Backup and continuity

If email, files or the server stop tomorrow

Many businesses know they have backups but cannot clearly explain what would happen if an essential service stopped tomorrow morning.

Good preparation does not require imagining every possible disaster. It requires understanding the most important dependencies, responsible people and acceptable recovery time.

This is a simple exercise for management and the person responsible for IT.

Start with activities, not devices

Instead of asking “what server do we have?”, ask:

  • how employees communicate;
  • where active documents are stored;
  • how invoices are issued;
  • how orders are received;
  • which applications are required to serve customers;
  • which systems control scheduling, payroll or building access;
  • which information must be available today, tomorrow or this week.

A computer can be replaced. A poorly understood dependency is harder to recover.

Scenario 1: email is unavailable

An email outage may be a provider incident, domain issue, compromised account or configuration error.

Ask:

  • do employees know how to report the problem without email;
  • is there a contact list outside the primary system;
  • can customers reach the business another way;
  • can authorized people check service status;
  • are administrative accounts and passwords available;
  • are important messages stored only in personal mailboxes;
  • do key people have an agreed backup channel.

A business that uses email as its only coordination method should establish a temporary alternative such as phone, a secondary messaging service or a call tree.

Scenario 2: shared files are unavailable

The first question is whether files are missing, deleted, encrypted, locked or simply unreachable because of a network problem.

The response depends on where they live: local server, SharePoint, OneDrive, cloud storage, NAS or a business application.

Review:

  • which teams are stopped;
  • which documents are truly critical;
  • whether recent copies exist;
  • whether permissions and versions can be restored;
  • who authorizes recovery;
  • how much data may be lost;
  • how long restoration may take;
  • how to avoid overwriting good data during the emergency.

A copy is useful only when it is protected, available to the right people and tested.

Scenario 3: the server or main application fails

A server may host files, a database, accounting software, a specialized application or several roles at once.

Impact depends more on what it does than on its age or brand.

Document:

  • hosted applications;
  • dependent users;
  • involved vendors;
  • required licences;
  • administrative accounts;
  • available backups;
  • last tested restore;
  • replacement hardware or environment;
  • service restoration order;
  • checks required before reopening access.

A restored server is not automatically a ready service. Applications, permissions, printers, integrations and access must also work.

Scenario 4: Internet or the internal network stops

Fast Internet does not guarantee a resilient network.

Ask:

  • is there only one provider or connection;
  • do phones depend on Internet access;
  • are payments, cameras or building access affected;
  • is cellular tethering realistic;
  • which applications can work offline;
  • who can reach the firewall and provider accounts;
  • do employees know how to distinguish a local issue from a general outage.

The temporary solution should fit the business. Not every organization needs a second connection, but it should understand the consequences of having no alternative.

Backup, availability and continuity are different

A backup is a copy that can be used to recover data or systems.

It does not automatically prove:

  • that the service remains available during an outage;
  • that every required component is included;
  • that administrative access is available;
  • that the application vendor will cooperate;
  • that recovery meets the expected timeframe;
  • that employees know what to do while waiting;
  • that restored data is recent enough.

Continuity includes people, communication, procedures, vendors and temporary workarounds as well as technology.

Two timeframes in plain language

IT specialists often use the terms RTO and RPO. Management can begin with two simpler questions.

How long can we wait?

This is the maximum acceptable time before the activity is restored.

The answer may vary:

  • minutes for payment or a clinical application;
  • hours for active files;
  • a day for a rarely used archive.

How much work can we lose?

This is the acceptable gap between the most recent recoverable copy and the incident.

A daily backup may mean losing almost a day of work. More frequent copies may reduce that loss, but they still require protection and testing.

Quick impact worksheet

For each important activity, complete:

| Activity | Dependent system | Owner | Acceptable time without service | Acceptable data loss | Temporary workaround | Last recovery evidence | | — | — | — | — | — | — | — | | Invoicing | Accounting software | Management/finance | 4 hours | 1 hour | Limited manual entry | Date/test | | Client documents | Server or SharePoint | Operations | 2 hours | 30 minutes | Approved local copies | Date/test | | Email | Microsoft 365 | Management/IT | 2 hours | Provider-dependent | Phone/secondary channel | Date/exercise |

These values should be chosen by the business, not invented by the IT provider.

What useful evidence should show

A serious review should produce simple evidence:

  • essential systems list;
  • backup locations;
  • recent alert history;
  • tested restore result;
  • observed restoration time;
  • people authorized to start recovery;
  • recoverable administrative access;
  • restoration order;
  • external dependencies;
  • corrective actions and owners.

The Canadian Centre for Cyber Security recommends identifying critical data, defining roles and testing backup and continuity procedures regularly.

Start small, but start before the emergency

A small business does not need a hundred-page manual.

It needs a usable first version:

1. five essential activities; 2. the systems supporting them; 3. one responsible person and one backup person; 4. vendor contact information; 5. acceptable downtime; 6. last restore evidence; 7. the three highest-priority gaps.

A backup and recovery assessment can turn these answers into a clearly scoped list of work and decisions.

If recovery depends on several vendors, accounts, backups and people, a managed and co-managed IT review can clarify who keeps the thread after the urgent event.

Contact Montreal IT to review dependencies, backups and recovery priorities.

Related resources