How Businesses Survive a Disaster: Prepare for the What If

Does your organization have a business continuity and disaster recovery plan? It’s a question that every organization – no matter its size – should be asking itself right now in light of Hurricane Sandy’s destructive path along the East Coast. In a moment, disasters can take businesses out of the game – for days, months or even forever.

A disaster recovery plan often is what stands between businesses surviving an unexpected event that impacts their ability to operate and experiencing a financial loss they cannot recover from. Businesses on the East Coast have been without power for a week and half now and predictions suggest it could be another week. What would happen if your organization lost power for two weeks? Having an answer is important.

A business continuity and disaster recovery plan is not only for catastrophic natural disasters, it also applies to other potential crises for your organization. At Marco, we rely heavily on our phone system to provide reliable technical support to our customers. This past month, the major carrier that provides our VoIP (voice over internet protocol) service had fiber lines cut both in Wisconsin and Washington at the same time. It’s so rare that anything like that would happen in the industry.

It meant our calls were rerouted over the Internet to another highly burdened line. Instead of giving customers the traditional busy signal that we used to expect when call volumes reached high volumes, the calls came through garbled, making it difficult to communicate. The event disrupted our calls for six hours and led us to update our company’s business continuity and disaster recovery plan to initiate a second backbone for long distance calls to prevent any future issues.

 

That’s certainly far from the challenges businesses are facing on the East Coast, but is an example of how any business can be affected by the unexpected and the importance of having a plan in place that addresses the “what ifs.”

Business continuity is essential to business surviving and thriving in the today’s competitive and around-the-clock business world. Here’s a look at just a few things to consider when creating your plan:

Back up your data off site.
In today’s increasingly cloud-based world, even the smallest businesses can store their data off site and receive the redundancy necessary to protect them from losing it – or losing access to it – during a disaster. The standard is to have your data stored at least 50 miles away from your location.

Identify a hot site for business continuity.
Business hot sites, also known as back-up sites, are being created throughout communities to provide a business bunker of sorts where key employees can go to continue their critical business operations. Organizations can buy into the service, often paying a monthly fee to have access if ever needed. A pod-based model also has been developed, delivering organizations a generator-powered portable space where they can step in and keep operating. Marco is not one of these hot site providers, but we do serve as a hot site for some customers. We have all the essential phone and computer equipment and connectivity services they would need to continue operations.

Set your minimum.
When a disaster strikes, it’s not about fully continuing all of your operations. Your plan should identify the minimum you need to sustain. Consider the number of employees and which roles are needed. Identify the tools and applications that need to be 100 percent operational. At Marco, our core is service calls requests and the delivery of supplies so we know we need to have employees to answer calls and dispatch technicians to our customer sites, as needed.

Test it.
Creating the plan is not enough. You need to test it and that does require time – and even some discomfort. It may mean employees need to come in on a Saturday or you have to coordinate a phone service shutdown with your carrier to ensure your backup initiates as expected. A plan is only valuable if it works and you will not know if you do not put it to the test.

It’s not enjoyable planning for worst-case scenarios that could cripple your organization. When done right, it can become second nature to your company just like the fire drills you had in school. You may never need to use your plan. But if you do, it will make all the difference in your success.

Related Posts

Ransomware Response Plan: A Step-by-Step Guide for SMBs
Ransomware Response Plan: A Step-by-Step Guide for SMBs

I've helped businesses through ransomware attacks, and the first hour matters more than almost anything else. What you do in that hour decides how fast you recover, how much you lo...

The Best Data Backup Solutions for Your Business
The Best Data Backup Solutions for Your Business

Too many businesses assume their backups are fine — only to get a terrible surprise if a server crashes, someone deletes the wrong folder, or ransomware locks everything down overn...

Healthcare Cybersecurity in 2026
Healthcare Cybersecurity in 2026

Cyberattacks and IT incidents have risen sharply in 2025 and 2026, and if current trends are any indication, cybercriminals are becoming bolder and far more dangerous. Just this pa...

5 Common Healthcare Cybersecurity Challenges (And How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (And How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

The State of Healthcare Cybersecurity in 2026
The State of Healthcare Cybersecurity in 2026

When I work with healthcare clients, one of the first things I tell them is that I completely understand how difficult it has been to prioritize cybersecurity updates when their va...

NIST Cybersecurity Framework: Full Overview & Guide
NIST Cybersecurity Framework: Full Overview & Guide

Back in 2013, the federal government directed NIST (National Institute of Standards and Technology) to work with industry leaders to build a common framework for cybersecurity risk...

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

The AI Governance Framework Every Org Needs Before Scaling AI
The AI Governance Framework Every Org Needs Before Scaling AI

AI is showing up in the enterprise faster than most governance programs can keep pace with: forecasting models, customer service bots, code generation tools, decision-support syste...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...