Frontrow Technology
← All insights & guides
Guide

Managed Services

Cyclone season IT continuity: a Queensland checklist

Cyclone season opens 1 November. The IT continuity work that matters happens before then: power, failover links, restore drills and the insurer's evidence file.

Graeme Lodge · 27 August 2026 · 11 min read

The Australian tropical cyclone season officially runs from 1 November to 30 April. For businesses between Mackay and Cairns, that date is not an abstraction; it is the deadline for every piece of continuity work that cannot be done in a howling gale. Frontrow runs offices in Mackay and Townsville, inside the zone this guide is written about, and the pattern every season is the same: the businesses that come through well did their IT preparation in September and October, and the ones that struggle started thinking about it when the Bureau of Meteorology published a track map.

Severe Tropical Cyclone Kirrily crossed the coast near Townsville in January 2024, and the recovery for many businesses was measured in days of lost power and connectivity rather than hours of wind. That is the real shape of the risk. Wind takes the headlines; it is the week afterwards, with the grid down in patches, fixed links dead and staff scattered, that decides whether a business trades or doesn't. The checklist below covers the seven areas Frontrow works through with clients before each season, roughly in the order they fail.

Power: the comms room fails before the town does

Most business continuity plans assume the uninterruptible power supply (UPS) works. Fewer have measured how long it actually runs under the real load of the comms room, and fewer still have a written order for what shuts down when it starts beeping. A UPS that carried 40 minutes when it was installed five years ago may carry 12 today, because batteries age and equipment has been added since.

  • Test UPS runtime under actual load before November, not from the label. Pull the wall power deliberately during a quiet window and time it.
  • Write a shutdown order for the comms room: what gets powered off first to stretch runtime, what must stay up (the firewall and one switch usually matter more than the phone system), and what can be allowed to die hard.
  • If there is a generator, the runbook needs to cover who starts it, where the fuel is, how long the stored fuel lasts, and how the comms room actually receives generator power. A transfer switch nobody has operated since installation is a plan on paper only.
  • Record who holds physical keys and alarm codes for the building and the comms room, and confirm at least two of those people live on different sides of town. After a crossing, roads close.

Fixed connections in north Queensland fail during cyclone events for reasons that have nothing to do with the cable into the building: loss of power at upstream infrastructure, damaged aerial runs, flooded pits. A continuity plan that has no second path is a plan to be offline for however long the carrier's restoration queue takes, and after a major event that queue is long.

  • Put a second, physically different path in place: a satellite service such as Starlink, or a 4G/5G service on a different network path, mounted and configured before the season, not couriered in after it.
  • Test the failover, under load, with staff working. A backup link that has never carried the office's real traffic will surprise you on the day: undersized, misrouted, or blocked by a firewall rule nobody remembers writing.
  • Document what changes when the backup link is active. Public IP addresses change, which can break inbound services, site-to-site VPNs and any allow-list a supplier holds for you.
  • Remember the backup link needs power too. A satellite dish and router on a circuit the UPS does not cover fails at exactly the moment it was bought for.

Microsoft 365 is the continuity layer, if the migration is finished

For a business already running properly on Microsoft 365, a large part of cyclone continuity is already done: files live in SharePoint and OneDrive rather than on a server in the flooded building, email keeps flowing, and Teams keeps working from wherever staff have ended up. The office becomes a place work happens rather than the place it is stored.

The trap is the half-finished migration. Frontrow sees this shape regularly in regional Queensland: email moved to M365 years ago, but the finance system data, the job files or one critical shared drive still lives on an on-premises server. That remainder is precisely the part a cyclone takes out. Before the season, the honest exercise is to list what still only exists inside the building, and either move it, replicate it, or accept in writing that it will be unavailable during an event. Frontrow's broader tenant checklist at /insights/microsoft-365-health-check-checklist-australia covers the M365-side items, from backup coverage to access, that this decision depends on.

Restore drills before November, not backup reports

A backup report that says green every morning proves the backup job ran. It does not prove anything can be restored, how long a restore takes, or that the person who knows the passphrase still works for the business. The difference only surfaces when it matters, which is the worst possible time to learn it.

  1. 1Pick the two or three systems the business genuinely cannot trade without and restore each one, for real, to alternative hardware or a cloud target.
  2. 2Time the restores. A 14-hour restore is fine to discover in October and a crisis to discover in February.
  3. 3Confirm at least one backup copy lives outside the cyclone zone, offsite or in cloud storage, and that restoring from it does not depend on equipment inside the building.
  4. 4Write down what was tested, when, by whom and how long it took. That record is operationally useful and, as covered below, worth money in an insurance claim.

Staff readiness: work from wherever people end up

After a crossing, staff are dealing with their own houses, their own families and their own street. Some will be able to work; the question is whether the IT lets them. This is mostly small, boring configuration that costs nothing to fix in September and a week of downtime to discover in January.

  • Laptops over desktops for anyone whose role must continue through an event. A desktop in a powerless office is furniture.
  • Check multi-factor authentication methods are not anchored to the office: a hardware token in a desk drawer or a landline-based method fails with the building.
  • Review Conditional Access and any location-based rules so that staff signing in from a relative's place, a library or an evacuation centre are not silently blocked.
  • Make sure the main business phone number can be redirected without anyone entering the building, and that more than one person knows how.
  • Keep a printed contact tree. The plan that lives only in a system nobody can reach during an outage is not a plan.

The insurer will ask for evidence: build the file now

Business interruption and equipment claims after a cyclone turn on documentation, and the documentation that carries weight is the kind that can only be produced beforehand. An asset register written from memory after the water has gone down is worth far less than one with serial numbers and photos dated the previous October.

  • Photograph the comms room, server equipment, workstations and plant as they stand, with dates. Re-do it each season; it takes an hour.
  • Keep an asset register with serial numbers, purchase dates and replacement values, stored in M365 so it survives the building.
  • File the evidence of preparation: UPS test results, restore drill records, failover test notes. Insurers and assessors respond well to a business that can show it managed its risk.
  • During and after an event, keep a running claims record: a timeline of what failed and when, outage notices from carriers and the energy distributor, every emergency purchase receipt, and the hours spent on recovery. Reconstructing this a month later from memory undersells the claim every time.

None of this list is exotic. It is an afternoon of testing, a few configuration reviews and some photographs, done while the sky is blue. The gap between businesses that trade through a cyclone season and businesses that spend February in recovery is rarely money; it is whether this work was done in October.

Common questions

Frequently asked

When does cyclone season start in Queensland?
The Australian tropical cyclone season officially runs from 1 November to 30 April, per the Bureau of Meteorology. Cyclones outside those dates are possible but rare. For IT continuity purposes the practical deadline is late October: UPS tests, failover drills and restore tests all need calm weather and a quiet maintenance window, which are exactly the things a named system removes.
What usually takes businesses offline in a cyclone: wind damage or power loss?
Power and connectivity loss, by a wide margin. Direct wind or water damage to IT equipment happens, but the more common pattern, as with Kirrily near Townsville in January 2024, is days of grid outages and dead fixed links across a wide area while buildings themselves are largely intact. That is why UPS runtime, generator runbooks and a second connectivity path sit at the top of the checklist.
Is Microsoft 365 enough of a continuity plan on its own?
It covers a great deal: files, email and Teams already live outside the building, so a business fully on M365 can keep operating from anywhere with power and a connection. It is not sufficient on its own, because most regional businesses still have something on-premises (a finance system, job files, a line-of-business server), and because staff still need working devices, sign-in methods that are not anchored to the office, and a connection. The honest pre-season exercise is listing what still only exists inside the building.
How do we test our backups without risking production systems?
Restore to somewhere other than production: spare hardware, a virtual machine, or a cloud target. The goal is to prove the backup produces a working system and to time how long that takes, not to touch the live environment. Time it, record it, and repeat for the two or three systems the business genuinely cannot trade without. A green backup report on its own proves only that the job ran.
What IT records do insurers actually want after a cyclone?
Two kinds. From before the event: a dated asset register with serial numbers and replacement values, photographs of equipment and premises, and evidence the risk was managed (UPS tests, restore drills, maintenance records). From during and after: a timeline of what failed and when, carrier and energy-distributor outage notices, receipts for every emergency purchase, and recovery labour hours. The pre-event file can only be created beforehand, which is why it is on the pre-season checklist.
We are outside the direct cyclone belt, in Brisbane or further south. Does this still apply?
Most of it. Ex-tropical cyclones and the flooding that follows them reach well south of the tropics, and the failure modes are the same: extended power loss, dead fixed links and staff working from wherever they can. The checklist items are identical; only the probability changes. Severe storm season affects the whole east coast over the same months.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.