Skip to main content
When the backups are gone too

When the backups are gone too

Why recovery, not prevention, is the decisive test of public sector cyber resilience

10 Nov 2026 12:00 PM - 1:00 PM AEDT
Webinar

Proudly supported by

Proudly supported logo

Strategic context

Organisations once considered low-value targets, including councils, universities and not-for-profits, are now squarely in scope. AI-enabled tooling has cut the time to orchestrate an attack from weeks to days or minutes. The assumption that an inability to pay ransoms offers protection no longer holds. Australia's major banks have shown the direction of travel: layered security, with recovery treated as a first-order control rather than a fallback. Yet many public sector organisations still rely on backup arrangements, in the cloud and on premises, that restore slowly, share the same exposure, and remain untested at scale. Where data retention is a legislated obligation, the risk is not only operational. The question leaders face is not whether an incident happens, but how quickly and completely they can restore operations when it does.

Key discussion points

Separate prevention from recovery: Treating recoverability as a distinct capability, with its own controls and assurance, changes where security investment delivers measurable resilience.

Make recovery immutable and automated: Regular, tamper-proof snapshots held apart from the production environment let teams restore volumes immediately once a threat is cleared, rather than rebuild over weeks.

Detect at the data layer: Systems that spot attack behaviour inside storage itself can trigger protective copies while an incident unfolds, shrinking the window between compromise and containment.

Reassess the cost equation: Rising cloud storage costs and longer hardware lifecycles are shifting the economics of where critical data sits and how long infrastructure investment holds value.

Who should attend

This session is for senior leaders in local government, state government, education and the not-for-profit sector who hold responsibility for data protection, infrastructure and operational continuity, particularly those balancing legislated retention obligations against constrained budgets.

Sign up or Log in to Public Sector Network to register for this event

Why Attend?

Stress-test your recovery position

You will be able to assess whether your organisation could restore operations after a data-loss event, and identify where current backup arrangements would fail.

Make defensible investment decisions

You will be better able to justify resilience spending to your executive and audit committee, using recovery time and recovery point as the measures that matter.

Clarify executive accountability

You will leave with a sharper view of who owns recovery outcomes across IT, finance and executive leadership, and what assurance each should expect.

Questions?

See our FAQs or get in touch

Ready to register?

Registration is free for government