SarjaTechnologies

Why reliability & security matter

When a system stops, the organisation stops with it.

Security and reliability aren't IT line items. They decide whether classes run, orders ship and patients get seen. Here is what a handful of well-documented incidents show — stated only as far as the organisations and regulators themselves have — and how we engineer against the same failures.

Evidence

What happened, and what it teaches.

Facts come from each organisation's disclosure, regulatory filings or government sources, linked with every entry and checked in September 2026. Where a source says what was not affected, we say so too.

Education · April–May 2026

Instructure (Canvas)

What happened

Instructure detected unauthorised activity in Canvas on 29 April. Usernames, email addresses, course names, enrolment information and messages were affected.

What was not affected

Instructure states core learning data — course content, submissions and credentials — was not compromised.

Impact

After a second intrusion on 7 May altered pages some users saw, Instructure temporarily put Canvas into maintenance mode. Institutions lost access to their learning platform; Instructure reported it fully back online on 9 May.

Engineering lesson

When coursework, submissions, assessment and communication all run through one platform, that platform's availability is part of educational continuity — and schools need an alternative way to keep working.

Sources

What we engineer in response

The same lessons, turned into systems.

Every principle below maps to work we design, build and operate.

Resilient architecture

  • Redundancy and high availability
  • Failover
  • Geographic separation where appropriate
  • Health checks and monitoring
  • Graceful degradation

Cloud & InfrastructureDevOps & Platform Engineering

Backup and recovery

  • Scheduled backups
  • Immutable or offline copies where appropriate
  • Tested restoration
  • Defined recovery objectives
  • Backup monitoring

A backup that has never been restored is an assumption, not a plan.

Business Continuity & Disaster Recovery

Data protection

  • Encryption in transit and at rest
  • Least privilege and privileged access management
  • SSO and MFA
  • Secrets management
  • Retention and secure deletion
  • Segmentation and audit trails

CybersecurityData Engineering & Analytics

Threat protection

  • Endpoint and malware protection
  • Phishing and malicious-domain blocking
  • Vulnerability and patch management
  • Monitoring and alerting

CybersecurityManaged IT Services

Application security

  • Secure development and code review
  • Dependency management and scanning
  • Authentication and authorisation design
  • Secure session handling
  • API security and penetration testing

Software DevelopmentCybersecurity

Continuity

  • Incident plans and escalation paths
  • Disaster recovery and recovery testing
  • Alternate workflows when a system is down
  • Service-status communication

Business Continuity & Disaster RecoveryManaged IT Services

Managed protection

What ongoing protection actually includes.

Protection is operated, not installed. These are the components we run for organisations — and what isn't available yet is labelled as such.

Available now

Protect

The security baseline every organisation should have, run and reported on for you.

  • Continuous endpoint protection
  • Patch management
  • DNS and web protection
  • Phishing protection
  • MFA and identity baseline
  • Device management
  • Backup monitoring
  • Security alerts to your contacts

Available now

Protect & Recover

Everything in Protect, plus proof that you can recover — and help when something happens.

  • Scheduled restoration tests
  • Vulnerability monitoring
  • Identity and infrastructure monitoring
  • Configuration reviews
  • Log retention
  • Incident response and recovery assistance
  • Periodic security reviews

Planned — not yet available

Extended monitoring

Security event monitoring (SIEM) and active threat detection beyond business hours.

  • SIEM and log correlation
  • Active threat detection
  • Out-of-hours alert handling

Being established. We don't advertise round-the-clock coverage until it is staffed; response hours are always set out in your agreement.

Find out what would stop if your core system went down.

We'll review your infrastructure, backups, identity and recovery plans, and tell you plainly where the risk is.