A backup is not a plan
Most businesses have backups. Far fewer have a plan. A backup is a copy of your data. A plan is how your people get back to work: which systems come back first, who does what, who calls whom, and how long it takes.
When an outage hits, a backup answers “is the data somewhere?” A plan answers “what do we do in the next ten minutes?”
Two numbers in plain English
Recovery time is how long it takes to get a system working again. Recovery point is how much work you’d lose: if the last good backup was at midnight and the outage is at 3 p.m., you’ve lost 15 hours of work unless something else captured it.
Every critical system should have both numbers written down, and both should be tested.
The seven parts of a continuity plan
- Critical systems. The short list of systems that, if they stopped, would stop the business. Ranked.
- Owners. One named person for each system, on your side and on your provider’s side.
- Recovery order. What comes back first, second and third, and why. Usually identity and internet first, then email and files, then line-of-business applications.
- Communication tree. Who calls whom, in what order, and what you tell clients, staff and vendors. Include personal phone numbers; email may be down.
- Vendor contacts. Account numbers, support lines and escalation contacts for every vendor in the critical path.
- Alternate work. What people do while systems are down: paper forms, a different location, mobile hotspots, a manual process.
- Test schedule. When the plan and the restores get tested, and who signs off on the results.
How to test without breaking anything
- Tabletop test (1 hour, twice a year). Walk through a scenario around a table. “It’s 9 a.m. Monday and email is down. What happens?” Note every gap.
- Restore test (monthly to quarterly). Restore a real file, a mailbox and a full system to a test environment. Time it. Compare it to your recovery time target.
- Failover test (annually). Switch to the backup internet line, the secondary site or the cloud copy, on purpose, at a quiet time.
The minimum standard
A plan can only work on an environment that supports it. Before we write one, we check for:
- Supported operating systems and applications
- Genuine, licensed software
- Servers under warranty and on battery backup
- Encrypted wireless
- A licensed, monitored backup that can actually be restored
- Administrative access for the people responsible for recovery
If any of those are missing, the first page of the plan is the list of gaps.
Self-assessment: 20 questions
Answer yes or no. Score one point for each yes.
- We have a written list of our critical systems.
- Each critical system has a named owner.
- We know the recovery time for each critical system.
- We know the recovery point for each critical system.
- We have restored a file from backup in the last 90 days.
- We have restored a full system in the last 12 months.
- Our backups include a copy outside the office.
- Our backups are encrypted.
- Backups are monitored and someone is alerted to failures.
- We have a written recovery order.
- We have a communication tree with personal phone numbers.
- We have vendor contacts and account numbers in one place.
- Staff know what to do while systems are down.
- We have a second internet connection or a failover plan.
- Servers and network equipment are on battery backup.
- Our operating systems and key applications are supported.
- Multi-factor authentication is on for every account.
- We ran a tabletop test in the last 12 months.
- The plan can be found in under 60 seconds, including offline.
- Someone owns the plan and updates it at least once a year.
16 to 20: Ready. Keep testing. 10 to 15: Partly ready. Close the gaps in order of your Downtime Ledger. Under 10: Not ready. Start with questions 1 to 6 this month.
Where this fits in the frameworks
If you answer to an auditor, examiner or insurer, a continuity plan maps to the Recover function of NIST CSF 2.0 and to CIS Controls v8.1 Control 11, Data Recovery. A written, tested plan is usually the single most persuasive piece of evidence you can show.
How Circle Square builds it
Every Circle Square client gets a written continuity and disaster recovery plan, or a written list of the gaps and what closing each one takes. We start with your Downtime Ledger so the plan protects the systems that matter most to your business, we verify backups daily, and we share the results of every recovery test with you.