September is National Preparedness Month. It’s a great opportunity to check your organization's information technology preparedness and cybersecurity resilience.
A business continuity plan is only as strong as the IT recovery plan built into it. This month, confirm that your plan reflects how your systems and data are protected today:
- Pair your business continuity plan with an IT disaster recovery plan. Inventory critical hardware, software, and data, and ensure IT recovery time objectives match business priorities.
- Confirm backups are current and tested. Don't just verify backups exist. Confirm you can actually restore from them.
- Keep contact and succession information current, including up-to-date rosters, lines of authority, and vendor/contractor contacts.
- Exercise the plan. A plan untested has unknown gaps. Schedule a walkthrough or drill.
- Revisit your communications plan, so you know in advance who notifies employees, the public, and other entities during a disruption and through which channels.
- Keep a copy of your plan accessible outside your primary network. If a cyberattack takes core systems offline, your continuity plan shouldn't be locked inside them, too.
- Build a cyber incident scenario into your continuity exercises. Many plans are tested against weather or facility disruptions but never a ransomware attack or system compromise. Run at least one cyber-focused exercise a year.
Take a small step this September. Review one piece of your plan, or test one backup. Small actions now make the difference when it counts.
Get more information on preparing for disasters by visiting ReadyNC.gov.