Skip to content
../services/security

RISK · DOWNTIME

Continuity & recovery

How long does your business last without its systems?

What it is

Downtime does not always come from an attack. A server failure, an unavailable cloud provider, water damage in the server room or a mishandled operation all produce the same result: you cannot work. The difference between companies that restart within hours and those that lose a week is not luck, but two numbers decided in advance and written procedures somebody has already executed at least once.

The two numbers that structure everything

  1. RTO

    Acceptable downtime

    How long can you stay down before the consequences become serious? Four hours and two days call for entirely different architecture and budget.

  2. RPO

    Acceptable data loss

    How much work are you willing to redo? A daily backup means you can lose a day of data entry.

  3. 01

    Ranking your activities

    Not all your functions carry the same urgency. Payroll, invoicing and production do not come back in the same order as the intranet.

  4. 02

    Procedures and drills

    A plan never executed is an intention. The drill reveals the missing passwords and the forgotten dependencies.

The signs you are not ready

These findings are extremely common, including in companies that believe they have a plan.

  • Nobody has written down how much downtime would be acceptable
  • The recovery plan, if it exists, is stored on the very server that would need restoring
  • Only one person knows how to bring the critical systems back
  • No full restore has been attempted in over a year
  • External dependencies — suppliers, licences, DNS — are documented nowhere

What genuinely makes the difference

01

Defined and owned objectives

RTO and RPO decided by leadership, not by IT alone: these are business trade-offs before they are technical ones.

02

Backups that match those objectives

A daily backup cannot meet a one-hour objective. The architecture follows from the number, not the other way round.

03

Documentation available offline

Procedures, contacts, licences and emergency credentials available even when everything is down.

04

Redundancy on single points of failure

One internet link, one server, one person who knows: these are three forms of the same problem.

05

Periodic drills

An annual exercise, even a partial one, turns a theoretical document into a real capability.

When the outage hits

The order of operations is decided calmly, in advance. Improvising under pressure multiplies the duration.

  1. 01Qualify the nature of the incident: technical failure or compromise, because the response differs radically
  2. 02Activate the planned response team and name one person responsible for decisions
  3. 03Communicate to clients and employees before they discover the problem themselves
  4. 04Restart in the defined priority order, not in the order of convenience
  5. 05Record the gaps observed so the plan can be corrected once the crisis passes

Five questions to place yourself

If you cannot answer with a number or a name, you have your starting point.

  • How many hours of downtime can your business absorb?
  • How much data can you afford to lose?
  • Where is your recovery plan if the network is unavailable?
  • Who makes the decisions if your IT lead is unreachable?
  • When did you last test a full restore?

What we put in place

A recovery plan gets tested, otherwise it is just a document.

We establish your recovery objectives with leadership, then verify that your backups genuinely meet them.

Define our objectives