Business Continuity

IT Disaster Recovery Services: A Melbourne SME Buyer’s Guide

IT Disaster Recovery Services: A Melbourne SME Buyer's Guide

Melbourne SMEs buying disaster recovery for the first time get stuck between three product categories, unrealistic RTO numbers, and a Microsoft 365 backup conversation nobody told them about. This is the buyer’s guide: what you are choosing between, the realistic 2026 price brackets, and the eight questions to ask any DR vendor before signing.

What this guide is and is not

This is not a planning guide. It is not ‘how to write a business impact analysis.’ It is the conversation you have once you have decided you need to buy something and you are trying to work out what to buy.

Three product categories cover almost every Melbourne SME DR purchase in 2026:

  1. DRaaS – replicating production workloads to a cloud target so they can be failed over (Azure Site Recovery is the dominant Australian play, with VMware Cloud Disaster Recovery and Zerto in specialised cases)
  2. On-premises BCDR appliances – a local appliance that backs up your servers and can stand them up locally or in the vendor’s cloud (Datto, Axcient, Acronis, Arcserve, Veeam with a hardware partner)
  3. SaaS backup – third-party backup for Microsoft 365 and Google Workspace, which the platform vendors do not back up for you (Keepit, Backupify, CloudAlly, Veeam for M365, AvePoint, Dropsuite)

Most SMEs need pieces of all three, in different combinations. A 60-staff professional services firm in Richmond probably needs Azure Site Recovery for the two on-premises servers, a third-party M365 backup, and not much else. A 90-staff manufacturer in Dandenong with a line-of-business ERP, a SQL database, and a need for fast local recovery probably needs a BCDR appliance plus SaaS backup. A 100% cloud-native software company needs SaaS backup plus a workload-specific backup of their cloud database. The product mix follows the workload.

For the planning side of the conversation – the BIA, the RTO and RPO targets, the runbook – see our backup and disaster recovery 2026 guide, which is the companion piece to this one.

Category 1: DRaaS (Disaster Recovery as a Service)

The model is: your production workload runs where it is (on-prem, in Azure, in AWS), and a replication layer copies it continuously to a standby environment in a cloud target. When something fails, you fail over to the standby and run there until you can return to primary.

Azure Site Recovery (ASR)

The default option for Australian SMEs running on Hyper-V or VMware on-prem, or running production workloads in Azure. Replicates VMs to a secondary Azure region (typically Australia East to Australia Southeast, or vice versa). Failover is orchestrated, and you can test failover into an isolated network without disrupting production.

Strengths:

  • Native Microsoft, integrates with the rest of the Azure estate
  • Australia-sovereign target regions
  • Pricing is genuinely SME-friendly: about $25 to $30 per protected instance per month for ASR itself, plus the storage and (during failover) the compute
  • Failover testing is non-disruptive and well-supported

Weaknesses:

  • RPO is typically 5 to 15 minutes for app-consistent recoveries; not the sub-minute that some marketing claims
  • Complex to configure properly; SMEs often deploy it half-configured
  • The compute cost during a real failover catches CFOs off guard – if you fail over 12 VMs and run them in DR for two weeks while you rebuild, that is a real Azure bill
  • Requires Azure expertise that not every MSP has at the level needed for reliable orchestration

VMware Cloud Disaster Recovery

For SMEs running VMware on-premises with a meaningful estate. Replicates to a VMware Cloud target on AWS or to an alternative pilot-light site. Usually overkill for under-50-VM environments.

Zerto

The premium DRaaS choice. Continuous data protection rather than scheduled replication, RPOs measured in seconds, mature failover orchestration. Priced accordingly. We deploy Zerto for clients who genuinely need sub-minute RPO on critical workloads; it is not the right answer for an average SME.

Category 2: On-premises BCDR appliances

The model is: a physical or virtual appliance lives at your office or data centre, takes regular image-level backups of your servers (and often endpoints), and can either restore locally (fast) or stand the workloads up in the vendor’s cloud (slower, but works if your office is gone).

Datto

The category-defining product. Datto Siris appliances are sold exclusively through MSPs. The local appliance has its own compute, so it can stand up a failed server as a virtual instance on the appliance itself within minutes. Off-site copies replicate to Datto’s cloud (in Australia, hosted in Sydney and Melbourne data centres).

Strengths:

  • Fast local recovery; the on-appliance virtualisation actually works
  • Cloud failover is real, not theoretical, and Datto runs the orchestration
  • Hardware refresh is part of the agreement; the appliance gets replaced on a cycle without a capex spike
  • Good for SMEs that want a single thing to point at when the auditor asks ‘show me your DR’

Weaknesses:

  • Per-protected-server pricing; can become expensive for environments with many small servers
  • Vendor lock-in; getting your backup data out of Datto if you change providers is a project
  • Local appliance is a single point of failure for local recovery; needs the off-site copy to be real
  • The MSP-only sales channel means you cannot evaluate it without going through a partner

Axcient

Similar concept to Datto, with the local appliance and the cloud failover. Often the right answer for slightly smaller environments where Datto’s pricing is over the budget. The cloud failover capability is solid; the on-appliance virtualisation is functional but slightly less polished.

Veeam with hardware

The build-your-own option. Veeam is the backup software, paired with a Dell PowerEdge or HPE ProLiant or a purpose-built backup appliance (Dell PowerProtect, HPE StoreOnce). More flexible and often cheaper at scale than the all-in-one appliances, but requires the MSP or internal team to design, build, and operate the stack rather than buying it as a service.

This is what we recommend for clients who already have Veeam expertise and who want to avoid the vendor lock-in of the all-in-one appliances. It is what we run in our own environment.

Acronis and Arcserve

Adjacent options in this category, both with valid use cases. Acronis Cyber Protect adds a security overlay (anti-malware, anti-ransomware) on top of the backup product, which appeals to SMEs that want fewer products to manage. Arcserve UDP has a strong reputation for hybrid workloads. Both worth evaluating if Datto and Axcient don’t fit.

Category 3: SaaS backup (the conversation nobody told you about)

The single most common gap we see in Melbourne SME DR posture: Microsoft does not back up your Microsoft 365 data in a way that helps you recover from accidental deletion, ransomware encryption, malicious insider activity, or a SharePoint policy gone wrong. They protect their infrastructure, not your content. This is the Microsoft 365 shared responsibility model, and it is documented in their own service description.

What Microsoft does:

  • Geo-redundant storage so a data centre failure does not lose your data
  • Retention policies you configure (litigation hold, retention labels)
  • Recycle bin and version history for a default period
  • Point-in-time recovery for Exchange Online within a window

What Microsoft does not do:

  • Full long-term backup of your mailboxes, OneDrive, SharePoint, and Teams content
  • Granular recovery to a point earlier than the retention or recycle bin window
  • Recovery of an entire tenant if it is wiped by a compromised admin
  • Export of mailbox data in a portable, restorable format outside of Microsoft’s tooling

The conversation to have with your IT lead: ‘If a user gets compromised and the attacker deletes the contents of their OneDrive and emails, and we do not notice for 45 days, can we recover the data?’ The honest answer from native Microsoft is usually no – the 30-day default retention window has passed.

Third-party M365 backup tools solve this. Pricing is per-user-per-month, typically $3 to $6 in the Australian market, retention is configurable up to ‘forever,’ and recovery is granular (a single email, a single OneDrive file, a single Teams chat). The leaders:

VendorStrengthsWatch-outs
KeepitIndependent vendor, Australian data residency, strong UI, good retention modelMid-market pricing
Veeam Backup for M365Same Veeam platform if you already use it on-prem, flexible storage targetsStorage costs are your problem; not all-in pricing
Backupify (Datto)Polished UI, MSP-friendly, good for Datto customersVendor lock-in
AvePoint Cloud BackupStrong on SharePoint and Teams, mature retention policiesHigher learning curve
DropsuitePer-user pricing, simple to manageLess granular than the leaders
CloudAllyLower-cost option, decent retentionSmaller vendor, fewer enterprise features

For every Microsoft 365 business we manage, a third-party M365 backup is part of the baseline stack. We default to Keepit for new deployments because the Australian data residency, retention model, and recovery experience are the best of the options, and the pricing is defensible for SME budgets.

Realistic price brackets for 2026

The number that comes out of a vendor sales call is rarely the number you end up paying once setup, support, replication storage, failover compute, and the inevitable additions are included. Approximate all-in monthly numbers for a 60-user Melbourne SME with 4 production VMs:

SolutionPer-month all-inWhat you get
Azure Site Recovery + Keepit M365$650 – $950Cloud failover for 4 VMs, M365 backup, MSP-managed
Datto BCDR + Backupify M365$1,400 – $2,200Local appliance with cloud failover, M365 backup, MSP-managed
Axcient BCDR + Dropsuite M365$1,100 – $1,700Mid-tier appliance + cloud failover, M365 backup
Veeam + Dell PowerProtect + Veeam M365$1,200 – $1,800Build-your-own appliance approach with M365 backup, requires expertise
Zerto + Keepit M365$2,200 – $3,500Premium sub-minute RPO for critical workloads

Add the implementation cost (typically $4,000 to $15,000 one-off depending on complexity) and the annual failover test (typically half a day of MSP time, billed at the going rate). For most 60 to 100 staff Melbourne SMEs, total DR spend lands between $14,000 and $30,000 per year all-in.

RTO and RPO: what vendors quote versus what they deliver

Vendor marketing materials quote ‘RTO of 5 minutes’ or ‘RPO of seconds.’ These numbers refer to the absolute best-case mechanical capability of the product under controlled conditions on the vendor’s test bench. They are not what you get in a real disaster.

Realistic numbers for the three categories under SME conditions, based on our experience running recoveries:

ScenarioVendor-quoted RTORealistic RTOWhy the gap
Azure Site Recovery, single VM failure5-15 minutes30-90 minutesNetwork reconfiguration, DNS, application validation
Azure Site Recovery, full site failover30-60 minutes4-12 hoursDependency ordering, user redirection, internal communication
Datto local recovery, single server5 minutes15-45 minutesPerformance on appliance compute, application checks
Datto cloud failover, full site1-2 hours4-10 hoursVPN setup, user routing, app validation
Zerto, critical workloadSub-minute10-30 minutesCloser to spec because the product is designed for it
M365 mailbox restoreMinutes1-4 hoursIdentifying what was lost, scoping the restore

The gap between vendor-quoted and realistic is not the vendor lying; it is the difference between the mechanical recovery time and the business-readiness time. When you negotiate, make sure the RTO in the contract is the business-readiness time, not just the time for the system to come up. Otherwise you are signing for a number that does not mean what you think it means.

The eight questions to ask any DR vendor before signing

  1. What is your contracted RTO and RPO, and is it measured to system-online or business-ready? If they cannot answer this clearly, walk away.
  2. Where is the off-site copy stored, and is the storage in Australia? Sovereign data residency matters for many SMEs, especially those with health, legal or government-adjacent data.
  3. What is the additional cost during a real failover (compute, egress, storage)? The DR product price is the steady-state cost; the failover cost can be substantial.
  4. How often do you test failover, who tests it, and what is the success rate? Untested DR is a hope, not a plan. Insist on at least an annual test.
  5. What does it cost to extract our data if we leave? Vendor lock-in is real. Get the exit number on the contract.
  6. What is the support model during an incident – phone, ticket, named engineer? When you are actually failing over, the time to get a human matters more than any other metric.
  7. Who else like us are you protecting in Melbourne, and can we speak to them? Reference checks from similar-sized businesses cut through the marketing fast.
  8. What is the upgrade and hardware refresh cycle, and who pays? For appliance-based products, this affects the multi-year total cost.

Picture a 40-staff law firm that goes to contract with a national MSP quoting a 30-minute RTO. The contract small print clarified that 30 minutes was system-online. In the first proper DR test, business-ready turns out to be 5 hours. The firm renegotiated the contract on renewal to specify business-ready RTO with measurable check points. Different number, more honest contract.

Sample DR scope checklist (30 to 100 user SME)

The scope of work conversation with a DR vendor is where mistakes get baked in. Use this as a starting checklist:

ItemIn scope?Notes
Production VMs (on-prem)YesList by name, OS, role, criticality
Production VMs (Azure / AWS / GCP)YesCross-cloud DR is a separate conversation
SQL or other databasesYes, with app-consistent backupsApplication-consistent, not just crash-consistent
Microsoft 365 (Exchange, OneDrive, SharePoint, Teams)Yes, via third-party SaaS backupMicrosoft does not back this up for you
Line-of-business SaaS (Xero, CRM, practice mgmt)Vendor-specificEach vendor’s backup policy is different; verify each
Endpoint data (laptops)OptionalOneDrive sync usually covers this; check the policy
File sharesYesOften the largest data set
Active Directory / Entra IDYesAD system state for on-prem; Entra ID via M365 backup
Network configurations (firewalls, switches)Yes, as config exportsOften missed; documented configs accelerate recovery
Documentation runbooksYesStored outside the systems being recovered
Annual testYesSpecify isolated network test, not a paper exercise
Incident response on-callYesWho do you call at 2 a.m. Sunday?

If a vendor proposal does not cover every row of this table or does not explicitly note items as out of scope with a reason, ask before signing. A DR proposal that omits Microsoft 365 backup is a flag, not because the vendor is dishonest but because the gap will surface during a real incident at the worst possible time.

How TechAssist delivers this

We are vendor-agnostic on DR. Our default stack for a typical Melbourne SME is Azure Site Recovery for IaaS, Keepit for M365 backup, and Veeam for environments that need a richer on-prem appliance story. We also run Datto where it is the right answer and Zerto where the RPO requirement justifies it.

The delivery is what makes the difference. Our NOC at Tecoma monitors backup jobs and replication health on every managed client, with 24/7 on-call and emergency support for P1 events. When a real incident hits, our 13 Melbourne-employed staff (no offshore tier-one queue) take the call, and same-business-day on-site response in Melbourne metro means an engineer can be at your office quickly if hands on the equipment are needed. The per-user fixed monthly pricing model includes the DR management on managed engagements; the DR product cost is a separate, transparent line item passed through at the vendor rate. The two Melbourne offices, Tecoma and Bourke Street CBD, cover both ends of the metro area, with the CBD office useful for city-based businesses that want a quick face-to-face during planning.

Our DR practice has run recoveries across professional services, healthcare admin, manufacturing and not-for-profits. The pattern across all of them is the same: the DR posture that works is one that has been tested, documented, owned, and reviewed annually. The product choice matters less than the discipline around it. To talk through your specific environment, our team is reachable through the contact page, or for the broader managed services context the Melbourne managed IT services page covers how DR sits in the overall engagement.

Frequently Asked Questions

Is Microsoft 365 backup really necessary if we have litigation hold?

Litigation hold is a retention control, not a backup. It prevents end users from permanently deleting items, but it does not protect against a compromised admin wiping the tenant, does not give you a portable export, and does not provide point-in-time recovery for arbitrary historical states. For any SME holding meaningful business data in M365 – which is all of them – a third-party backup is a baseline control, not an option.

Can we just rely on the local appliance and skip the cloud failover?

If the disaster is a ransomware attack that encrypts the local appliance, or a fire that takes the office, the local-only configuration is no protection at all. The cloud or off-site copy is what makes the DR posture survive a real disaster. Local appliance plus cloud copy is the minimum; local-only is not DR, it is backup with extra steps.

What is the difference between backup and disaster recovery?

Backup is the data; DR is the ability to operate from that data after a major incident. A nightly backup of your server is backup. The ability to fail that server over to a working environment within a contracted time is DR. Most SMEs need both, in coordinated form, not one or the other.

How often should we test failover?

At least annually for a full test, quarterly for component tests, and continuously for the automated health checks the platform should be running. A DR plan that has not been tested in 18 months is no plan; it is a hope.

Will our cyber insurance cover the cost of a DR failover?

Sometimes yes, sometimes no. Read the policy. Many cyber policies cover business interruption losses but exclude or limit the actual restoration costs. The cleanest approach is to budget for the failover cost as a separate line, and treat any insurance recovery as upside.

Does the same DR product work for our on-premises servers and our Azure workloads?

Mostly no. The categories were designed for different starting points. Azure Site Recovery covers both Azure-native and on-prem to Azure. The appliance-based BCDR products are typically on-prem first, with limited cloud-native coverage. If your workload split is meaningful in both directions, expect to run two products. Our Melbourne cloud services page has more on hybrid architecture.

← Previous Azure Cost Creep: A FinOps Starter Guide for Melbourne SMEs Next → IT Budget Template for a 50-Person Melbourne SME (FY27 Edition)

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon, just a clear-eyed look at where you stand and what's possible.