Tag: disaster recovery planning

  • What does your business’s cyberattack response plan look like?

    What does your business’s cyberattack response plan look like?

    Most businesses spend a lot of time thinking about how to prevent a cyberattack, but far less time thinking about what happens when prevention fails. Firewalls, endpoint protection, multifactor authentication, email security, backups, and employee training are all important, but none of them eliminate risk entirely.

    That is why every organization needs a documented cybersecurity response plan. A good plan gives your team a clear path forward when systems are compromised, data becomes unavailable, ransomware appears on a workstation, or an employee account is taken over.

    It should also work hand in hand with your disaster recovery plan. Cybersecurity response focuses on containing the incident, understanding what happened, and preventing further damage, while disaster recovery focuses on restoring systems, applications, data, and business operations. When those two plans are developed together, your organization is much better prepared to recover without making an already difficult situation worse.

    Cyber incidents create confusion quickly because people are forced to make decisions while critical systems may already be unavailable. Employees may not know whether they should shut down their computers, disconnect from the network, call IT, notify management, contact customers, or simply stop touching anything. Without a documented process, well-meaning employees can accidentally destroy evidence, spread malware further, overwrite usable backups, or delay the response while people argue about who has authority to make decisions. A cybersecurity response plan removes much of that uncertainty before an incident ever happens.

    The goal is not to create a 200-page binder that nobody will read. The goal is to establish clear responsibilities, reliable communication methods, technical recovery procedures, and a defined order of operations that your team can actually follow under pressure.

    Traditional disaster recovery planning often focuses on events such as equipment failures, storms, fires, power outages, or accidental data loss. Those scenarios still matter, but cyberattacks create additional complications because the systems you are trying to restore may themselves be compromised. For example, restoring a server from backup is not enough if the attacker still has access to an administrator account. Reconnecting restored systems to the network can immediately expose them to reinfection if the original vulnerability has not been identified and contained.

    Modern disaster recovery planning therefore needs to account for security incidents as well as infrastructure failures. Recovery should not simply mean getting computers running again. It should mean restoring the business to a known, secure, and functional state.

    10 Must-Have Items in a Disaster Recovery and Cybersecurity Response Plan

    A practical disaster recovery and cybersecurity response plan should cover the technical side of recovery as well as the people, communication, and decision-making processes surrounding an incident. At a minimum, every business should address the following ten areas.

    1. A clearly defined incident response team. Identify who is responsible for technical response, executive decisions, communications, legal coordination, insurance notifications, and vendor management. Everyone involved should know who has final authority during an incident.
    2. An emergency contact list that works when normal systems do not. Maintain contact information for employees, IT providers, cybersecurity vendors, insurance carriers, legal counsel, key software providers, and other critical partners. Store a copy somewhere that does not depend on your primary email system or network.
    3. A complete inventory of critical systems and data. Your team should know which servers, cloud platforms, applications, databases, endpoints, and business processes are essential to operations. Recovery priorities become much easier to determine when critical dependencies are already documented.
    4. A documented backup and restoration strategy. Backups should include critical business data and systems, and they should be protected from the same credentials and infrastructure used by production systems whenever possible. Restoration procedures should also be tested regularly rather than assumed to work.
    5. Defined recovery priorities and acceptable downtime. Determine which systems need to return first and how long the business can reasonably operate without them. This helps establish recovery time objectives and prevents less important systems from distracting the response team.
    6. Procedures for isolating compromised systems. Your cybersecurity response plan should explain how affected devices, accounts, servers, and network segments can be contained without unnecessarily taking the entire organization offline. Employees should also know when to disconnect a device and when to leave it untouched for investigation.
    7. Account and identity recovery procedures. Many modern attacks begin with stolen credentials, compromised email accounts, or abused administrator privileges. Your plan should include procedures for resetting credentials, revoking active sessions, reviewing authentication methods, disabling compromised accounts, and validating administrative access before systems are restored.
    8. A communication plan for employees, customers, vendors, and leadership. Determine who is authorized to communicate about an incident and how updates will be distributed if email, phone systems, or collaboration platforms are unavailable. Clear communication reduces confusion and helps prevent rumors or contradictory instructions.
    9. Cyber insurance, legal, and regulatory procedures. Know when your cyber insurance carrier must be contacted and what documentation they require. Businesses should also understand whether an incident could trigger contractual, regulatory, law enforcement, or customer notification requirements.
    10. A testing and review schedule. A plan that has never been tested is largely theoretical. Conduct tabletop exercises, restoration tests, contact-list reviews, and technical recovery drills so your team can identify gaps before a real cyberattack exposes them.

    Backups are a piece of the puzzle, but businesses sometimes treat backups as if they are synonymous with disaster recovery. Backups are one of the most important components of recovery, but having a backup does not automatically mean the business can recover quickly or securely. You also need to know how long restoration will take, whether the backup contains all required systems and data, whether passwords and encryption keys are available, and whether the environment you are restoring into is safe. These questions become particularly important during ransomware and account compromise incidents.

    A good disaster recovery plan answers those questions before anyone is staring at an encrypted server at 2:00 in the morning. It turns backup technology into an actual recovery capability rather than an insurance policy that may or may not work when needed. Your response plan should not count on your normal methods of communication only. Many businesses coordinate emergencies through Microsoft 365, Google Workspace, Teams, Slack, or another cloud platform. That works well until the incident involves the same identity provider, email environment, or collaboration system your team normally uses.

    Your response plan should include an alternate method for contacting leadership, employees, vendors, and your IT provider. It should also establish where critical documentation, insurance information, recovery credentials, and emergency contacts can be accessed if the primary network is unavailable. This does not mean printing every password and putting it in a desk drawer. It means intentionally designing an emergency communication and access process that does not depend entirely on the systems that might be under attack.

    It’s also important you test your plan before you need it. A cybersecurity response plan that exists only as a document is not enough. Your team needs to know whether the procedures actually work and whether the people listed in the plan understand their responsibilities. Tabletop exercises are one of the easiest ways to test preparedness without disrupting normal business operations. You can walk through a realistic scenario, such as a compromised Microsoft 365 administrator account or a ransomware event affecting a file server, and ask each participant what they would do next.

    These exercises often expose practical gaps that are easy to overlook during normal operations. Missing phone numbers, undocumented administrator accounts, unclear vendor responsibilities, outdated backup procedures, and forgotten legacy systems are much easier to correct during a planning meeting than during an active cyberattack. The objective of cybersecurity planning is not to guarantee that nothing bad will ever happen. The objective is to make sure a security incident does not automatically become a business-ending event.

    Organizations that prepare in advance can make decisions faster, isolate affected systems sooner, restore operations more confidently, and communicate more effectively with employees and customers. They are also more likely to preserve the information needed to understand what happened and prevent it from happening again.

    Valley Techlogic helps businesses evaluate their cybersecurity preparedness, backup strategy, disaster recovery capabilities, and incident response procedures. If your current cyberattack response plan is little more than “call the IT person and hope the backups work,” it is probably time to build something more resilient and Valley Techlogic can help your business in creating, and maintaining, your disaster recovery plan. Learn more today through a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • Inclement weather, solar flares, earthquakes – how disaster proof is your businesses technology?

    Inclement weather, solar flares, earthquakes – how disaster proof is your businesses technology?

    We’ve written quite a bit about cyber security disasters and disaster recovery in that context (here are just a couple options Why every business needs a documented backup and disaster recovery strategy and Data Breached? 5 ways to reduce the impact on your business), but what about a disaster that’s truly out of your hands?

    Depending on where you live there are different types of types of disasters to worry about, and some disasters such as solar flares or geomagnetic storms are a global concern.

    While it’s been hyped by certain news outlets that a solar storm of spectacular magnitude could wipe out our global network and cause nationwide blackouts, solar events of the level required to cause mass destruction are spectacularly rare. Nasa rates solar flare levels on a scale that includes B Class which is the smallest, through C, M and X class which is the biggest. Within each scale there is a rating from 1-9 for the first three levels of solar flares and X class flares can be rated up to 17.

    X-class flares actually occur fairly frequently, with there being 11 so far in 2023 at the time of writing. These flares are strong enough to disrupt satellite signals or deliver a minor dose of radiation to passengers on an airplane when they occur.

    The best defense against solar events such as these is to advocate for improving our electricity grids, above ground electricity components are the most vulnerable if a significant solar flare were to occur. We do want to stress again though that an event of that nature would be exceedingly rare.

    Let’s now take a look at events that are much more common, such as inclement weather or for California based businesses such as ours, earthquakes.

    While you most likely have insurance that would cover your physical property including your office building, hardware and office furniture, it might be important to ask your insurance broker if it will also cover intangible assets.

    It is likely you’ll need a cyber liability policy to provide coverage for your data, below is a chart for what we typically see is covered (and not covered) by cyber liability coverage.

    As you can see most cyber liability policies cover business interruptions and data loss even if the cause is not cyber security related. What’s often not covered is events that fall within your control (such as the human element we’re always mentioning when it comes to common hacking techniques such as phishing).

    Another good way to protect your data from disaster events that may impact your business is to have most of your data located off premises in the cloud.

    While the cloud is often construed as a nebulous concept, really hosting your data in the cloud just means it’s on a server somewhere else. If your on-premises server is subject to catastrophic system failure for any reason, the cloud copy of your data would be safe.

    There are many low cost or free cloud options you can take advantage of for your data, we have a guide to the best way to use the free OneDrive storage that comes with your Microsoft 365 subscription here.

    Also, if you work with a managed IT provider such as Valley Techlogic, backups and backup maintenance is often included as part of your service plan. We have information about our own back program, TechVault.

    If disaster proofing your business in 2024 is on your to-do list, why not collaborate with us? We have experience in creating plans for businesses to make sure we avoid all preventable downtime and to protect your data from catastrophic events. If you’ve already suffered a data breach or other system outage and need assistance in data recovery that is also a service Valley Techlogic can provide. Reach out today for more information.

    Looking for more to read? We suggest these other articles from our site.

    This article was powered by Valley Techlogic, an IT service provider in Atwater, CA. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on Twitter at https://x.com/valleytechlogic.

  • Five Must Have Features in a Business Continuity Plan

    Five Must Have Features in a Business Continuity Plan

    While business continuity plans should cover topics that extend beyond the realm of technology, it makes sense that technology naturally moves to the forefront when much of the focus of a good business continuity plan focuses on the ability to perform business functions as normal.

    Business continuity is defined as “”the capability of an organization to continue the delivery of products or services at pre-defined acceptable levels following a disruptive incident”, and disruptive event can have many meanings. It could be a natural disaster, a cyberthreat, or even a short-term outage situation like if your office loses power or internet access.

    You should have plans for both short-term and long-term outages written into your plan. However some studies have shown that as high as 51% of businesses globally do not have a business continuity plan in place at all, and what’s worse – only 10% of businesses who experience a disaster and do not have a business continuity plan survive.

    Who should make plans for your business if not you? If you have no continuity plan in place you may find that you’re scrambling to make decisions under duress and attempting to delegate to third party vendors who have their bottom line in mind, not yours.

    So, how do you start in creating that plan? The first step is to have an honest look at your businesses risk factors. This includes environmental factors, does your area face brown outs when the heat starts to peak in the summer? Or snow that prevents employees from reaching the office in the winter at times?

    Maybe there are some things that are individual to you, such as touch and go internet access in your office building or phonelines that are less than reliable. Do you have a server on its last legs that’s been acting finicky? Its eventual failure should be written into your continuity plan.

    You also need to look at your cyber risks, if your employees aren’t being training on cybersecurity safety then that’s a huge factor that must be addressed and planned for. You need to ask yourself what you would do if your data was breached, or an employee email was compromised.

    It’s overwhelming but as with most things starting the process is the hardest part and having a candid look at your business could mean eliminating certain risk factors (like moving data away from the server on it’s last legs into a cloud solution).

    You may even find ways to make your business more efficient, if you know brown outs are common where your office building is located in the summer perhaps you would make a plan to have employees work from home more during that time. Or having your internet service provider address the issue of frequent outages rather than just rolling with them as they occur.

    All in all, these are the five things we would suggest you focus on as you make your business continuity plan:

    1. Technology – How will employees continue to work if your office operations have been waylaid.
    2. Power – If power goes out what kind of backup plan will you need to have in place, such as a generator to keep your server online.
    3. Communications – Do you have a standard way with communicating with your employees? If you need to get a message out quickly to all of them, could you presently do that?
    4. Vendors – Inform your vendors of the provisions you’ve put in place in case a disaster were to occur, and inquire what plans they have in place on their end (because a disaster for them could be a disaster for you).
    5. Data Protection – Most businesses require an online presence to continuing operations, you will need provisions for if your data is compromised or inaccessible. At Valley Techlogic we suggest having a multi-layer backup approach, so if one backup is compromised you will have the others to fall back on.

    To get you started, we’ve prepared this emergency contact worksheet for your employees. You can fill in who they should begin to reach out to and what steps they should take if an emergency occurs. If you would like us to personalize it with your logo just let us know.

    Click to grab the full size version for your business. Need it personalized? Contact us.

    Valley Techlogic can help you to begin establishing a business continuity plan and also help you with mitigating risks to your business, learn more today.

    Looking for more to read? We suggest these other articles from our site.

    This article was powered by Valley TechLogic, IT service provider in Atwater, CA. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on Twitter at https://x.com/valleytechlogic.

  • DDoS Attack or Not? Yesterday’s Outage Left Many Systems Down for Hours

    DDoS Attack or Not? Yesterday’s Outage Left Many Systems Down for Hours

    Yesterday, an outage stemming from T-Mobile left many major systems down. Affected websites included T-Mobile itself, Instagram, Comcast, Sprint and Chase Bank. Was it a massive DDoS attack or just a server misconfiguration as they’re claiming?

    First, it’s probably a good idea to explain what a DDoS attack or Distributed Denial-of-Service attack is and what it aims to do.

    A DDoS attack is a cyber attack where the perpetrator or group of perpetrators seeks to make a server or network unavailable by attacking its connection to the internet. They typically do this by flooding the affected systems with traffic, overloading them and causing them to go down.

    These attacks can happen to a single computer, an office, or even on a global scale. The website https://digitalattackmap.com/ attempts to track these DDoS attacks on a global level, however it’s somewhat controversial among cyber security experts as they question the veracity of it’s data.

    Many time these outages are made apparent by the website https://downdetector.com/ which accurately tracked the cascading wave of websites that went down in yesterdays event.

    Down Detector is a reliable source for tracking whether the connection issues you’re having are stemming from your network or the website or service you’re trying to access is truly down.

    So, was yesterday’s event a DDoS attack or just an error? The public will probably never know. However as cyber crime continues to ramp up – purported to be a $6 trillion dollar industry by 2021 – it’s a good idea to have the best protections in place so you and your business don’t fall victim.

    A DDoS attack aimed at your systems may expose other vulnerabilities, and the downtime alone can be costly. If your IT team isn’t adequately prepared to defend against this or any of the other varieties of cyber attacks plaguing the technology market, it might be time for a new team.

    This article was powered by Valley TechLogic, an IT provider in Atwater, CA. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on Twitter at https://x.com/valleytechlogic.

    Looking for IT Services in Fresno, Modesto, Stockton, Ceres, Atwater, Merced, Visalia or Lodi? We cover all these areas and more!