Essential tips for a successful disaster recovery plan

November 2019 Security Services & Risk Management

Byron Horn-Botha, lead: Arcserve Southern Africa Channel and Partnerships, says that there is no excuse for not building a successful DR plan at a time when tolerance for critical application downtime is rapidly dwindling. “Today, a tolerance of less than fifteen minutes is not uncommon. With availability requirements like that, companies are pressured to get it right,” he says.

Building a successful DR plan requires active participation across all business units, so that everyone at the table has a clear understanding of both data risk and expectations for recovery.

“The right resources and technology to deliver against recovery objectives have their place, of course, but without a foundational knowledge, businesses can end up guessing and that can translate into catastrophe,” he says.

The following highlights some of the key elements of Arcserve’s recommended DR planning process.

1. Set recovery expectations

We live in a world where customers expect data and applications to be available anytime, anywhere, and with touch-of-a-button ease. Furthermore, there’s an expectation that if something goes wrong, recovery can happen swiftly, and without data loss.

But this is not always the case and it’s a conversation companies should be having regularly across their business units. It’s crucial that everyone understands what the organisation wants versus what can be delivered.

2. Document business objectives and availability requirements

Business objectives and the criticality of the data and applications being protected in the organisation must be documented.

To create an effective business continuity and disaster recovery (BCDR) plan, it is essential to be intimately familiar with the organisation so that you can determine an acceptable level of risk. This can only be achieved through engagement across the company, which will determine the actual amount of downtime that is sustainable for each system and application.

Then it is necessary to identify interdependencies to ensure no single piece of the DR puzzle has been neglected. This means mapping out how data flows from one application to the next and facilitates a clearer picture of what needs to be protected. It also underscores the level of availability with a view to spotlighting what applications in the value chain cannot be recovered with the requisite speed necessary to support another critical application.

3. Think beyond costs

Getting buy-in for infrastructure improvements, given the competing demands for business investment, can be difficult. It is crucial to discuss any discrepancy between the cost of a company’s DR solutions, which are recurring, versus the loss expectancy – should systems go down for an extended time, or be lost entirely. The improvement of IT infrastructure as a cost must be considered as an ongoing investment in the health of the organisation.

4. Test the reliability of the DR solution

Testing the recoverability of critical apps should be done consistently. DR testing really needs to be a continuous effort, so the organisation is confident with both recovery points and times that can be achieved. This is where a backup and recovery solution that offers automated, application-level testing capabilities and reporting becomes critical.


Byron Horn-Botha.

5. Test the disaster preparedness of your people

Of course, automated testing covers the technical component of your DR plan but it would be unwise to rely solely on automated reports. The value of a full DR drill is that it illuminates how people behave, and identifies which processes work and which don’t. It also helps to verify whether or not these processes have been fully documented.

6. Is your DR plan up to the task?

Ransomware only represents one of many threats that must be considered when creating a DR plan, but the likelihood of infection – a near certainty now – is changing the game. As risks of ransomware infection escalate, the importance of a thorough, effective, and rehearsed DR plan has never been more crucial.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Visualise and mitigate cyber risks
Security Services & Risk Management
SecurityHQ announced its risk and incident management capabilities for the SHQ response platform. The SHQ Response Platform acts as the emergency room, and the risk centre provides the wellness hub for all cyber security monitoring and actions.

Read more...
Eighty percent of fraud fighters expect to deploy GenAI by 2025
Security Services & Risk Management
A global survey of anti-fraud pros by the ACFE and SAS reveals incredible GenAI enthusiasm, according to the latest anti-fraud tech study by the Association of Certified Fraud Examiners (ACFE) and SAS, but past benchmarking studies suggest a more challenging reality.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Proactive strategies against payment fraud
Financial (Industry) Security Services & Risk Management
Amid a spate of high-profile payment fraud cases in South Africa, the need for robust fraud payment prevention measures has never been more apparent, says Ryan Mer, CEO of eftsure Africa.

Read more...
How to prevent and survive fires
Fire & Safety Security Services & Risk Management
Since its launch in August 2023, Fidelity SecureFire, a division of the Fidelity Services Group, has been making significant strides in revolutionising fire response services in South Africa.

Read more...
A long career in mining security
Technews Publishing Editor's Choice Security Services & Risk Management Mining (Industry)
Nash Lutchman recently retired from a security and law enforcement career, initially as a police officer, and for the past 16 years as a leader of risk and security operations in the mining industry.

Read more...
Risk management: There's an app for that
Editor's Choice News & Events Security Services & Risk Management
Zulu Consulting has streamlined the corporate risk management process with the launch of Risk-IO, a web-based app designed to consolidate and guide risk managers through the process, monitoring progress as one proceeds.

Read more...
Integrated information platform for risk management
Editor's Choice News & Events Security Services & Risk Management
Online Intelligence recently launched version 7 of its CiiMS risk and security platform. Speaking to SMART Security Solutions after the launch event, the company’s Arnold van den Bout described the enhancements in version 7.

Read more...
Global Identity Fraud Report revealing eight-month ‘mega-attack’
Editor's Choice Security Services & Risk Management
AU10TIX recently released its Q4 Global Identity Fraud Report, with the research identifying two never-before-seen attack patterns, with the worst case involving 22 000+ AI-generated variations of a single U.S. passport.

Read more...