restores tested on a schedule. See cloud backup and recovery and business continuity and disaster recovery, read why managed backups beat do it yourself backups, or call us on 1300 787 429.
Backup and recovery questions
What is the difference between backup and disaster recovery?
A backup is a copy of your data. Disaster recovery is the plan and the tools for getting your systems running again from that copy, within a time the business can live with. You can have backups and still have no way to recover quickly.
What is the 3-2-1 backup rule?
Keep at least three copies of your data, on two different types of storage, with one copy offsite. Many businesses now add a fourth rule: one copy that cannot be changed or deleted, so ransomware cannot reach it.
Does Microsoft back up Microsoft 365?
Microsoft keeps your data available and keeps deleted items for a limited time, but that is not the same as a backup you control. A separate Microsoft 365 backup protects you from ransomware, a departing staff member deleting files or a mistake nobody notices for months.
How often should we back up?
As often as the data changes and as much as you can afford to lose. For most businesses that means Microsoft 365 several times a day and servers at least nightly. Your recovery point objective sets the number.
How often should we test a restore?
At least every quarter, and after any change to your servers or backup system. The Essential Eight asks for restores to be tested as part of disaster recovery exercises.
Is cloud backup enough on its own?
Cloud backup covers the offsite copy. You still need to know how long a full restore takes over your internet connection. For large servers, a local copy or a recovery environment in a data centre is often what makes the recovery time work.


