sandra_gittlen
Contributing Writer

Digging into disaster recovery

Opinion
Jan 21, 20043 mins

* How to be prepared for all eventualities

It’s the start of the new year and there’s no better project to dig your feet into than improving your disaster recovery plans. This year is bound to be the one where stockholders and company executives alike ask you to lay out your plans and prove that you’ve got every scenario covered.

Answering to pressure internally and externally will make you want to put together a well-tested plan that accounts for just about everything – fire, flood, terrorism, equipment failures, and physical plant malfunctions. No disaster is too big or too small to throw into the mix.

Let’s start with the word “disaster.” It means different things to different people. Your chief financial officer’s laptop being stolen might be counted as a disaster if the company’s most important financials are on the hard drive. Having a sprinkler malfunction above your most used server might constitute a major disaster. If your company is mostly comprised of a far-flung workforce, having access cut off to the home office might be a disaster. It’s important to know what you think of as a disaster vs. an inconvenience.

You also need to know how soon you’ll need access to the information in the affected locales. What if access was cut off for an extended – even permanent – period of time? What would the fallout be? Do you have a failover plan? Is the data replicated somewhere else?

Let’s remember, too, that creating a disaster recovery plan typically means committing resources to failover networks. And there’s no guarantee those networks will ever need to be used – it’s insurance. Is that a cost your company wants to assume? How much of a guarantee of data recovery does the company need and for what specific information? There’s probably no need to replicate every single aspect of your corporate network – only the data that is mission-critical. And you can put different layers of failover based on how fast you need the information recovered.

These are all things that need to be plotted out and tested. It’s important to get a cross-functional team involved in this planning – don’t make it an IT-only project. Physical plant needs to be involved. High-level executives need to know what’s going on. And other parties are going to want a glimpse at what you have planned.

Even if you went through this exercise last year, I recommend that you revisit it now. Things change a lot in a year – what data you need to protect, what systems you have in place and what your service providers are doing to protect you, just to name a few factors.

Good luck…