Recovery objectives that hold under pressure.
Most continuity plans are written once and never tested. This outcome makes recovery a live capability: objectives agreed, systems mapped, and restore procedures rehearsed on a cadence the business signs off.
Agree
Recovery time and recovery point objectives, signed off by the business.
Protect
Backup across servers, endpoints and Microsoft 365, managed daily.
Rehearse
Restores tested on a schedule, with results reported to leadership.

RTO / RPO
Objectives agreed with the business, not assumed by IT.
Live restores
Real recovery tests, not tabletop walkthroughs.
Full coverage
Servers, endpoints and Microsoft 365 in one managed service.
Reported
Test results and gaps reach the leadership team every quarter.
Most continuity plans fail on the day they are needed, not the day they are written.
Written once, never tested
A plan approved two years ago describes systems and people that have since changed.
Backups nobody has restored
Jobs report success for years. The first real restore attempt is the first genuine test.
Undocumented dependencies
One line-of-business application quietly depends on a server, a licence or a person nobody listed.
Assumed cloud protection
Teams assume Microsoft 365 is backed up. Retention is not backup, and deletion is permanent.
The standard the outcome is held to.
Recovery objectives are signed off, not assumed. Critical systems and their dependencies are mapped. Restores are rehearsed on a schedule and the results reach the leadership team. Personnel change; the continuity capability does not.
- Recovery time and recovery point objectives agreed at executive level.
- Critical systems mapped, dependencies documented.
- Backup and restore tested on a defined schedule, not on incident day.
- A continuity playbook that survives changes in personnel.
A rehearsed sequence, not a bespoke project.
Assess and map
Critical systems, data and the dependencies between them.
Agree objectives
Recovery time and recovery point targets, approved by the business.
Protect
Managed backup across servers, endpoints and Microsoft 365.
Rehearse
Scheduled restore tests against the agreed objectives.
Report and revise
Results, gaps and playbook updates reviewed with leadership.
Coverage scales with the NumataOne service tier.
Each tier includes everything in the one before it.
Core
Managed backup for servers and Microsoft 365, with monitored job success and an annual restore test.
Standard
Adds endpoint coverage, documented recovery objectives and half-yearly restore testing by system.
Premium
Adds dependency mapping, a maintained continuity playbook and quarterly restore tests with executive reporting.
Enterprise
Adds scenario rehearsals, named escalation paths and continuity evidence prepared for audit or diligence.
What leadership can review, and when.
- Objectives approved and current.
- Restore-test results by system.
- Continuity playbook version history.
- Incident timeline and lessons learned.
Nobody is judged on the plan. They are judged on how long the business was down, and whether anyone could say when it would be back.
Questions leadership teams ask.
What is the difference between RTO and RPO?
Recovery time objective is how long the business can accept a system being unavailable. Recovery point objective is how much data the business can accept losing, measured in time. Both are business decisions, not technical ones, and both should be signed off by leadership.
Is Microsoft 365 already backed up by Microsoft?
No. Microsoft protects the platform and offers limited retention, but it does not provide point-in-time recovery of your data after deletion, ransomware or a departed user. A separate managed backup for Exchange, SharePoint, OneDrive and Teams is required.
How often should restores be tested?
At minimum annually for every critical system, and quarterly for the systems the business cannot operate without. Testing frequency should follow business impact, not the size of the environment.
What does a restore test actually involve?
Recovering a defined system or dataset into an isolated environment, timing the recovery against the agreed objective, verifying the data is usable, and recording the result. Anything less is a report, not a test.
How long does it take to get continuity under control?
A baseline assessment and dependency map typically completes inside the first quarter, with protection in place alongside it. The first full restore-test cycle and leadership report follows in the quarter after.
