Research & InsightsCybersecurity

Key steps for successful business continuity planning

Essential strategies to keep your business running when the unexpected happens, from backups that actually restore to a plan people have practised.

FLYONIT Research Team26 September 20246 min read
Executive summary

The short version

A continuity plan is only as good as its last test. Many businesses have backups they have never restored and plans nobody has read.

The practical path is short: know what matters most, decide how long you can be without it, and test the recovery of those systems on a schedule.

Findings

What we found

1

Recovery time is rarely defined

Most organisations we assess have not agreed how quickly each system must be back. Without that target, backup design is guesswork.

2

Ransomware is now the leading trigger

Hardware failure used to drive most recoveries. Today it is ransomware, which also encrypts poorly protected backups.

3

Practised plans work, written plans do not

Teams that run a recovery exercise at least once a year recover in hours. Teams working from an untested document take days.

Recommendations

What to do next

  • Rank systems by business impact and agree a recovery time for each.
  • Keep at least one backup copy offline or immutable so ransomware cannot reach it.
  • Run a restore test every quarter and a full recovery exercise every year.

Methodology and sources

  • Drawn from business continuity and disaster recovery assessments FLYONIT delivered for professional services, healthcare and industrial clients.