Guide · Worldwide

Business Continuity and Disaster Recovery Plan Starter

Regulators, insurers, and enterprise customers now ask for evidence that recovery has been tested, not merely documented. This starter follows ISO 22301 and NIST SP 800-34, and gives you the structure to build a plan your organization can actually execute under pressure.

Step one: business impact analysis

  1. 01List the business processes that generate revenue, serve customers, or carry legal obligations.
  2. 02For each process, record the maximum tolerable outage and the financial or regulatory impact per hour.
  3. 03Map each process to the applications, data stores, suppliers, and people it depends on.
  4. 04Identify single points of failure, including individual staff members and sole-source suppliers.
  5. 05Rank processes into tiers so recovery investment follows business criticality.

Step two: set and record objectives

  • Recovery time objective for each tier, agreed by the business owner rather than by technology staff.
  • Recovery point objective defining the acceptable amount of data loss.
  • Minimum viable service level that counts as recovered, including degraded operating modes.
  • Dependencies on cloud provider regions, and the documented response to a regional failure.
  • Supplier recovery commitments captured in contracts, not assumed from marketing material.

Step three: build the recovery runbooks

  • Activation criteria, declaration authority, and the escalation tree with out-of-band contact details.
  • Technical restore procedures, sequenced by dependency, with named owners and expected duration.
  • Backup architecture including immutable or offline copies isolated from production credentials.
  • Alternate work arrangements for staff, facilities, and payment or payroll continuity.
  • Customer, regulator, and employee communication templates prepared before an event.
  • Return-to-normal criteria and the data reconciliation steps required after failover.

Step four: test and improve

  1. 01Quarterly: restore a sample of production data and record the time taken and issues found.
  2. 02Twice yearly: run a tabletop exercise covering a cyber-driven outage such as ransomware.
  3. 03Annually: perform a full failover or technical recovery test for at least one tier one service.
  4. 04After every test and real event, complete a review and feed the actions into the risk register.
  5. 05Review recovery objectives whenever the business, architecture, or supplier base changes materially.

Need a continuity plan that survives a real outage?

Dephiant runs the business impact analysis, writes the runbooks with your engineers, and facilitates the exercises that prove recovery works.