Haven’t you heard about cyber-attacks and the loss of vast amounts of data in the business world? But do you know what it is and how to put a BCP in place? We’ll tell you now.
In general, few SME business owners stop to think about what would happen if they suffered a cyberattack resulting in the loss of all their company’s data. They usually assume that with a good cybersecurity system in place, they’re safe. As many cybersecurity firms point out, no one is 100% protected, and anyone who believes otherwise is missing the point. Today’s cybercriminals are constantly evolving, developing new ways every day to interfere with companies’ information systems. If large companies are exposed to these cybercriminals, what makes SMEs, freelancers, or micro-businesses any less exposed? So what are the possible solutions to protect your business and avoid the loss of all its data?
What is a business continuity plan (BCP)?
A business continuity plan, or BCP, refers to a set of measures a company adopts to ensure its operations are not substantially affected by events beyond its control. Putting a BCP in place covers everything related to the efforts a company makes to keep running smoothly under all circumstances. The data recovery system (DRS) — the way data is recovered after a disaster so the business can keep operating — and high availability of systems are two of the categories included in a BCP.
A business continuity plan, or BCP, is a logistical plan for how an organization should recover and restore its critical resources, whether partially or fully disrupted, within a predetermined timeframe following an unwanted disruption or disaster.
Considerations for a BCP
When implementing a BCP, two main considerations must be taken into account: the RPO (Recovery Point Objective) and the RTO (Recovery Time Objective).
The first refers to the volume of data at risk of loss that the organization considers tolerable. In other words, it determines the maximum acceptable loss of data entered since the last data backup, up until the system fails. It does not depend on recovery time.
As for the second, it expresses the length of time an organization can tolerate the shutdown of its critical applications and the associated drop in service level, without affecting the continuity of any business activity.
Tolerable downtime keeps shrinking, due to the growing intensity of business processes, their globalization, and the need for real-time cooperation between multiple internal and external units. In addition, a growing number of transactions are now paperless, which makes recovery practically impossible in the event of data loss.
Data recovery plans to ensure business continuity
The disaster recovery plan (DRP) is a recovery process covering essential data, hardware, and software. Its aim is to enable a business to resume operations after a significant data loss. It’s a process or workflow that enables data recovery, whether through physical or software-based solutions. This allows the business to resume operations even in the event of an incident — natural, human-caused, ransomware, or other cyberattacks on its systems.
A disaster recovery plan aims to provide the business with alternative means of carrying out its normal functions when the usual means are unavailable due to an unforeseen event.
The DRP focuses on the IT systems that support the company’s essential functions. It differs somewhat from what is meant by a BCP, which involves keeping a company’s essential aspects running despite major disruptive events. It can be said that the DRP is a subset of the BCP.
Having and maintaining a DRP is essential for any type of business in order to assess the impact of a disaster situation. It also enables a quick recovery and relaunch of operations after a loss. This helps minimize the risk of capital loss and, above all, avoid the loss of trust in the company among its customers.
What points should be considered when designing a DRP?
To properly design a DRP, the first step is to establish what needs to be protected and how long it will take to recover it. After that, drafting the document should cover the remaining considerations to take into account. These considerations are:
- Assess the tolerable downtime;
- Review the SLA to understand the consequences of a disaster;
- Set target recovery times for each part of the business and department;
- Take inventory of hardware and software, ranked by importance to the business;
- Have the contact details of the technical support provider(s) for each piece of hardware or software application;
- Recovery order for each system;
- Specify roles and responsibilities;
- Implement a communication plan;
- Additional documentation.
Lastly, keep in mind that the DRP is a constantly evolving document. There’s no point designing and putting a disaster recovery plan in place just to leave it on a shelf. You need to familiarize your staff with the DRP and make sure they know their role. It will need to be tested, continuously reviewed, and kept easy to update or extend. This will allow you to protect the core of your IT infrastructure against any unforeseen disaster as effectively as possible.
