Category: Cloud & Backup

  • How Social Engineering Turns a Trusted Identity Into Payment Fraud

    How Social Engineering Turns a Trusted Identity Into Payment Fraud

    The most dangerous part of an online scam is often not the technology. It is the relationship the criminal constructs before asking for money or information.

    On 11 September 2026, Reuters reported that South Africa had agreed to extradite six alleged members of the Black Axe network to the United States. US authorities accuse them of wire fraud and money laundering connected to online romance scams that allegedly defrauded more than 100 victims. The accusations will still need to be tested through the legal process. Reuters’ report provides the case details.

    Romance scams and business payment fraud are not identical. The useful connection is the method: establish credibility, control communication, create urgency and convert trust into a transaction.

    A believable identity is not proof

    Criminals can assemble a persuasive profile from public websites, social media and leaked data. They may know a director’s name, the company’s suppliers and which employee processes payments.

    They can also compromise a real mailbox or messaging account. A message coming from the correct address therefore does not always mean the legitimate owner sent it.

    Staff should judge high-risk requests through an agreed process, not through confidence in the sender’s writing style or profile photograph.

    Slow down the transaction

    Social engineering often uses urgency: a payment must happen before close of business, the supplier’s bank account has suddenly changed, or an executive is “in a meeting” and cannot take a call.

    The business needs rules that remain in force when someone applies pressure. Require independent verification for:

    • New or changed banking details
    • Unusual payment destinations
    • Confidential payroll or customer records
    • MFA codes or login approvals
    • Requests to install remote-access software
    • Exceptions to normal approval limits

    Do not verify using the phone number supplied in the suspicious message. Use a trusted number already recorded in the accounting system, contract or official directory.

    Separate request, approval and payment

    Where practical, one person should not be able to receive a request, change supplier details and release the payment alone. Dual approval creates a second opportunity to notice an inconsistency.

    Record who confirmed the change, which number was called and when approval occurred. A clear audit trail helps staff follow the rule consistently rather than relying on memory.

    Protect the communication accounts

    Process controls work best with secure accounts. Enable multifactor authentication, use separate administrator accounts, remove former employees promptly and investigate unexpected forwarding rules or login alerts.

    Train employees to report mistakes immediately. If someone approved a suspicious login or sent information, a fast report gives administrators a better chance to revoke sessions and limit damage. Punishing the first person who reports a mistake teaches everyone else to hide the next incident.

    Respond quickly to suspected fraud

    Contact the bank immediately through an official channel, preserve messages and transaction information, and involve the IT provider to check whether email or other accounts were compromised. Obtain appropriate legal, insurance and law-enforcement guidance for the circumstances.

    RandTech IT helps South African SMEs secure Microsoft 365, investigate suspicious access and implement practical security-awareness procedures. Trust is essential to business, but payments and confidential data need verification that does not depend on trust alone.

  • Cloud Services Still Need a Business Continuity Plan

    Cloud Services Still Need a Business Continuity Plan

    The debate concerns national infrastructure and development policy, but it also highlights a simpler lesson for small businesses: “it is in the cloud” does not mean every dependency has disappeared.

    The Associated Press reported on 5 September that South Africa hosts a substantial portion of Africa’s data-centre capacity and that campaigners are challenging further hyperscale expansion. Reuters had previously reported approval and objections around proposed Equinix facilities in Cape Town on 28 July 2026.

    For an SME in Johannesburg, the immediate risk is usually not the hyperscale facility. It is the fibre line, router, office power, DNS, user account or laptop between the employee and the service.

    Map the full chain

    Ask what is required for staff to open email, process an order or help a customer.

    The chain may include:

    • Electricity to the office and network cabinet
    • Fibre or fixed-wireless connectivity
    • Router, firewall, switches and Wi-Fi access points
    • Microsoft 365 or another cloud provider
    • Multifactor authentication on an employee’s phone
    • A working, updated laptop
    • Access to files and passwords

    A highly resilient cloud platform cannot compensate for a router that switches off two minutes into an outage.

    Add connectivity failover carefully

    An LTE or 5G connection can keep essential users online when fibre fails, but only if it is configured and tested in advance. Confirm signal quality, data limits, network coverage and whether the router changes connections automatically.

    Failover should prioritise essential services. A software update or cloud backup can consume mobile data while accounts staff are trying to process payments. Appropriate firewall and traffic rules can preserve the link for email, voice and critical applications.

    Size backup power for the network

    Keeping laptops charged does not help when the fibre terminal, router and switch have no power. Identify every network component that must remain on, measure its load and set a realistic runtime objective.

    A UPS battery also degrades. Test it under load and replace it based on condition, not merely age or a green indicator light.

    Prepare a degraded way of working

    Business continuity is not always full restoration. It may mean allowing a smaller group to continue essential work while the main connection is repaired.

    Document who needs priority access, which phone hotspot may be used, how incoming calls are handled, and which files can be securely available offline. Avoid copying uncontrolled customer data onto personal devices as an emergency shortcut.

    Test the plan

    Disconnect the primary internet connection during a controlled window and observe what happens. Can users still authenticate? Does Teams calling work? Can the business reach cloud accounting and retrieve key documents? Record the gaps and repeat the test after remediation.

    RandTech IT helps Johannesburg businesses design and test internet failover, office-network UPS protection and Microsoft 365 continuity. The cloud removes many local server risks, but resilience still depends on the last kilometre—and on a plan that has been proved before the outage.

  • Why a Slow PC May Need an SSD, Not Replacement

    Why a Slow PC May Need an SSD, Not Replacement

    Why a Slow PC May Need an SSD, Not Replacement

    A computer that takes several minutes to start, freezes while opening applications and becomes unresponsive during updates may appear to have reached the end of its life.

    In many cases, the real bottleneck is an old mechanical hard drive.

    Replacing that drive with a solid-state drive can dramatically improve startup times, application loading and everyday responsiveness. For a suitable computer, an SSD upgrade can provide several more years of useful service at a fraction of the cost of replacement.

    Why traditional hard drives feel slow

    A mechanical hard disk stores information on spinning platters and uses a moving read-and-write head to access it. This design works well for inexpensive bulk storage, but it is relatively slow when Windows needs to access thousands of small files.

    A solid-state drive has no moving parts. It can retrieve information far more quickly, which is particularly noticeable when:

    • Windows starts
    • Outlook opens
    • Applications launch
    • Updates install
    • Files are searched
    • Several tasks run simultaneously

    An SSD will not turn every old PC into a high-performance workstation, but it can remove one of the most common performance bottlenecks.

    Signs the hard drive may be the problem

    Possible indicators include:

    • Disk usage repeatedly reaching 100%
    • Extremely slow startup
    • Delays when opening folders
    • Freezing during Windows updates
    • Clicking or unusual mechanical sounds
    • File errors or corrupted data
    • Applications becoming unresponsive while the disk is busy

    A failing hard drive is more than a performance problem. It can also become a data-recovery emergency, so unusual sounds and file errors should be investigated promptly.

    When an SSD upgrade makes sense

    An upgrade is usually worth considering when:

    • The processor still meets the user’s needs
    • The computer has enough RAM or can be upgraded
    • The motherboard, screen and hinges are healthy
    • The machine supports the required operating system
    • The total upgrade cost is well below replacement cost
    • The device is otherwise reliable

    A good-quality business laptop with an older hard drive may be a better upgrade candidate than a low-cost new laptop with weaker construction.

    When an SSD will not solve the problem

    Storage is only one component.

    An SSD cannot repair a damaged motherboard, overheating processor, broken hinge or unsuitable amount of RAM. It also cannot make an unsupported computer appropriate for critical business use indefinitely.

    Before approving an upgrade, a technician should evaluate the complete device, including:

    • Drive health
    • RAM usage
    • Processor performance
    • Cooling system
    • Battery condition
    • Windows compatibility
    • Physical condition
    • Backup status

    This prevents customers from spending money on one improvement when several expensive repairs are approaching.

    Cloning versus a clean installation

    An existing hard drive can sometimes be cloned onto the SSD, preserving Windows, applications and settings. This is convenient when the current installation is healthy.

    A clean Windows installation may be preferable when the old system contains corruption, unwanted software or years of accumulated problems. User data must be backed up and verified before either process begins.

    The correct method depends on the condition of the original drive and the customer’s software requirements.

    Diagnose before replacing

    PC Warehouse and RandTech IT provide computer diagnostics, SSD upgrades, data migration and replacement advice in Randburg and Johannesburg.

    We assess the complete machine and explain whether repair, upgrade or replacement offers the best value. If the device is worth saving, an SSD can be one of the most noticeable upgrades available.

    Before replacing a frustratingly slow computer, have it tested. The machine may not be finished—it may simply be waiting for its slowest component to be replaced.

  • How Often Should a Business Test Its Backups?

    How Often Should a Business Test Its Backups?

    How Often Should a Business Test Its Backups?

    A business should test important file restores at least quarterly and conduct a broader recovery exercise at least once a year. Higher-risk businesses may need monthly restore tests and more frequent disaster-recovery exercises.

    There is no universal schedule for every organisation. The correct frequency depends on how quickly information changes, how costly downtime would be and whether the business handles regulated or highly sensitive data.

    The central principle is simple: a successful backup notification does not prove that the business can recover.

    Why backups fail when they are needed

    A backup job may display a green status while still failing to protect the information the business considers critical.

    Common problems include:

    • Important folders were never selected
    • A new server or SharePoint site was not added
    • Backup credentials expired
    • Storage reached its capacity
    • Files were already corrupted before being copied
    • The backup is encrypted by the same ransomware
    • Nobody knows the recovery password
    • Restore instructions are outdated
    • The available internet connection is too slow for timely recovery

    These problems are often discovered only when someone urgently needs the data.

    Use more than one type of test

    Backup testing should happen at several levels.

    Monthly automated review

    An IT provider should review failed jobs, warnings, storage capacity and devices that have stopped reporting. This is monitoring rather than a complete recovery test, but it catches obvious problems early.

    Quarterly sample restores

    Restore several representative items, such as:

    • An email
    • A OneDrive folder
    • A SharePoint document
    • An accounting-data file
    • A folder from a server
    • Data belonging to a former employee

    Confirm that the restored information opens correctly and that its permissions and dates are usable.

    Annual recovery exercise

    At least once a year, simulate a more serious outage. Assume a server, primary storage system or Microsoft 365 administrator account is unavailable.

    Measure how long it takes to rebuild access and restore priority services. The exercise should expose unclear responsibilities, missing passwords and unrealistic recovery expectations.

    Businesses that cannot tolerate several hours of downtime should test more frequently.

    Define what must return first

    Not every file has the same operational value.

    An architectural practice may prioritise active project files. A brokerage may need client records, policy documents and email. A retailer may need point-of-sale data and supplier information.

    Your recovery plan should identify:

    • The most critical systems
    • The order in which they must be restored
    • The maximum acceptable data loss
    • The maximum acceptable downtime
    • Who can authorise a recovery
    • Where passwords and encryption keys are stored
    • How staff will work during the outage

    A test should measure performance against these requirements.

    Test Microsoft 365 as well

    Many SMEs back up a local server but overlook Exchange Online, OneDrive, SharePoint and Teams.

    Microsoft provides resilient infrastructure and native recovery tools, but businesses should understand their configuration and recovery limits. Independent Microsoft 365 backup can provide another recovery layer, particularly where deletion or compromise is discovered late.

    Testing should include the restoration of individual cloud files, folders and emails.

    Record and improve every test

    Document what was restored, how long it took and which problems occurred. Assign corrective actions and repeat failed tests.

    RandTech IT helps South African businesses implement monitored backups, test Microsoft 365 and local-data recovery, and create practical disaster-recovery plans.

    If your business has never completed a recorded restore test, you do not yet know whether you have a working backup. Schedule the test before a real emergency sets the deadline for you.

    Source: CISA’s ransomware and backup guidance

  • Is Microsoft Defender Enough for a Small Business?

    Is Microsoft Defender Enough for a Small Business?

    Is Microsoft Defender Enough for a Small Business?

    Microsoft Defender Antivirus is included with modern Windows computers and provides credible protection against many common threats. For a home user or a very small business with basic requirements, that makes it a useful security foundation.

    The important word, however, is foundation.

    Cybersecurity involves far more than scanning downloaded files for viruses. A business must also protect email accounts, administrator credentials, cloud data, remote access, backups and the devices employees use outside the office.

    Microsoft Defender Antivirus can form part of that protection, but the free built-in component should not be mistaken for a complete managed security service.

    What Microsoft Defender Antivirus does

    The antivirus component built into Windows can detect and block many forms of malware, suspicious files and potentially unwanted applications. It receives threat-intelligence and security updates through Microsoft.

    It also works with Windows security features such as:

    • Firewall protection
    • SmartScreen reputation checks
    • Tamper protection
    • Controlled folder access
    • Cloud-delivered protection
    • Secure Boot
    • Device encryption and BitLocker

    The effectiveness of these controls depends on whether they are enabled, correctly configured and monitored.

    A security feature that has been disabled for six months provides little protection, even if its icon still appears in Windows.

    Antivirus cannot solve every security problem

    Many modern attacks do not begin with a traditional virus.

    A criminal may steal a Microsoft 365 password through a fake login page, convince an employee to approve an MFA request or compromise a supplier’s genuine email account. An accounts employee could then receive a convincing request to pay an invoice into a different bank account.

    Antivirus may have nothing malicious to scan in these situations.

    It also cannot independently ensure that:

    • Backups are completing successfully
    • Deleted Microsoft 365 data can be restored
    • Former employees no longer have access
    • Shared administrator passwords have been eliminated
    • Suspicious mailbox-forwarding rules are detected
    • Computers receive patches on time
    • Staff verify payment-detail changes
    • An incident-response plan exists

    These protections require additional technology, configuration and human procedures.

    Defender Antivirus and Defender for Business are different

    Microsoft uses the Defender name across several products, which can cause confusion.

    Microsoft Defender Antivirus is the endpoint antivirus included with Windows. Microsoft Defender for Business adds business-focused endpoint detection, investigation and management capabilities and is included with certain Microsoft 365 subscriptions or available separately.

    A managed endpoint platform can provide central visibility across company computers. It helps an IT provider identify vulnerable devices, investigate alerts and respond when suspicious behaviour appears.

    Simply seeing “Microsoft Defender is on” does not establish that the device is centrally monitored.

    Small businesses need layered protection

    A sensible SME security baseline should include:

    • Centrally managed endpoint protection
    • Multifactor authentication
    • Separate administrator accounts
    • Microsoft 365 security monitoring
    • Prompt Windows and application patching
    • Independent backups
    • Regular recovery testing
    • Email and phishing controls
    • Staff awareness training
    • A documented incident-response process

    The correct combination depends on the business’s information, regulatory responsibilities and tolerance for downtime.

    Start with an assessment

    Installing multiple security products without a plan can cause conflicts while leaving important gaps untouched.

    RandTech IT helps South African SMEs assess Microsoft Defender, Microsoft 365, endpoints, backups and identity controls. We can determine whether built-in protection is appropriate, whether Defender for Business or another managed endpoint platform is required, and which security gaps need priority.

    Microsoft Defender is a strong starting point. For a business holding customer information and relying on its computers every day, it should be one part of a monitored, layered security strategy—not the entire strategy.

    Source: Microsoft Defender for Business documentation

  • What to Do After a Ransomware Attack: An SME Response Guide

    What to Do After a Ransomware Attack: An SME Response Guide

    What to Do After a Ransomware Attack: An SME Response Guide

    A ransomware incident rarely begins with a dramatic message appearing on every screen. The first warning may be a user unable to open a document, a shared folder containing strangely renamed files or a computer suddenly running unusual processes.

    What happens during the next hour can determine whether the incident affects one computer or spreads across the business.

    South African SMEs should have a simple ransomware response plan that employees and decision-makers can follow without improvising under pressure.

    1. Isolate affected devices

    Disconnect a suspected computer from wired and wireless networks as quickly as possible. Remove its network cable or disable Wi-Fi, but do not immediately erase, reset or reinstall it.

    If several devices show similar symptoms, disconnect affected network segments and shared storage where practical. The objective is to limit further encryption, data theft and movement between computers.

    Do not continue opening files to test whether they work. Every additional action may spread damage or overwrite useful evidence.

    2. Contact your IT and security provider

    Treat the event as a security incident rather than an ordinary computer fault.

    Your provider needs to determine:

    • Which users and devices are affected
    • Whether administrator credentials may be compromised
    • Whether files are still being encrypted
    • Whether Microsoft 365 or other cloud accounts were accessed
    • Whether data may have been stolen
    • Whether backups remain safe
    • How the attacker gained access

    Modern ransomware incidents may include data theft before encryption. Restoring files alone does not establish that the threat has been removed.

    3. Protect identities and administrative access

    If account compromise is suspected, passwords and sessions may need to be reset from a known-clean device. Administrative accounts, remote-access tools, VPN credentials and Microsoft 365 access should receive priority.

    Simply changing one employee’s password may be insufficient. Attackers sometimes create forwarding rules, add authentication methods or establish alternative accounts that allow them to return.

    Security changes should be coordinated carefully so the response team does not accidentally lose access to essential evidence or recovery systems.

    4. Preserve evidence

    Keep affected devices, ransom notes, suspicious emails, timestamps and security logs. Take photographs or screenshots where appropriate, but do not interact unnecessarily with malicious files.

    Evidence can help establish the entry point, scope of the incident and whether personal information was affected. This may also be important for cyber-insurance claims, regulatory obligations and law-enforcement reporting.

    Where personal information may have been compromised, the business should obtain appropriate POPIA and legal guidance regarding notification requirements.

    5. Verify backups before restoring

    Do not reconnect backup drives or begin restoring data until the environment has been assessed.

    A backup connected too early could also be encrypted or contaminated. The recovery team should confirm that the backup predates the attack, remains isolated and can be restored into a clean environment.

    Recovery should follow business priorities. Email, accounting, customer records and operational systems may need to be restored in a planned sequence.

    Should a business pay the ransom?

    Paying does not guarantee that criminals will provide a working decryption key, delete stolen information or avoid attacking again. Payment may also create legal, ethical and insurance complications.

    This decision should not be made impulsively. Obtain specialist incident-response, legal and insurance advice based on the exact circumstances.

    Prepare before the attack

    The best time to decide who disconnects systems, contacts the insurer and authorises recovery is before ransomware is discovered.

    RandTech IT helps SMEs implement managed endpoint protection, Microsoft 365 security, independent backups and tested incident-response procedures.

    If you suspect ransomware, stop using the affected device, disconnect it from the network and contact professional support immediately. Fast containment is far less expensive than allowing a single compromised computer to become a business-wide outage.

    Source: CISA StopRansomware Guide

  • Why Your Business Still Needs Microsoft 365 Backup

    Why Your Business Still Needs Microsoft 365 Backup

    Why Your Business Still Needs Microsoft 365 Backup

    Microsoft 365 stores business email, documents, Teams information and SharePoint data in highly resilient cloud infrastructure. That often creates the impression that everything in Microsoft 365 is automatically backed up forever.

    It is not quite that simple.

    Microsoft protects the availability and operation of its cloud platform, while your business remains responsible for how its users, administrators and connected applications handle company information. Deleted data may be recoverable for a limited period, but Microsoft 365 retention features should not automatically be treated as a complete independent backup system.

    Cloud storage and backup are different

    OneDrive synchronises files between a user’s computer and the cloud. SharePoint gives teams a central place to store and collaborate on documents. Exchange Online keeps business email accessible across devices.

    These services are built for productivity and availability. Backup has a different purpose: maintaining a separate recoverable copy of data in case the live information becomes unavailable, corrupted or deliberately removed.

    If a user deletes a synchronised folder, the deletion may be reflected across the environment. If an attacker compromises an administrator account, they may attempt to delete data or weaken retention settings. Malware can also encrypt files before the damaged versions synchronise to OneDrive or SharePoint.

    Microsoft 365 includes recycle bins, version history and retention capabilities, but each feature has rules, limits and configuration requirements.

    Common ways businesses lose Microsoft 365 data

    Data loss is not always caused by Microsoft suffering a major outage. More common causes include:

    • A staff member accidentally deleting a mailbox or folder
    • An employee leaving before important information is transferred
    • A compromised account deleting or manipulating data
    • Incorrect SharePoint permissions exposing files
    • Malware encrypting synchronised documents
    • An administrator changing a retention policy
    • A third-party application corrupting or deleting information
    • The business discovering a loss after the recovery window has passed

    A backup becomes particularly valuable when nobody notices the problem immediately.

    What should be protected?

    A Microsoft 365 backup strategy should account for the services the business actually uses. This may include:

    • Exchange Online mailboxes
    • Shared mailboxes
    • OneDrive accounts
    • SharePoint sites and document libraries
    • Teams files and associated SharePoint data
    • Contacts and calendars

    The system should also make it possible to restore individual items. Recovering one deleted email or folder should not require rebuilding an entire environment.

    Retention and backup solve different problems

    Retention policies are important for governance, compliance and controlling how long information is kept. They can help prevent permanent deletion during a defined retention period.

    Independent backup provides another recovery layer. It can preserve separate copies, offer longer recovery histories and reduce dependence on the state of the live Microsoft 365 tenant.

    Many businesses benefit from using both. Retention helps govern information inside Microsoft 365, while backup provides an additional route to recovery.

    A backup must be tested

    A dashboard showing successful backup jobs is reassuring, but it does not prove that the correct data can be restored quickly.

    Businesses should periodically test:

    • Restoring an individual email
    • Recovering a OneDrive folder
    • Restoring a SharePoint document and its previous version
    • Recovering data belonging to a former employee
    • Confirming who is authorised to initiate a restore
    • Measuring how long recovery takes

    These tests turn backup from a subscription into an operational recovery capability.

    RandTech IT helps South African businesses assess Microsoft 365 retention, implement independent cloud backup and test the recovery of Exchange, OneDrive and SharePoint information.

    Your data may be in Microsoft’s cloud, but it is still your business’s responsibility. A properly configured and tested backup ensures that one mistake, compromised account or late discovery does not become permanent data loss.

    Source: Microsoft 365 Backup documentation

  • AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    Artificial intelligence is not only helping businesses automate work. It is also helping cybercriminals create convincing scams, analyse targets and launch attacks more efficiently.

    INTERPOL’s 2026 African Cyberthreat Assessment reports that artificial intelligence was involved in 55% of reported cybercrime across Africa. The assessment also identifies South Africa as a particularly significant ransomware target, accounting for 92% of detections in the African dataset cited by the report.

    These figures do not mean that 92% of every ransomware attack in Africa occurred in South Africa. They come from a specific threat-detection dataset. They do, however, reinforce what local businesses are already experiencing: South Africa is an attractive and active target.

    How criminals use AI

    Traditional phishing emails were often easy to identify because of poor grammar, strange wording or an obviously incorrect company logo.

    Generative AI can now produce polished emails that imitate the tone of a supplier, manager or colleague. Criminals can use information from company websites, social media profiles and leaked databases to create messages that feel relevant to the recipient.

    AI may help attackers:

    • Write convincing phishing messages
    • Translate scams into natural local language
    • Generate or modify malicious code
    • Analyse stolen information more quickly
    • Impersonate executives or suppliers
    • Automate reconnaissance against exposed systems
    • Produce fake voices, documents or payment instructions

    A small criminal operation can consequently target more businesses without employing a large technical team.

    Why SMEs are attractive targets

    Many business owners assume that criminals are interested only in banks, government departments and major corporations. In reality, SMEs frequently combine valuable information with weaker protection.

    A smaller business may hold customer identity documents, banking information, contracts, payroll records and access to larger customers or suppliers. At the same time, it may rely on a single administrator, basic antivirus and backups that have never been tested.

    Automated attacks do not need to know the company personally. They scan for weak passwords, exposed remote access, outdated websites, unpatched computers and compromised Microsoft 365 accounts.

    MFA is essential—but it is not the whole solution

    Multifactor authentication remains one of the most important protections a business can deploy. However, modern attackers also use fake login approval requests, stolen browser sessions, malicious email rules and social engineering.

    Effective SME protection should therefore include several layers:

    • MFA on all business accounts
    • Separate, protected administrator accounts
    • Endpoint security on every computer
    • Prompt Windows and application patching
    • Email filtering and domain protection
    • Independent Microsoft 365 and server backups
    • Regular restore testing
    • Monitoring for suspicious logins and forwarding rules
    • Staff training using current scam examples

    No individual security product can compensate for missing backups, excessive permissions or an administrator account shared by several people.

    What business owners should do now

    Start with a short security review rather than buying random products. Identify where company data resides, who has administrative access, whether departed employees still have access and whether the business could recover from a compromised account.

    Staff should also be given a clear verification rule: unexpected requests involving payments, bank-detail changes, passwords or confidential documents must be confirmed through a second communication channel.

    AI is increasing the speed and quality of cybercrime, but businesses are not powerless. Strong identity controls, managed protection, tested recovery and alert employees still stop many attacks.

    RandTech IT helps South African SMEs assess Microsoft 365, endpoints, backups and recovery readiness. A practical cybersecurity review can reveal the gaps before an attacker finds them.

    Source: INTERPOL’s 2026 African Cyberthreat Assessment announcement

  • Microsoft 365 Backup Retention Explained for SA SMEs

    Microsoft 365 Backup Retention Explained for SA SMEs

    Introduction

    Understanding Microsoft 365 backup retention explained is essential for South African small and medium-sized businesses. Many organisations assume Microsoft fully protects their data, but the reality is more nuanced. This article explains what Microsoft covers, common gaps, recommended retention strategies for SMEs, and practical steps you can take in Gauteng and across South Africa to reduce risk and meet compliance needs.

    What Microsoft 365 covers — and what it doesn’t

    Microsoft provides a range of built-in data protection features across Exchange Online, SharePoint, OneDrive and Teams. These include versioning, retention policies, and basic recovery options. However, Microsoft’s shared responsibility model means customers retain responsibility for long-term retention, point-in-time recovery, and protecting against accidental deletion, malware and insider threats.

    Included features

    • Version history for files in OneDrive and SharePoint.
    • Recycle Bin retention for deleted items (limited timeframes).
    • Retention labels and policies for compliance scenarios.
    • Basic restore tools for administrators.

    Common gaps to be aware of

    • Microsoft is not a true backup provider — point-in-time restores beyond the retention windows can be difficult.
    • Deleted items may be purged after the recycle bin period, making recovery impossible without backups.
    • Ransomware and mass-deletion attacks can propagate through connected services.
    • Regulatory or contractual retention requirements may exceed Microsoft’s default settings.

    Key retention concepts explained

    To make sensible retention decisions, SMEs should understand a few core concepts:

    Retention policies vs backups

    Retention policies prevent deletion or preserve data for a set period to meet compliance needs. Backups create independent copies that allow point-in-time restores even if original items are modified or removed.

    Versioning and point-in-time recovery

    Versioning keeps prior versions of files, but it is not a substitute for backup because versions can be removed or become impractical for large-scale recovery.

    Retention periods

    Retention periods should reflect legal, tax and operational requirements. In South Africa, businesses may need to retain financial records or employment documents for several years — often longer than Microsoft’s default windows.

    Practical retention strategies for South African SMEs

    Apply a layered approach combining Microsoft capabilities with independent backups to achieve resilience and compliance.

    1. Assess legal and operational requirements

    • Identify documents and mailboxes that require long-term retention (e.g., tax records, contracts).
    • Confirm retention durations dictated by SARS, labour regulations or industry rules.

    2. Configure Microsoft 365 retention and labels

    • Use retention labels to classify content and apply minimum retention and deletion rules.
    • Apply policies to SharePoint sites, OneDrive accounts and Exchange mailboxes where appropriate.

    3. Implement third-party backups

    Choose a backup solution that offers:

    • Automated, scheduled backups of Exchange, SharePoint, OneDrive and Teams.
    • Point-in-time restore capability and long-term archival storage.
    • Encryption in transit and at rest, with reliable role-based access for restores.

    4. Define retention tiers and storage locations

    • Short-term tier: quick restores for operational continuity (days to months).
    • Long-term tier: archival storage for compliance (years). Consider on-prem or local region cloud storage for data sovereignty concerns.

    5. Test restore procedures regularly

    Backups are only useful if restores work. Schedule regular restore tests to validate procedures, timing and data integrity.

    Cost considerations for SMEs in South Africa

    Budget realistically. Backup costs vary by provider, retention period and storage class. For many SMEs the goal is to balance affordability with risk tolerance. Factor in:

    • Monthly subscription fees for backup software or services.
    • Storage costs for long-term archives.
    • Internal time to manage and test backups.

    Discuss options with your IT partner to compare local versus international storage, and any implications for data access speeds and compliance.

    Checklist: Implementing a robust Microsoft 365 retention plan

    1. Audit current Microsoft 365 settings and data types.
    2. Map legal and business retention requirements.
    3. Apply retention labels and policies where possible.
    4. Deploy an independent backup solution for point-in-time recovery.
    5. Define retention tiers and archival locations.
    6. Test restores quarterly and after major changes.
    7. Document procedures and assign responsibilities.

    FAQs

    Do I need a separate backup if I use Microsoft 365?

    Yes. Microsoft protects platform availability and provides some data retention tools, but it does not replace dedicated backups for long-term retention or comprehensive point-in-time recovery.

    How long does Microsoft keep deleted Exchange items?

    Retention for deleted items depends on mailbox settings and retention policies. Default recycle bins are time-limited and may not meet all compliance needs, so verify and extend retention where required.

    Can I meet SARS or labour retention rules with Microsoft retention policies?

    Possibly, but you should confirm that applied retention periods and auditability match statutory requirements. Independent backups provide stronger assurance for long-term legal holds.

    Is local (South African) storage necessary?

    Local storage can help address data sovereignty concerns and may reduce latency. Whether it’s necessary depends on your industry, contractual obligations and risk appetite.

    How often should I test restores?

    Test restores at least quarterly, and after any significant change to your environment or backup configuration.

    Conclusion

    Microsoft 365 backup retention explained shows that while Microsoft provides useful tools, SMEs must take active responsibility for long-term retention and recoverability. By combining retention policies with independent backups, clearly defined retention tiers, and regular restore testing, South African businesses can minimise risk and meet compliance requirements without disrupting operations.

    If you’d like practical help implementing or reviewing your Microsoft 365 retention and backup strategy, contact RandTech IT. Our experienced engineers provide fast, effective support so you get reliable protection without learning on your time.

  • Backup vs Business Continuity: What’s the Difference?

    Backup vs Business Continuity: What’s the Difference?

    Introduction

    Many South African small and medium-sized businesses use the terms “backup” and “business continuity” interchangeably. That can be costly. While both aim to protect data and keep operations running, they serve different purposes and require different planning. This article explains the difference, why each matters for SMBs in South Africa, and practical steps you can take to reduce downtime and recover quickly.

    What is a Backup?

    A backup is a copy of data or systems stored separately so you can recover information after data loss. Backups protect against accidental deletion, hardware failure, ransomware, or corruption.

    Common backup types

    • Full backups: Complete copy of selected data. Simple to restore but storage-intensive.
    • Incremental backups: Only changes since the last backup. Saves storage and time but can lengthen restores.
    • Differential backups: Changes since the last full backup. A middle ground between full and incremental.
    • Image-based backups: Capture entire system images, useful for quick server or workstation restoration.
    • Cloud backups: Offsite copies held by providers—scalable and often faster to deploy.

    What backups achieve

    • Restore lost files and databases.
    • Recover after ransomware (if backups are clean and isolated).
    • Meet compliance and retention requirements.

    What is Business Continuity?

    Business continuity (BC) is a broader discipline that ensures critical business functions continue during and after a disruptive event. It combines people, processes, technology and communication plans so your organisation can operate at an acceptable level while full recovery takes place.

    Key components of business continuity

    • Business Impact Analysis (BIA): Identifies critical processes and acceptable downtime.
    • Continuity strategies: Alternate work arrangements, redundant systems, and supplier contingency plans.
    • Communication plans: How you notify staff, customers and suppliers during incidents.
    • Testing and exercises: Regular drills to ensure procedures work in practice.

    What business continuity achieves

    • Maintains customer service and revenue streams during incidents.
    • Reduces the operational impact of disasters, power outages or cyberattacks.
    • Protects reputation by demonstrating resilience and preparedness.

    Backup vs Business Continuity: Side-by-side

    Think of backups as one essential tool inside a business continuity toolbox. Backups restore data; business continuity keeps the business running. Comparing them directly highlights their distinct roles.

    Focus

    • Backups: Data and systems recovery.
    • Business continuity: Operational resilience and process continuity.

    Recovery time objective (RTO) and recovery point objective (RPO)

    RTO and RPO are central to both planning disciplines but are applied differently:

    • RPO (how much data you can lose): Set backup frequency to meet RPO.
    • RTO (how long you can be down): Guides continuity strategies, such as failover systems or temporary workarounds.

    Cost and complexity

    Backups alone are usually less complex and cheaper to implement. Comprehensive business continuity often requires additional investment—redundant connectivity, secondary sites, cloud failover and staff training—but delivers far greater resilience.

    Practical Steps for South African SMBs

    SMBs in South Africa face specific challenges: load-shedding, variable internet reliability, physical security risks and increasing cyber threats. A pragmatic approach balances cost, complexity and risk.

    1. Start with a simple BIA

    Identify the processes that generate revenue or are legally required. Determine acceptable downtime and potential costs of interruption in rand (R). This gives you priorities for backups and continuity investments.

    2. Implement a 3-2-1 backup strategy

    • Keep at least three copies of data
    • Store copies on two different media
    • Keep one copy offsite (cloud or physically separate location)

    3. Harden backups against ransomware

    • Use immutable or air-gapped backups where possible.
    • Test backups regularly to ensure data integrity.

    4. Plan for power and connectivity issues

    Consider UPS systems, backup generators and multiple internet providers. For Johannesburg/Gauteng businesses, redundant ISP links and mobile failover can reduce disruption during load-shedding or local outages.

    5. Create simple continuity playbooks

    Produce short, actionable guides for incidents: who to contact, how to switch to cloud services, remote-work instructions, and where key backups are stored. Make these accessible offsite and print copies for key personnel.

    6. Test regularly and update

    Conduct tabletop exercises and full restore drills at least annually, or after major changes. Testing exposes gaps and builds staff confidence.

    How Managed IT and MSPs Help

    Many SMBs lack the in-house resources to plan and maintain robust continuity. A managed service provider can:

    • Design backup architectures aligned with RPO/RTO targets
    • Manage offsite and cloud backups with encryption and immutability options
    • Implement failover solutions and remote access for quick continuity
    • Run regular tests and provide incident response expertise

    Working with experienced engineers reduces risk and speeds recovery—especially when you need resolution fast rather than long vendor learning curves.

    Cost Considerations for SMBs

    Budgeting for backup and continuity should be risk-based. Compare the estimated cost of downtime (lost revenue, fines, reputational damage) with the cost of solutions. Small businesses in South Africa often start with cloud-based backups (monthly costs in rand) and scale into continuity services as they grow.

    Conclusion

    Backups and business continuity are complementary. Backups recover data; business continuity keeps the business operational during incidents. For South African SMBs, a practical, tested plan that combines reliable backups, clear continuity playbooks and fast-response technical support is the best way to reduce downtime and protect your business.

    FAQ

    • Q: Can backups alone provide business continuity?

      A: No. Backups help you recover data but don’t guarantee continued operations. Continuity requires processes, alternate access methods and communication plans.

    • Q: How often should I test backups?

      A: Test restores at least quarterly and perform a full recovery drill annually, or after major system changes.

    • Q: What is a reasonable RTO for an SMB?

      A: That depends on the business. Critical services may need RTOs measured in minutes to hours; less critical functions might tolerate days. Use a BIA to decide.

    • Q: Are cloud backups safe for South African businesses?

      A: Yes, when properly configured with encryption, access controls and regional redundancy. Ensure your provider meets legal and data residency needs.

    • Q: How much will business continuity planning cost?

      A: Costs vary by scope. A basic plan with cloud backups and simple continuity playbooks can be affordable for SMBs. More advanced failover and redundant infrastructure will cost more but may be justified by reduced downtime losses.

    If your business needs practical, experienced assistance to implement reliable backups and a realistic continuity plan, contact RandTech IT. Our engineers focus on fast resolution and proven solutions to keep your business running.