Disaster Recovery Plan

Almost every organisation has backups. Very few know how long they would take to come back and how much information they would lose on the way, because they have never tested it. A plan that has not been rehearsed is not a plan: it is a document.

Two numbers your board should know

RTO
How long to come back
The maximum time the business can be down. Decided by management, not by IT, because it is a business decision with a cost attached.
RPO
How much can be lost
The amount of information that can be lost without irreparable damage. It drives how often you back up, and therefore what it costs.
Reality
What it actually takes
The number that comes out of a real restore test. It is almost always a long way from the one written in the plan.

What we do

Business impact analysis: which processes are critical, which systems support them and what each hour of downtime costs. Without this, everything else is guesswork.
Backup strategy review: what is backed up, how often, where it is kept and — most importantly — whether those backups would survive ransomware arriving with domain administrator privileges.
Immutable and isolated backups: designing a strategy that withstands deliberate deletion, not just a disk failure.
Recovery procedures written in enough detail to be executed by someone other than whoever wrote them.
Real restore tests, timed. It is the part almost nobody does and the only one that produces a reliable number.
Drills of full scenarios: loss of the data centre, mass encryption or cloud provider outage.

How we work

1
Impact analysis
Interviews with business areas to set RTO and RPO per process, with the associated cost.
2
Current capability assessment
What is actually backed up, what is left out and whether the backups are within reach of an attacker holding privileges.
3
Plan design
Procedures, roles, call tree, activation criteria and system recovery ordering.
4
Real test
We restore for real, against the clock, and compare the result with the committed RTO.
5
Adjustment
With the real number in hand you decide: either invest to bring it down or adjust the business expectation. Both are valid decisions; ignoring it is not.
6
Periodic drill
We repeat at the agreed frequency, because infrastructure changes and plans age.

What you get

Business impact analysis with RTO and RPO per process, approved by the business.
Assessment of the backup strategy and its resistance to deliberate deletion.
Documented recovery plan, with executable procedures and assigned roles.
Test report with measured times against committed ones.
Improvement plan prioritised by cost-to-downtime-reduction ratio.
Evidence valid for the ENS, ISO 27001, ISO 22301, NIS2 and DORA.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

We have cloud backups. Are we covered?
It depends on whether those backups can be deleted with the credentials an attacker would obtain by compromising your domain. If the answer is yes, you are not covered: you are covered against hardware failure, not against an attack.
Do we have to stop to test a restore?
No. It is restored into an isolated environment and measured there. What is worth doing occasionally is testing the full scenario, within an agreed window.
How often should it be tested?
At least annually, and always after a significant infrastructure change. A three-year-old plan describes an architecture that no longer exists.
Is this the same as business continuity?
The recovery plan is the technology part. Business continuity is broader and covers people, facilities and suppliers. If you need the full framework, we also work to ISO 22301.
How long would it take you to come back?
Half an hour with an auditor to review your backup strategy and decide which restore test would give you the number you are missing.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES