Disaster recovery during Covid-19 and beyond

Issue 5 2021 Security Services & Risk Management

The Covid-19 pandemic has been the catalyst for momentous change throughout the IT landscape and for disaster recovery (DR) in particular as the global pandemic made widespread disruption and uncertainty a clear and present reality.


Andrew Cruise.

“The onset of Covid-19 was one kind of disaster as companies had to quickly invoke business continuity and disaster recovery plans to cope with employees being denied access to their offices. It has put into sharp focus many enterprises’ lack of DR plans and accelerated the penetration of Disaster Recovery as a Service (DRaaS) in the market,” says Andrew Cruise, managing director at Routed, a vendor-neutral cloud infrastructure provider.

According to Cruise, having coherent DR plans in place are a non-negotiable, especially given the wide-ranging threats today’s businesses face on an ongoing basis. He says that while there are a number of obvious disasters that CIOs should be planning for, there are some no less high-profile disasters that don’t receive adequate attention until it’s too late. “Ransomware is, of course, one of the most common and insidious disasters that can occur, but another which receives very little press, mostly due to embarrassment, is internal sabotage, closely followed by employee error. These are much more common than fire, theft and flood and all require a slightly different approach to ensure a resolution.

Four key DR factors

Cruise highlights four key factors to keep in mind while planning for effective recovery from disasters.

1. Disaster Recovery (DR) plans are the technical part of business continuity (BC) planning and should never sit in isolation. The objective of DR plans is to satisfy business continuity objectives, which are typically deployed to maintain some level of business function in the face of an unexpected destructive event. The scope of a DR plan usually covers IT only. This would cover the accessibility of a recovery environment at a minimum, including the recovery and usability of data and applications and the network’s access to said data.

2. Test your DR plans. If your DR doesn’t work, it’s like paying for insurance and then not getting a pay-out when you claim. Disaster recovery is not trivial to implement, but it should be easy enough to test and your provider should have this built into their solution, both technically and commercially. No one wants to fix the roof while it is raining or change a tyre at 100 km/h and businesses cannot afford to address serious technical problems in the face of a major disaster. Testing DR plans shows up performance and capacity issues and allows organisations to plan accordingly, which may include switching providers.

3. Find the right skills. Anyone who is part of a DR team should be well organised and calm in the face of pressure. Clearly, technical skills to operate, manage and test the environment are also required. Enterprises need to ensure they have access to these skills from their provider.

4. Consider the costs. Although cloud-based disaster recovery solutions are designed for the enterprise, it is available, in scale, and therefore within the reach of smaller businesses too. Disaster recovery should not be more than 20-30% of an organisation’s IT production budget. Keep in mind that it is not necessary to invest in capital by purchasing the target hardware and software. Businesses can buy DRaaS and rent what is needed based on usage.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Visualise and mitigate cyber risks
Security Services & Risk Management
SecurityHQ announced its risk and incident management capabilities for the SHQ response platform. The SHQ Response Platform acts as the emergency room, and the risk centre provides the wellness hub for all cyber security monitoring and actions.

Read more...
Eighty percent of fraud fighters expect to deploy GenAI by 2025
Security Services & Risk Management
A global survey of anti-fraud pros by the ACFE and SAS reveals incredible GenAI enthusiasm, according to the latest anti-fraud tech study by the Association of Certified Fraud Examiners (ACFE) and SAS, but past benchmarking studies suggest a more challenging reality.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Proactive strategies against payment fraud
Financial (Industry) Security Services & Risk Management
Amid a spate of high-profile payment fraud cases in South Africa, the need for robust fraud payment prevention measures has never been more apparent, says Ryan Mer, CEO of eftsure Africa.

Read more...
How to prevent and survive fires
Fire & Safety Security Services & Risk Management
Since its launch in August 2023, Fidelity SecureFire, a division of the Fidelity Services Group, has been making significant strides in revolutionising fire response services in South Africa.

Read more...
A long career in mining security
Technews Publishing Editor's Choice Security Services & Risk Management Mining (Industry)
Nash Lutchman recently retired from a security and law enforcement career, initially as a police officer, and for the past 16 years as a leader of risk and security operations in the mining industry.

Read more...
Risk management: There's an app for that
Editor's Choice News & Events Security Services & Risk Management
Zulu Consulting has streamlined the corporate risk management process with the launch of Risk-IO, a web-based app designed to consolidate and guide risk managers through the process, monitoring progress as one proceeds.

Read more...
Integrated information platform for risk management
Editor's Choice News & Events Security Services & Risk Management
Online Intelligence recently launched version 7 of its CiiMS risk and security platform. Speaking to SMART Security Solutions after the launch event, the company’s Arnold van den Bout described the enhancements in version 7.

Read more...
Global Identity Fraud Report revealing eight-month ‘mega-attack’
Editor's Choice Security Services & Risk Management
AU10TIX recently released its Q4 Global Identity Fraud Report, with the research identifying two never-before-seen attack patterns, with the worst case involving 22 000+ AI-generated variations of a single U.S. passport.

Read more...