Coverage
Confirm which information, users, devices, applications and locations are protected, retained or excluded.
Backups matter only when the right information can be restored by authorized people within a timeframe the business can tolerate. CyberTECT independently reviews coverage, recovery responsibilities and selected restore paths so owners can see what is proven, what is assumed and what still depends on one person or provider.
Backup systems can report that copies were created while important mailboxes, SharePoint sites, local files, applications or vendor-hosted records remain outside the policy. Recovery validation follows the complete path from business information to usable restoration, including access, authorization, timing and provider involvement.
Confirm which information, users, devices, applications and locations are protected, retained or excluded.
Identify who can request, approve and complete recovery when the usual administrator or provider is unavailable.
Validate a selected recovery path and record whether the restored information is accessible, complete and usable.
Statistics Canada’s 2023 survey covers businesses with 10 or more employees across most economic sectors. These figures provide national context and are not a prediction of what will happen to an individual organization.
of Canadian businesses reported being impacted by cyber security incidents in 2023.
was spent by Canadian businesses recovering from cyber security incidents in 2023, double the 2021 total.
of impacted businesses reported ransomware attacks in 2023.
The scope is matched to the organization. It can include Microsoft 365, local devices, servers, websites, accounting records, practice-management systems and other critical services identified during the validation.
Exchange email, OneDrive, SharePoint, local files, accounting records, websites and agreed line-of-business data.
Schedules, protected users and sites, retention periods, storage locations, exclusions and policy changes.
How much recent data loss is tolerable, how quickly priority work must resume and which systems come first.
Administrator roles, recovery permissions, approval requirements, credentials and alternate authorized contacts.
What the business, IT provider, cloud platform and backup supplier each operate, monitor and support.
Separation, restricted access, encryption, offline or isolated copies and protection against deletion or alteration.
Microsoft 365 is designed with substantial platform resilience and geographic redundancy. Organizations still need to decide whether dedicated backup is required, which Exchange accounts, SharePoint sites and OneDrive accounts are protected, who controls recovery and whether the restore workflow supports business needs.
The validation method is chosen around the system, business impact and available permissions. Some engagements use a selected file, folder, mailbox or alternate-location restore. Higher-impact tests require additional planning and provider coordination.
Your IT/MSP may operate the platform: your IT company, Microsoft partner, cloud provider or backup supplier may configure and monitor the underlying service.
Your organization makes the business decisions: you determine what information is critical, how much data loss is acceptable, who can authorize recovery and how long priority work can remain unavailable.
CyberTECT validates the recovery picture: CyberTECT clarifies responsibilities, reviews available evidence and validates selected recovery paths with your organization and IT/MSP.
Critical information, systems, protection methods, retention and known exclusions.
Business owners, administrators, providers, approvers and recovery contacts.
Observed RPO, RTO and maximum tolerable downtime assumptions for priority operations.
Scope, date, result, elapsed time, limitations and confirmation of usability.
Coverage gaps, access issues, provider dependencies and recommended corrections.
A plain-language record of what is proven, what remains conditional and what should be retested.
The service is designed for rural and small Ontario businesses, professional offices, law and real-estate practices, municipal and community organizations, Microsoft 365-dependent teams and businesses that rely heavily on an outsourced provider or one knowledgeable administrator.
Where downtime, missing files or unavailable email can quickly stop sales, service and administration.
Where client information, confidentiality and specialized systems make recovery time-sensitive.
Where limited local support, vendor distance and small teams can increase recovery dependency.
The focused Control Check covers backup testing, approved storage, continuity, recovery records and leadership oversight.
CyberTECT provides: coverage and responsibility review, coordinated representative testing, documented evidence and practical follow-up.
The result remains conditional: systems, providers, configurations, data and threats change. Recovery capability must be monitored and revalidated.
Higher-impact testing is separately planned: complete failover, production cutover and complex application recovery require explicit authorization, technical coordination and an agreed test plan.
The goal is a realistic, repeatable recovery path, not a dramatic test that creates avoidable operational risk.
Coverage depends on the service, configuration, retention settings and any separate backup product. The validation establishes what is actually protected and what remains excluded.
It is a controlled recovery of selected business data, such as an email, file or folder, chosen to verify the expected recovery path without disrupting normal operations.
Usually, with the organization’s authorization and suitable cooperation from the provider. The scope records who performs each step and what evidence is available.
No. A test provides evidence that a defined recovery path worked at a particular time. Coverage, monitoring and testing must remain current as systems and data change.
The public list is intentionally selective. These sources cover recovery objectives, backup practices, small-business controls, Microsoft 365 recovery and cybersecurity event recovery.
Review the systems, people and providers your business would depend on before an outage, account compromise or ransomware incident forces the question.
CyberTECT periodically reviews Canadian cybersecurity guidance, Microsoft documentation and recovery standards. References are updated when material guidance or platform changes are identified.