If the Office Disappeared Tomorrow, Could the Business Still Work?
A business-continuity exercise based on a Red Cloud article about theft, fire and water damage: data, applications, credentials, installers, backups and alternate workplaces.
Think beyond the lost hardware
The Red Cloud article starts with a simple scenario: burglary, fire or water damage removes the office computers and perhaps the local backups too. New hardware can be purchased; lost data, application configuration and licensing knowledge are harder to recreate.
List what the business actually needs to resume
Applications, files, databases, license information, user access, configuration and connectivity all matter. A continuity plan should identify the minimum set required to perform the organization's critical work rather than focus only on replacing devices.
Keep recovery dependencies away from the same failure
If the backup media, credentials, documentation and replacement plan all depend on the same office, the same incident can remove the recovery capability. The underlying lesson from the hosted-service sales article is separation of production work from the single physical site.
Test an alternate-workplace scenario
A useful exercise is to assume nobody can enter the office for several days. Can key staff authenticate from another location? Can they reach the required data? Are the instructions and contact details available without access to the normal file server?
Connect continuity with security visibility
Continuity planning benefits from knowing what exists. Scantide Auditor can help identify systems and software that need ownership, while external monitoring can identify public dependencies and certificates that continue to matter when the normal workplace is unavailable.
Questions that usually come next
Is cloud hosting automatically a continuity plan?
No. The original Red Cloud article used hosted desktops as one answer to office loss, but a real continuity plan still needs access, identity, provider, backup and operational procedures.
What should be tested first?
Start with the critical business process: identify the people, applications, data and credentials required to perform it from an alternate location.
Use the evidence, then choose the tool
Scantide Guides explains the problem. Use Online for outside-in public evidence, Auditor for authorized internal visibility, Observe for browser-visible behavior and Guard for active server protection.
All Scantide GuidesScantide ProductsPractical depth: examples, failure modes and what to verify
Field experience from the archive
Design, implement and manage the rCloud Office Cloud solution at Red Cloud iT. Also act as manger for Consultants and founder. Red Cloud is still active and Juha is still involved in all aspects of the business. Technical skills: Windows Server, RDS, Terminal Server, Microsoft Exchange, Sharepoint. Linux
Senior IT consultant with 25 plus years of experience in the business including server operations, DevOps, disaster recovery specialist, backup specialist and project management. Juha also has a keen interest in all aspects of IT security and was the initiator of Syspeace. He is also a Cloud Architect and has had a freelance contract as a teacher in Cloud Security.
Server Operations (Windows, Linux. Netware) , 2nd and 3rd level Support, Project Management. IT Security, DRP/BCP (Disaster Recovery Planning and Business Continuity Planning) and various troubleshooting. Juha has managed for instance Windows Servers, RDS Servers, Citrix, Active Directory, Exchange Servers, Lotus Domino Servers. SQL Server, Oracle, Citrix farms etc. as well as VMWare and Hyper-V environments. Programming languages and techniques .Net, vbs, PowerShell and other related languages needed for server operations and automation.
Be sure to have a Disaster Recover Plan (DRP ) / Business Continuity Plan (BCP) if your site is compromised or an accident should occur. Also in this case, treats the secondary DR location as mission critical data.
You need to make a SWOT analysis and have a Business Continuity Plan (BCP) in place for the different scenarios actually. It sounds expensive (and, yes, it can be) but the day you servers are under attack, you'll be happy you took the time to create one. Trust me. So will your CEO be. Maybe he'll also read this post about hacking yourself .. You should also consider having a Incident Management Plan and process in place ..
14. Backups! Backups! and again. BACKUPS!! Make sure you have good backups (and test them at least once a year for a complete disaster revovery scenario) and make sure you have multiple generations of them in case any of them is corrupted, preferrably stored offsite in some manner in case of a fire, theft or anything really.For day to day operations and generation management I highly recommend using the builtin VSS snapshot method but never ever have it instead of backups. You can also use the built in Windows Server backup for DR as described here
Practical review checklist
- Design, implement and manage the rCloud Office Cloud solution at Red Cloud iT.
- Be sure to have a Disaster Recover Plan (DRP ) / Business Continuity Plan (BCP) if your site is compromised or an accident should occur.
- Senior IT consultant with 25 plus years of experience in the business including server operations, DevOps, disaster recovery specialist, backup specialist and project management.
- You need to make a SWOT analysis and have a Business Continuity Plan (BCP) in place for the different scenarios actually.