Rand Water Cyberattack: Could Your Business Keep Operating?
A recent cyberattack against Rand Water has given South African businesses a very practical lesson in disaster recovery. Rand Water disclosed that attackers had penetrated parts of its network and damaged servers. Importantly, its core water operations continued, while affected treasury services were transferred to a disaster-recovery environment. The organisation’s debt officer indicated that without […]
A recent cyberattack against Rand Water has given South African businesses a very practical lesson in disaster recovery.
Rand Water disclosed that attackers had penetrated parts of its network and damaged servers. Importantly, its core water operations continued, while affected treasury services were transferred to a disaster-recovery environment. The organisation’s debt officer indicated that without its disaster-recovery site, the situation would have been far more serious.
The incident has not publicly been confirmed as ransomware, and the precise entry point and extent of any data exposure remain under investigation. Nevertheless, it demonstrates an important principle: preventing every cyberattack is unrealistic, but preventing an attack from stopping the entire business is achievable.
A backup is not automatically a recovery plan
Many small and medium-sized businesses believe they are protected because someone copies files to an external drive or because documents are stored in OneDrive.
Those measures can help, but they do not answer the most important question: how will the business continue operating if its server, computers, Microsoft 365 accounts or administrative credentials become unavailable?
A complete recovery capability should address:
- Where business-critical information is stored
- Whether backup copies are isolated from the main environment
- How quickly information can be restored
- Who has access to administrator accounts and recovery keys
- How staff will communicate during an outage
- Which systems must be restored first
- Whether the recovery process has actually been tested
Cloud storage and synchronisation should not be confused with independent backup. If a compromised account deletes or encrypts synchronised data, those changes may be carried into the cloud environment.
Recovery time matters
A business may technically have a backup but still face several days of downtime while someone finds equipment, downloads data and rebuilds systems.
This is why businesses should define a recovery time objective: the maximum acceptable period before a critical service must be operational again.
An accounting practice may need access to email, client documents and its accounting platform within hours. A retailer may prioritise point-of-sale systems, supplier information and internet connectivity. A professional-services company may regard Microsoft 365 identities and SharePoint files as its first recovery priorities.
The correct plan depends on how the business works—not merely on how much data it owns.
Five questions every SME should answer
Business owners should be able to answer these questions confidently:
- When was our last successful backup?
- When was a full restore last tested?
- Could an attacker delete both the live data and its backup?
- Who can recover our Microsoft 365 tenant if the main administrator is compromised?
- How would we continue working tomorrow if our server or cloud accounts were unavailable?
If the answers are uncertain, the business has a continuity risk.
Turn backup into business resilience
The lesson from the Rand Water incident is not that every SME needs an expensive secondary data centre. It is that recovery must be designed before an emergency.
For smaller businesses, an effective solution may combine managed cloud backup, an isolated secondary copy, Microsoft 365 backup, documented administrator access, replacement-device planning and scheduled restore tests.
RandTech IT helps South African businesses assess their existing backups, identify recovery gaps and build continuity plans that fit their size and budget.
Do not wait for a cyberattack to discover whether your backup works. Arrange a business continuity and recovery assessment before the next incident becomes your incident.


