Disaster recovery is one of an IT manager's primary duties. These 20 steps outline a business continuity plan (BCP) for a media company, with IT administrators responsible for carrying it out.

  1. Identify the IT systems and functions essential to the media company's daily operations. These may include email, production systems, content management systems and customer databases.
  2. Define recovery time objectives (RTOs): the maximum acceptable downtime for each critical system and function. Use them to prioritize recovery during an outage.
  3. Write detailed recovery procedures for each critical system and function based on its RTO. Include backup and recovery strategies, system configurations and contact details for vendors and service providers.
  4. Test the plan! IT administrators should test the BCP annually or semiannually to check that it will work during an outage. Tests may cover backup systems and recovery procedures, with quarterly tabletop exercises to expose weaknesses and potential problems.
  5. Make BCP part of the culture. Train all employees for their roles during an outage, including communication protocols, backup procedures and access to critical systems and data.
  6. Identify everyone who needs information during an outage. Establish communication protocols so IT administrators can give them clear, timely updates on the situation and recovery work.
  7. Back up all critical systems and data on a regular schedule, and test those backups. Store them offsite in a secure location.
  8. Provide redundancy for critical systems and functions to reduce the impact of an outage.
  9. Do your maintenance! Maintain and update critical systems and hardware on a regular schedule so they work at their best.
  10. Conduct regular security audits to identify vulnerabilities and keep security protocols current.
  11. Establish access controls so only authorized personnel can reach critical systems and data.
  12. Maintain current contact details for vendors, service providers and everyone else involved. Verify the lists each month.
  13. Establish disaster recovery sites as secondary locations for critical systems and data during a disaster.
  14. Provide remote access to critical systems and data so staff can reach them from anywhere during an outage.
  15. Conduct regular risk assessments to identify potential threats and vulnerabilities.
  16. Establish incident response teams to manage IT outages and other incidents.
  17. Agree on contractual service level agreements (SLAs) with vendors and service providers in advance. Set acceptable timeframes for restoring critical systems and functions.
  18. Review and update the BCP on a regular schedule to keep it current and relevant. Senior management should know its high-level steps from memory.
  19. Train key employees to understand the importance of the BCP and their part in carrying it out.
  20. Keep records of BCP procedures and tests up to date so everyone involved can understand the plan and auditors can examine it.

Original publication on GoDaddy