Subnet Blog

Cyber Resilience in Aged Care: Protecting Systems, Supporting Care

Written by Ben Luks | 5 August 2026, 04:05:50 Z

Cybersecurity conversations within aged care have traditionally focused on prevention—deploying security controls, reducing vulnerabilities and defending against an ever-evolving threat landscape.

While prevention remains essential, many IT leaders are shifting their attention towards a broader objective: cyber resilience. The question is no longer simply: "Can we prevent every cyber attack?" It's: "How quickly can we recover while continuing to support safe resident care?"

As digital transformation accelerates across the aged care sector, technology has become fundamental to delivering quality care. Microsoft 365 has become the collaboration platform of choice for many providers, while cloud-based care management platforms, medication systems, identity services and digital documentation underpin almost every aspect of daily operations.

When these systems become unavailable, cybersecurity quickly becomes an operational issue.

A Different Way to Think About Cybersecurity

Consider this scenario. It's 6:00 am on a Monday morning. Staff begin reporting they can't access Microsoft 365. Email has stopped working. Microsoft Teams is unavailable. SharePoint document libraries are inaccessible. Clinicians are unable to retrieve critical documentation, while resident management systems begin experiencing widespread disruption.

The incident response plan is activated. The first question is: Which services must be restored first to ensure residents continue receiving safe, uninterrupted care?

For experienced IT teams, this is where cyber resilience begins. Recovery priorities, communication plans and business continuity become just as important as the technical controls designed to prevent the incident in the first place.

Prevention Will Always Matter—But Recovery Defines Resilience

Modern Microsoft environments provide an impressive range of security capabilities. Combined with security monitoring, vulnerability management and frameworks such as the Australian Cyber Security Centre's Essential Eight, these technologies significantly reduce organisational risk.

However, even mature organisations recognise that no security strategy can eliminate risk entirely. Cyber resilience acknowledges this reality.

Rather than assuming every attack can be prevented, resilient organisations invest equally in their ability to detect incidents quickly, contain threats effectively and recover critical services with minimal disruption.

Recoverability Is Becoming the New Measure of Resilience

Many organisations measure how well they're protected. Far fewer measure how recoverable they are. Recoverability isn't simply about having backups. It's the confidence that systems, applications and data can be restored quickly enough to support operational priorities when an incident occurs.

For aged care providers, that means asking questions such as:

  • Can we recover resident documentation within our target recovery time?
  • How quickly can Microsoft 365 services be restored?
  • Which systems are essential for safe resident care?
  • Have we validated that our recovery plans actually work?

Cyber resilience isn't ultimately measured by how many attacks are blocked. It's measured by how effectively an organisation can recover.

 

As per the above diagram, while each layer delivers value independently, true cyber resilience comes from integrating them into a cohesive strategy. Security technologies help reduce risk. Monitoring enables rapid detection. Modern backup platforms—including immutable backups—provide confidence that critical systems can be recovered. Business continuity planning ensures the organisation can continue supporting residents throughout the recovery process. Together, these layers strengthen an organisation's most valuable capability: Recoverability.

Recovery Is More Than Restoring Data

One of the biggest misconceptions surrounding Microsoft 365 is that because it's hosted in the cloud, comprehensive backup and recovery are automatically taken care of.

While Microsoft provides exceptional platform availability, organisations remain responsible for protecting and recovering their own data. Accidental deletion, insider threats, ransomware and malicious activity can all result in the loss or corruption of critical business information.

For organisations responsible for sensitive resident information and operational records, relying solely on native retention capabilities may not align with organisational recovery objectives.

This is why many organisations extend their Microsoft environments with dedicated data protection platforms such as Veeam Backup for Microsoft 365, providing greater control over how Exchange Online, SharePoint, OneDrive and Microsoft Teams data is protected and restored.

The objective isn't simply to have backups. It's to have confidence that critical information can be recovered quickly, accurately and with minimal disruption to resident care.

Modern Backup Strategies Have Evolved

Backup strategies have changed significantly over the past decade. Traditional backups were designed to recover from hardware failures or accidental file deletion.

Today's cyber threats require organisations to assume that backup infrastructure itself may become a target. As a result, modern cyber resilience strategies increasingly include:

  • Microsoft 365 data protection.
  • Immutable backup repositories that prevent backup data from being modified or deleted.
  • Isolated backup environments designed to reduce the impact of ransomware.
  • Automated backup verification and recovery testing.
  • Strong encryption and privileged access controls.
  • Clearly defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

Immutable backups have become particularly important in defending against ransomware. By ensuring backup data cannot be altered or encrypted during a defined retention period, organisations gain greater confidence that clean recovery points remain available when they're needed most.

Technology alone, however, isn't enough. The real value comes from regularly validating that recovery processes work as expected.

Resilience Means Testing Recovery—Not Just Creating Backups

Creating backups is only one part of a resilient recovery strategy. The more important question is whether those backups have been tested. Leading IT teams are increasingly asking:

  • Can we recover Microsoft 365 workloads within our agreed RTO?
  • Can we restore a SharePoint site, Exchange mailbox or Teams workspace without affecting production?
  • Are immutable backup repositories protected from privileged account compromise?
  • How long would it take to restore our core clinical systems?
  • When did we last complete a full disaster recovery exercise?

Five Questions Every Aged Care IT Leader Should Consider

Cyber resilience is an ongoing journey rather than a destination. These five questions provide a useful framework for discussion.

1. Have we identified which systems are truly critical to resident care?

Recovery priorities should reflect operational impact—not simply technical complexity.

2. When did we last complete a full recovery exercise?

Testing validates people, processes and technology—not just backup jobs.

3. Are our data protection strategies designed for modern cyber threats?

Do we have independent protection for Microsoft 365? Are our backup repositories immutable? Have recovery processes been tested recently?

4. Can we achieve our recovery objectives?

Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) should be defined, regularly reviewed and aligned with operational expectations.

5. Is recoverability understood beyond the IT department?

The strongest technical response can still falter if executive teams and operational leaders haven't rehearsed their role in a major cyber incident.

How Subnet Can Help

Building cyber resilience requires more than deploying technology—it requires aligning people, processes and platforms.

At Subnet, we help organisations across South Australia strengthen every layer of their resilience strategy. From Microsoft security and identity services through to Microsoft 365 data protection, Veeam-powered backup and replication, immutable storage and disaster recovery planning, we work with organisations to build environments that are resilient by design.

Whether you're reviewing your Microsoft security posture, modernising your backup strategy, implementing immutable backups or validating your disaster recovery capabilities, our team can help you strengthen your organisation's recoverability and support continuity of care.