CoreTech
Backup and business continuity

Business continuity planning before a crisis | CoreTech

Continuity connects people, processes, suppliers, locations, data and IT. A plan becomes useful only when decisions are clear and exercised.

CoreTech tim · 7 min

Cross-functional management, operations and IT team exercises a business-disruption scenario
KEY TAKEAWAYS

What to remember.

  • Continuity is a business plan, with IT recovery as one component.
  • Critical decisions, authority and alternate channels are defined before an incident.
  • Exercises reveal dependencies that documents often miss.

The management answer

A continuity plan explains how the company sustains its most important activities when people, facilities, suppliers or technology are unavailable. A disaster recovery plan describes the return of IT systems, but it does not solve manual work, communication, authority and business decisions.

A good plan is not a large document nobody opens. It is a set of priority decisions, contacts, alternate procedures and exercises that people can use under pressure.

Critical processes and minimum service

For every critical process, define the minimum level of operation that must continue. This may be a limited number of orders, manual processing of urgent requests, alternate communication or temporary work from another location.

Record the people, data, applications, facilities, equipment and suppliers required. Dependence on one person or communication channel remains a risk even when technology is redundant.

Roles and decisions

The plan should state who declares an incident, leads the response, approves alternate operation, communicates with employees and customers, and tracks contractual or regulatory obligations. Define deputies for critical roles.

Provide an alternate communication channel and a contact list available when primary systems are down. Sensitive details must remain protected but accessible to authorised people during a crisis.

Connection with IT recovery

Business priority determines IT recovery sequence. If a process can run manually, IT may first restore a service without an alternative. If manual work creates serious safety or financial risk, the recovery objective must be shorter.

Align continuity with RTO, RPO, backup, suppliers and team capacity. A plan requiring twenty specialists when only four are available is not viable.

Tabletop exercise

  • Choose a realistic scenario and timeline
  • Include management, operations, IT, legal and communications as needed
  • Do not pre-solve the scenario; test existing decisions
  • Record unclear ownership, unavailable contacts and hidden dependencies
  • Assign owners and deadlines for corrective actions

The CoreTech approach

We connect the technical continuity layer with business priorities. Through a service map and exercise, we check whether infrastructure, backup, suppliers and people can deliver the agreed minimum level of operation.

FAQ / AEO

Common questions

Is continuity an IT responsibility?

No. IT leads technology recovery, while business owners define priorities, minimum operation and acceptable impact.

How often should the plan be exercised?

According to risk, at least after significant changes in people, suppliers, facilities, process or technology, plus regular periodic exercises.

Does a tabletop exercise interrupt operations?

No. It is a guided simulation of decisions and communication. A technical failover test can be planned separately.

Sources and further reading

  1. NIST SP 800-34 Contingency Planning Guide ↗
  2. CISA Tabletop Exercise Packages ↗