Designing and implementing a functional business-continuity plan is a multimonth process. Here’s what to consider.
Walk away from this article with two pieces of data in your mind:
1. The University of Texas estimates that more than half of small and midsize businesses (SMB) that lose data in a disaster go out of business within two years
2. Gartner estimates that less than half of all midsize businesses and only 25% of small businesses have disaster recovery plans in place.
If there is any bright spot in the legacy of Hurricane Katrina, it is that business, government and education institutions seem to have a better understanding of the requirement for business continuity and disaster recovery. Yet, as the Gartner numbers testify, there is still a chasm between understanding the requirements and generating the organizational commitment to meeting them.
Like all business leaders with priorities, SMB owners and executives must juggle a number of things that compete for time and resources. As a result, they tend to put business continuity into the “solve tomorrow” pile until right before (or right after) an incident. This is a critical, sometimes disastrous mistake. Like all business-essential Information Technology (IT) programs, designing and implementing a functional continuity plan is a multimonth process. Here is why:
* Business continuity is a business process: A functional business-continuity plan is more about understanding and protecting key business process than it is about managing IT assets. As such, it will require input from key business leaders and will necessitate in-depth planning and preparation so that every person in the organization knows what to do in the event of an emergency.
* Assessment and design: Developing the core business-continuity plan is not a one-person job; it requires input from a cross-functional team that includes sales, communications, finance, back office, human resources and IT leaders. Without that input, it is impossible to correctly prioritize and tier support systems tol meet demands during a disaster incident
* Back order of critical elements: The back order log for business-sized power generators from reliable manufacturers is often 30 weeks. That means if you order today, your generator will be available in seven months. If you try to substitute this essential element with a generator from your local Home Depot, you’ll find that the power from household generators is too unstable for use by IT equipment without some type of power cleaning device. In some cases, the power simply won’t turn on, while in others you risk permanent damage to your assets.
* Entering the telecommunications queue: It usually takes a long time to get telecommunications providers to install backup lines to SMBs, because: 1) the backup service provider is (we would hope) different from your primary provider; you will have to initiate a new business relationship, including all of the associated legal and administrative hurdles; and 2) as the backup line will not represent a sizeable business opportunity, you will have to wait in line behind more profitable opportunities – including some that enter the queue after you do.
* Implementation: Once all of the pieces of the continuity solution are in place, building the system, connecting it to ongoing IT programs and aligning it with the corresponding business processes takes time. Assuming that the IT staff (or person) will also have to focus on their regular job at the same time they implement the new system, view this commitment in days or weeks as opposed to hours.
* Temporary relocation: In many disaster scenarios, resuming operations at the same location will no longer be possible. It will be necessary to have plans and agreements in place for a backup location and logistics for resuming operations in the new facility. This also involves having an IT layout pre-planned for the backup location to ensure that all of your critical systems will function at the secondary facility.
* Testing: Your business-continuity system is only as good as its last test. Like flashlight batteries, smoke detectors or brakes, you don’t want to find out about shortfalls during an emergency. Regular and systematic testing in a number of different situations will consume time and effort, but it is really the only way to know if systems are functioning properly. Plan to extend tests over weeks and months to make sure that the system aligns fully with business operations.
In the end, you can beat the odds, but not the percentages. Though Gartner and the University of Texas did not correlate the relationship between business continuity and disaster survivability, CDW’s experience across thousands of customers leads us to believe that the link between the two is significant. If you are inclined to agree, we would recommend that you get started today with the following steps: As mentioned above, convene a cross-functional team to evaluate the business requirements and tier data based on its importance to operations. Organizations should back up data frequently to ensure records are kept, and consider upgrading the backup equipment to a faster version to reduce the time it takes to complete a backup cycle. Organizations should add uninterrupted power supplies (UPS) for critical servers, network connections and selected personal computers to keep the most essential applications running. Documentation should include updated configuration diagrams of the hardware, software and network components to be used in the recovery. The plan should also include logistical details, including travel to backup sites, and even who has spending authority for emergency needs. Telecommunications backup must involve both redundancy and alternatives. In the case of spot outages, redundancy may be enough. For larger outages, alternatives such as wireless phones, wireless data cards and satellite phones, should be considered. A strong relationship with hardware, software, network and service vendors can help expedite recovery, as these vendor contacts often can work to ensure priority replacement of critical telecommunications equipment, personal computers, servers and network hardware in the event of a disaster. This is especially important for small and midsize organizations, which may lack the resources that larger companies can tap in an emergency.
1. Conduct a business-impact assessment:
2. Take steps to protect data:
3. Review power options:
4. Document, test and update the disaster preparedness plan:
5. Consider telecommunications alternatives:
6. Form tight relationships with vendors:
In the end, there is no guarantee against a natural or man-made disaster, only a very high probability that you will fail without a detailed business-continuity plan. Though the time and resources required will conflict with other organizational priorities, executives need to dedicate the time to ensure business survivability. Tomorrow is already too late.




