Backup & Disaster Recovery
If your files were encrypted tonight, how much work would you lose, and how long would you be shut? GravIT sets up backups that answer both questions honestly (on site, off site, in Microsoft 365, and with immutable copies that ransomware cannot delete), then tests the restores, because a backup nobody has restored from is a hope rather than a plan.
The one most businesses get wrong
Microsoft 365 is not backed up. Microsoft keeps the service running and available, and that is all they promise. Getting your data back after someone empties a mailbox, a departing staff member takes a SharePoint site with them, or ransomware syncs its way through OneDrive is your responsibility, and the built-in retention windows are shorter than people expect.
It is the single most common gap we find, and the cheapest to close.
What we back up
- Microsoft 365. Mail, files, SharePoint and Teams, on a proper retention schedule.
- Servers and files. Local backup for fast restores, so a deleted folder is a five-minute job.
- Off-site replication. A second copy somewhere a fire, a flood or a burglar cannot reach, held in Australia.
- Tested, not assumed. We monitor that backups complete, and restores are verified automatically on a schedule rather than sampled once a year.
Immutable backups: the copy nobody can delete
Ransomware stopped being a smash-and-grab years ago. The crews that matter get in quietly, look around for days or weeks, and go after the backups first, because a business that can restore does not pay, and a business that cannot restore pays whatever it is told. By the time anything is encrypted, the escape route has usually already been destroyed.
An immutable backup is the answer to that. Once a copy is written, it cannot be altered or deleted until its retention period expires, whether the request comes from ransomware, a stolen administrator password or a departing employee having a bad day. We cannot delete it either, and that last one is the part worth pausing on, because an administrator credential is exactly what an attacker steals. If your IT provider can delete your backups, then so can whoever gets into your IT provider.
It is enforced by the storage itself rather than by a permission somebody can switch off, which is what makes it different from a folder marked read-only or an account with the delete button hidden.
The honest limits
- Immutable is not the same as tested. It guarantees the copy still exists, not that it restores. Those are different promises and you want both, which is why we still restore from backups rather than just watching the jobs go green.
- The retention window has to outlast the intruder. If someone sat in your network quietly for two months and your locked copies only go back a fortnight, the last clean one has already aged out. We set the window against how long an intrusion realistically goes unnoticed, not against what is cheapest.
- It costs more, and it is meant to. You cannot clear space early even when you want to. That inflexibility is the feature; if you can delete it in a hurry, so can someone else.
The old rule was three copies, on two kinds of media, with one off site. The version that survives a modern ransomware event adds one more: at least one copy that cannot be changed. It is also what the ACSC Essential Eight is driving at when it asks whether someone with your credentials could destroy your backups, rather than simply whether you have them.
Seven years of restore points
Up to seven years. That means seven years of restore points you can actually go back to and pull a specific day out of, rather than seven years of the last version of a file.
That number is not arbitrary. Most Australian businesses have records obligations measured in years rather than weeks: the ATO wants five for most records, and a fair few industries, funders and insurers want seven. A backup that only reaches back thirty days is a good answer to “someone deleted the folder” and no answer at all to “we need the file as it stood in 2021”.
Two things about that worth knowing, because they are the parts that usually cost people money elsewhere:
- Keeping more history does not cost more. It is priced per machine rather than per gigabyte, so the bill does not creep upward every year as the archive grows. You are not choosing between affordability and being able to go back.
- An old restore point comes back as fast as a recent one. There is no long chain of increments to walk back through, which is where traditional backups get slow and fragile the further back you reach, and where a single corrupt link can quietly take out everything behind it.
Proving it works before you need it
“The backup ran” and “the backup works” are different sentences, and the gap between them is where businesses discover they have been backing up nothing useful for eight months. Watching a job go green tells you a job went green.
- Restores are tested automatically, on a schedule. Backups are started up and checked that they actually boot and are readable, routinely and with the evidence kept, rather than sampled once a year when someone remembers.
- A ready-to-start copy of your servers. Rather than beginning a rebuild from scratch on your worst day, there is already a standby copy waiting to be switched on. That is the difference between being down for a day and being down for a week.
- Restore the whole thing, or one file. A full system, a database, an application, or the single spreadsheet somebody overwrote at 4pm. Most real restores are the last one, and it should not require a project.
- Encrypted the whole way. AES-256 in transit and at rest, with the data held in Australia.
Backup sized to the downtime you can wear
That is the question that sets the price, and it is worth answering deliberately. A business that can work off paper for a day needs something very different from a clinic that stops the moment its system does. We size the backup to the answer instead of selling you the biggest one.
What's included
- Microsoft 365 backup
- Server and file backup
- Off-site replication in Australia
- Immutable copies: undeletable, including by us
- Up to 7 years of restore points
- Retention that does not cost more as it grows
- Monitored daily
- Restores tested automatically, not annually
- Full system, database or single file
- AES-256, held in Australia
Frequently asked questions
Doesn't Microsoft 365 back itself up?
Not in the way people assume. Microsoft protects the platform and keeps it available; recovering your data after a deletion, a departing staff member or a ransomware event is your side of the bargain. Retention windows are short and unforgiving.
How fast could we be back up?
That depends on what broke and what you're willing to spend, which is exactly the conversation worth having before it happens rather than during. We size the backup to the downtime you can actually tolerate.
Do you test the backups?
Yes. Monitoring that a job completed is not the same as knowing the data comes back, so we restore from them.
What's the difference between backup and disaster recovery?
Backup is having a copy. Disaster recovery is how quickly you can work again. A business that can wear two days offline needs a very different setup from one that can't wear two hours, and the price difference is real.
Where are the backups kept?
On-site for fast restores plus an off-site copy in Australia for the day the office itself is the problem, encrypted with AES-256 in transit and at rest.
How long do you keep backups for?
Up to seven years of restore points, and points you can actually go back into rather than seven years of the latest version. That covers the five years the ATO expects for most records and the seven that some industries, funders and insurers ask for. Because it is priced per machine rather than per gigabyte, keeping more history does not make the bill creep up each year.
Are old backups slower to restore from?
No. There is no long chain of increments to walk back through, so a restore point from three years ago comes back the same way as one from last night. That matters more than it sounds: chained backups are exactly where traditional systems get slow and fragile the further back you reach, and where one corrupt link can quietly take out everything behind it.
What is an immutable backup, and do we need one?
It is a copy that cannot be altered or deleted until its retention period runs out, whether the request comes from ransomware, a stolen administrator account, or from us. You need one because modern ransomware goes after the backups before it encrypts anything: a business that can restore does not pay. If your current backup can be deleted by whoever holds the admin password, it is one compromised credential away from being no backup at all.
If backups are immutable, can we still delete data we should not be keeping?
Not from a locked copy before its retention period expires. That is the whole point of it, and it is worth knowing before you turn it on rather than after. It is a real consideration if you have privacy or records obligations that require deletion, so we set the retention window deliberately rather than as long as possible, and we will talk it through with you first.
Test your backup before you need it
If the honest answer is "never", that is the thing worth fixing this month.