← BUSINESS CONTINUITY GUIDE
BUSINESS CONTINUITY GUIDE

Test the plan: tabletop drills and restore days

Every untested continuity plan contains at least one surprise. The backup that silently stopped in March. The "emergency contact" who left the company. The restore that works but takes nine hours instead of the two everyone assumed. Testing exists to buy those surprises at rehearsal prices instead of performance prices. Here's the testing calendar we recommend, smallest effort first.

The tabletop drill: one hour, quarterly

Get the key people in a room. One scenario, spoken aloud: "It's Tuesday 9 a.m. and the file server is dead." Then walk the plan out loud. Who gets called first? Is that number current? What's the workaround for invoicing while it's down? Who talks to customers, and what do they say?

No systems are touched. You're testing the plan's paperwork and the humans' understanding of it, and an hour of talking reliably finds holes: the contact who moved on, the workaround nobody actually knows how to run, the two people who each thought the other owned a step. Rotate scenarios each quarter: server death, ransomware, internet outage, building access lost, key person unreachable.

The restore drill: twice a year

Now touch systems. Restore three things from real backups: one file, one folder, one whole system, and time each. The method is written up in our restore drill guide; the continuity-specific addition is comparing the times against the RTO you set per system. A nine-hour restore against a four-hour RTO is a finding, and it's a finding you want on a calm Thursday. While you're there, confirm the whole backup inventory ran recently, not just the server job everyone remembers.

The failover test: once a year

Whatever your recovery tier promises, make it prove it. Boot the standby VM and log into the application on it. Pull the primary internet line and watch whether failover actually cuts over, and whether the phones and card readers survive the switch. Kill power to the closet and see if the UPS carries the equipment long enough for clean shutdowns. Ten minutes of controlled failure per system, scheduled after hours, tells you things no dashboard will.

Write down what broke

Every drill produces a short list: what worked, what didn't, who's fixing each item, by when. Fifteen minutes, same day. Then, and this is the part that separates the habit from the theater, the fixes go on a calendar and the next drill checks them. A drill that finds the same broken thing twice wasn't a drill the first time.

The effort, totaled

Four one-hour tabletops, two half-day restore drills, one evening of failover testing. Call it three working days a year, less with a provider running the technical halves. Against what a single surprise costs at your downtime rate, it's the best-priced insurance in the building.

Want this handled instead of homeworked? That's the job.

Email us →
RELATED READING
Write a business continuity plan that fits on five pages Business Continuity →
A backup strategy for everything, not just the server Business Continuity →
Ransomware recovery: decisions to make before the bad day Business Continuity →
The whole Business Continuity guide Pillar →

From the blog

ALL POSTS →
NO FORMS. JUST EMAIL.
mason@hurbs.io
or (832) 457-4317, LA and Houston