Consulting Module

Module 7 โ€” Recovery & Resilience

The most common recovery lie in the industry: 'we have backups.' Having a backup is not the same as being able to recover. This module replaces the assumption with a tested, documented, and rehearsed capability โ€” so when the incident happens, recovery is a procedure, not an improvisation.

What It Delivers

๐Ÿ”

Backup Architecture Review

Current backup coverage assessed for every workload: M365 data, on-premises systems, cloud VMs, and critical databases. The gaps that consistently appear โ€” M365 data that employees believe Microsoft backs up but that has no independent point-in-time backup, backup systems reachable from the same network as production, backup credentials stored in the same password manager as everything else โ€” are found and documented before an attacker finds them first.

๐Ÿงฑ

Immutable Backup Deployment

Immutable, off-network backup deployed for critical workloads. Ransomware operators delete or encrypt backups before they hit production โ€” a backup reachable from the compromised estate is not a backup. Immutability ensures the backup cannot be modified or deleted even by a fully compromised admin account.

๐Ÿ“–

Disaster Recovery Runbooks

Step-by-step recovery procedures written for every critical workload โ€” including the scenarios nobody documents: AD forest recovery, M365 tenant configuration restore, and cloud infrastructure rebuild from ASTRAL baseline. Each runbook is tested, not just written. A runbook that has never been executed is a hypothesis.

๐ŸŽฏ

Tabletop Exercise

A structured scenario walkthrough โ€” typically a ransomware incident or identity compromise โ€” run with the actual response team. Gaps in communication, decision authority, and technical procedure surface in a tabletop, not in a live incident. Every gap found in the exercise is a gap not found under pressure.

๐Ÿ”€

ASTRAL Baseline as Rebuild Blueprint

The ASTRAL Git repository โ€” capturing your M365 and Intune configuration โ€” becomes your authoritative rebuild baseline. After a catastrophic configuration failure or tenant compromise, "what do we restore to?" has a deterministic answer. The restore pipeline applies the known-good state without manual reconstruction from memory.

The Antifragile Recovery Principle

A robust organisation survives an incident and comes back the same. An antifragile one comes back different โ€” with a shorter kill chain, a tested runbook it now knows works, and one more scenario it has rehearsed. Every incident that runs through this module’s feedback loop makes the next one cheaper. The tabletop is not a compliance checkbox; it is the cheapest incident you will ever have.

Scope and Prerequisites

Duration30โ€“60 days
EnvironmentM365 and/or on-premises
PrerequisitesASTRAL deployed (Module 1 or 3) for the configuration baseline; inventory of critical workloads
Natural follow-onModule 11 (Blue/Purple Team) to build the detection capability that feeds the recovery loop

Know you can recover before you need to

An untested backup is simultaneously fine and worthless. Module 7 tells you which one yours is โ€” before the incident does.