Would Your Business Keep Running During a Disaster?

Would Your Business Keep Running During a Disaster?

Business continuity and disaster recovery often are married under the BC/DR acronym in the technology world. But they are actually very different and you can have one without the other.

iStock_000072597499_FullBoth help organizations prepare for disruptive events that could quickly and dramatically shut down operations. We often think of natural disasters, but the more common occurrences are related to power outages or a malware attack on software and computer systems. Virus threats are more pervasive and have elevated the need for BC/DR planning.

Time and time again, I find that organizations are not prepared. Many times a lack of understanding between business continuity and disaster recovery planning prevents organizations from taking the steps they need to. Having a back-up system is not enough.

What’s the Difference?
Simply put, disaster recovery ensures you have something to go back to after a disruptive event. Business continuity outlines how you will quickly resume operations or keep working through it until the normal operations can be restored. That may be a matter of hours or in severe cases, days.

Take data. Conducting back-ups as part of a disaster recovery plan ensures the data is not lost. Business continuity planning ensures that data can be accessed during a disaster.

What’s in it?
Business continuity plans outline how you will continue to communicate, where employees will go and how your key business functions will operate during a disruptive event.

The details of a plan vary based on the size and scope of an organization. The key is to pull a team together and determine what are mission critical parts of your business. To get started, consider:

  • What are the apps you need to access no matter what?
  • How will you reroute inbound and outbound calls?
  • Do you need a generator or other equipment to maintain power for specific equipment or work areas?
  • Who are your mission critical team members who need to keep working through a disaster and who are their back-ups?
  • Where will they go if their work areas are not available?

How do you test it?
The best way to test the system is turn everything off and create an environment as though a disaster has just happened. Yes, that is scary. But it is far better to do it in a controlled environment where you can see what’s working as intended and what’s not. You may not want to turn everything off at once, but there should be a plan for testing each component. Trust me. Role-play is not sufficient.

A business continuity and disaster recovery plan is just paper. You need to validate that it will work. I can guarantee you that if you don’t test your plan, it will get tested for you.

Shortly after moving to our new corporate headquarters, our plan got tested by a power outage. That’s not the way you want your plan to get tested. It’s common to find holes in the planning and execution. We learned that while our Support Desk phone systems were plugged into generator power, the computers at each workstation were not. We added an Uninterruptible Power Supply (UPS) to each station and connected them to generator power. We also added generator power to the reception console to ensure our front desk could function as well during a disruptive event. That’s much easier than running extension cords from the generator to the areas you need power.

Are you ready for a catastrophe?
It’s a question we don’t like to consider. But not being able to answer “yes” to this question could cripple your organization – in a matter of minutes. The threats are not just weather related anymore. They also include cyber attacks. Take the time to create a disaster recovery and business continuity plan and then test it. You’ll be glad you did.

Related Posts

Ransomware Response Plan: A Step-by-Step Guide for SMBs
Ransomware Response Plan: A Step-by-Step Guide for SMBs

I've helped businesses through ransomware attacks, and the first hour matters more than almost anything else. What you do in that hour decides how fast you recover, how much you lo...

The Best Data Backup Solutions for Your Business
The Best Data Backup Solutions for Your Business

Too many businesses assume their backups are fine — only to get a terrible surprise if a server crashes, someone deletes the wrong folder, or ransomware locks everything down overn...

Healthcare Cybersecurity in 2026
Healthcare Cybersecurity in 2026

Cyberattacks and IT incidents have risen sharply in 2025 and 2026, and if current trends are any indication, cybercriminals are becoming bolder and far more dangerous. Just this pa...

5 Common Healthcare Cybersecurity Challenges (And How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (And How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

The State of Healthcare Cybersecurity in 2026
The State of Healthcare Cybersecurity in 2026

When I work with healthcare clients, one of the first things I tell them is that I completely understand how difficult it has been to prioritize cybersecurity updates when their va...

NIST Cybersecurity Framework: Full Overview & Guide
NIST Cybersecurity Framework: Full Overview & Guide

Back in 2013, the federal government directed NIST (National Institute of Standards and Technology) to work with industry leaders to build a common framework for cybersecurity risk...

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

The AI Governance Framework Every Org Needs Before Scaling AI
The AI Governance Framework Every Org Needs Before Scaling AI

AI is showing up in the enterprise faster than most governance programs can keep pace with: forecasting models, customer service bots, code generation tools, decision-support syste...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...