IT Resilience Plans
Why your organisation needs an IT Disaster Recovery Plan
Our increasing dependence on IT services means organisations need a clearer understanding of:
The recoverability of the critical applications and data they use — whether on premises or in the cloud
The content and warranties in the agreements written with service providers
The resilience of your providers, and how they'll treat your organisation if they suffer a disruption
We help Australian organisations address all three, and develop IT Disaster Recovery Plans that are practical and meet the recoverability needs of the business.
What’s included
Assessing your capability
We audit your capability across people, process, technology and third-party suppliers. In the context of your organisation's recoverability needs, we identify recovery gaps and priorities.
IT DR documentation review
We review your documentation and focus on:
Is it complete, and does it cover all your critical application systems and infrastructure?
Is it appropriate, and will it support your IT staff during a disruption? Are the Technical Recovery Procedures complete?
Does it address what you need to know if a primary SaaS provider suffers an outage?
Is your Incident Management Plan integrated with your IT DR Plan?
What's the testing schedule?
IT DR testing and training
Plans are only useful if they're tested with the people responsible for recovery when disaster strikes.
Where IT disaster recovery fits
IT disaster recovery planning works best once you know what you're recovering for. If you haven't run a Business Impact Analysis yet, that's usually the right starting point — it sets the recoverability targets your IT systems need to hit.
APRA-regulated entities
If your organisation is regulated by APRA (including ADIs, general insurers, superannuation funds, and life insurers) CPS 230 (Operational Risk Management) sets specific requirements for IT DR planning third-party risk management.
We have considerable experience helping regulated entities meet these obligations, from initial gap assessment through to full CPS 230 compliance.
Where next?
Does your IT keep you up at night? Not sure how resilient the services you're relying on actually are? Contact us and we'll talk through where to start.
Get in touch