The continuity readiness checklist
26 items, in the order we would actually do them. Stage 2 is the one that matters most: a backup nobody has restored is a hope with a schedule attached. Print it, mark it up, give it an owner.
1. Decide what matters
- Name the three things that must work for you to trade.Taking orders, taking payment, knowing what is in stock — whatever yours really are.
- For each, agree how long you could be without it.This is your recovery time objective. Ask the person who would take the calls.
- For each, agree how much recent work you could afford to lose.This is your recovery point objective, and it is what the backup schedule should be derived from.
- Write both numbers down where someone else can find them.
- List the systems each of the three depends on.Including the ones you do not own.
2. Make recovery real
- Confirm every critical system is backed up.
- Confirm the backup lives somewhere it cannot be deleted along with the original.Separate account, separate credentials. Same console is not separate.
- Restore one thing, for real, and time it.The single highest-value item on this page.
- Write down what broke during the restore.Something always does. That list is the actual plan.
- Compare the measured restore time to the number you agreed in stage 1.
- Diarise the next restore test.
3. Remove the single points of failure
- List anything only one person knows how to do.
- Write down the top three while that person is still here.An hour each. The cheapest insurance on this page.
- Confirm someone else can get into the domain registrar.
- Confirm someone else can get into hosting, banking and payments.
- Confirm the phone number receiving one-time passwords is reachable by more than one person.This is the one that strands people.
- Record where credentials live and who can reach them.
4. Know your reporting obligations
- Write down the CERT-In route: within six hours of becoming aware of a qualifying cyber incident.
- Write down the DPDP route: affected people without delay, detailed report to the Board within 72 hours.
- Name the person who makes the call on each.
- Check your log retention against both requirements.One year for personal data under Rule 6(1); 180 days of ICT logs, kept in India, under the CERT-In Directions.
5. Rehearse it
- Draft a holding message to customers, with a named sender.
- Pick the most likely failure, not the most dramatic one.
- Walk it through out loud for an hour, with the people who would be on the call.
- Write down every question nobody could answer.That list is next quarter’s work.
- Diarise the next walk-through.