1. Identify critical services
List the systems, data, people, suppliers and facilities required to operate important business processes. Prioritise them based on business impact rather than technical preference.
2. Define recovery objectives
Agree realistic Recovery Time Objectives and Recovery Point Objectives for critical services. These targets should guide architecture, backup frequency and investment decisions.
3. Review backup design
Check what is backed up, where copies are stored, how they are protected from ransomware, how long data is retained and whether cloud/SaaS data is included where needed.
4. Document dependencies
Applications often rely on identity, DNS, networking, internet connectivity, certificates, databases, integrations and third parties. Recovery plans must reflect those dependencies.
5. Plan for people and communications
Define who declares an incident, who makes decisions, how employees and customers are informed, how suppliers are contacted and how teams work if normal systems are unavailable.
6. Test recovery
Carry out restore tests and scenario exercises. Record what worked, what failed and what needs improvement. Untested recovery assumptions are one of the most common resilience weaknesses.
Choose your next step
Use the guidance in the way that suits you.
EaseThat can review backup, disaster recovery and business continuity arrangements and turn gaps into a practical resilience improvement plan.
Direct PDF download - no registration or email address required.