Business Continuity & Disaster Recovery
How Reyman Pty Ltd keeps delivery running through disruptions — and how we protect the systems and data we operate for clients.
1. Commitment & Scope
Axisonic is committed to maintaining business continuity and disaster recovery arrangements that keep client work progressing and client-operated systems available during disruption — whether from infrastructure failure, cyber incidents, severe weather, or other events.
This policy applies to Axisonic's own operations and, where contracted, to the systems and environments we design, build, and operate for clients. Continuity and recovery commitments are documented per engagement, because requirements differ materially between a marketing site and a mission-critical government platform.
2. Business Impact & Risk Assessment
Services and systems are assessed for the impact their loss or degradation would cause, and prioritised accordingly. For each critical engagement we agree recovery objectives — such as recovery point (acceptable data loss) and recovery time (acceptable downtime) targets — and document them in the service or support agreement.
3. Backups
- Automated backups for client data and environments we operate, scheduled and monitored rather than ad hoc.
- Encrypted at rest and protected from unauthorised access, in line with our information security practices.
- Separated storage — backups are held independently of the primary environment so a single incident cannot destroy both.
- Retention aligned to requirements — backup retention periods are matched to the client's data retention and business requirements, never longer than needed.
- Restore testing — backups are only trusted once a restore has been proven; see Recovery Testing below.
4. Disaster Recovery
Documented recovery procedures are maintained for the cloud infrastructure, environments, and systems we operate. Where practical and contracted, this includes defined recovery steps, redeployment automation (infrastructure-as-code), and the ability to rebuild environments in alternate Australian regions or zones in line with each client's data sovereignty requirements.
5. Business Continuity
- Remote-first operations — delivery teams work across Australian locations, so a single-site disruption does not stop work.
- Communication plan — clients are informed promptly of any incident affecting their services, consistent with our incident response commitments.
- Identified roles — continuity actions and decision rights are assigned, so escalation is clear during an event.
- Cross-trained capacity — critical delivery functions are not dependent on a single individual.
6. Recovery Testing
Restore and recovery procedures are tested periodically — restore exercises for critical backups at least annually, and disaster recovery exercises where contracted. Test results are reviewed and procedures updated where gaps are found. An untested continuity plan is an assumption, not a plan.
7. Supplier & Subcontractor Continuity
Where delivery depends on suppliers or specialist partners, continuity risk is considered as part of supplier assessment, and key dependencies are not left to a single provider. Subcontractor arrangements remain governed by our supply chain governance model, with Axisonic retaining accountability for recovery and continuity regardless of provider performance.
8. Review
This policy is reviewed periodically — and at least annually — and updated as our operations, client requirements, and recovery testing results evolve.