Security & trust

BC/DR

Planning and preparation to support service continuity through disruption.

Business continuity planning

Our business continuity plan sets response roles, communication routes and restoration priorities for disruptions affecting the platform or organisation. It covers client-facing services alongside the systems and people our team depends on.

Scenarios include platform outages, cyber incidents, equipment loss, connectivity failure and staff unavailability. The plan is reviewed annually and after invocation or material change, helping keep it aligned with the services we deliver.

  • Identify the affected functions and activate the appropriate response roles.
  • Coordinate restoration and communication around the service impact.
  • Review the plan as infrastructure, dependencies or organisational needs change.

Recovery priorities

The platform, client-facing services, email, source control and staff devices have defined recovery priorities. These dependencies help the team decide what to restore first and what is needed to support the recovery effort.

For your own service, consider the complete operating chain. An application journey can also depend on identity, document storage, APIs, notifications and the staff who use submitted information.

  • Understand the systems needed to deliver and support a live service.
  • Consider downstream dependencies alongside the platform itself.
  • Agree service-specific recovery requirements through the applicable engagement.
Review hosting and service resilience

Backups and agreed recovery requirements

Managed backups support recovery of supported service data and configuration under the applicable plan. The backup and continuity arrangements form part of operating the platform, alongside monitoring and incident response.

Where a service needs contracted recovery commitments, discuss the scope, recovery point and recovery time with our team. Include files, connected systems and your own operating processes when defining how the complete service should recover.

  • Review what information and configuration need to be recovered.
  • Agree backup scope, retention and recovery requirements for the engagement.
  • Coordinate recovery responsibilities for external stores and other dependencies.
Discuss Institutional service commitments

Continuity exercises

Tabletop exercises let the team walk through disruption scenarios and practise response decisions. The continuity programme includes outage and lost-device scenarios, with an annual exercise cadence.

Participants consider ownership, escalation, communication and recovery priorities. Recording the discussion helps identify gaps in the plan and improvements to procedures before those decisions are needed during a real disruption.

  • Practise how the team would recognise and escalate a disruption.
  • Review decisions, dependencies and the order of restoration.
  • Capture actions that improve plans, contact routes or preparedness.

Continuous improvement

Exercise outcomes and corrective actions are recorded and used to improve continuity arrangements. Reviews consider what worked, where responsibilities need clarification and which dependencies need more attention.

The plan evolves with platform and organisational changes. Lessons from incidents, exercises and risk assessments can inform updated procedures and the next review of recovery requirements.

  • Assign owners to improvements identified through exercises or incidents.
  • Review plans after material changes or an invocation.
  • Use follow-up activity to check that agreed improvements have been addressed.
Explore learning from incidents
Build with confidence

Secure services start with a conversation.

Talk to our team about your organisation’s security requirements, hosting choices and the services you want to deliver.