The 15-Minute Business Continuity Meeting Every Kentucky Leadership Team Should Have

If your business lost access to its computers, files, email, phones, or critical software tomorrow, would your leadership team know exactly what to do?

Most business owners would probably say yes.

But when a ransomware attack, server failure, cyberattack, power outage, natural disaster, or critical vendor failure actually occurs, many organizations discover that their preparedness plan exists mostly in people’s heads.

That can become an expensive problem.

For a healthcare practice, the disruption could interfere with patient care and access to electronic protected health information. For an accounting firm, it could mean losing access to tax and financial records. For a manufacturer working with the Department of Defense, an IT outage could affect systems containing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). For another business, it could simply mean employees cannot work and customers cannot be served.

September is National Preparedness Month, making it an excellent time for Kentucky business owners, CEOs, practice managers, and leadership teams to evaluate how prepared their organizations really are. FEMA recognizes September as National Preparedness Month, emphasizing the importance of preparing for emergencies before they occur.

The good news is that your leadership team doesn’t need an eight-hour planning retreat to start.

You need 15 minutes, the right people, and five questions.


1. If Our Business Stopped Operating Tomorrow, What Would Need to Be Restored First?

This is one of the most important questions your leadership team can ask.

Don’t simply make a list of every computer, application, server, and piece of technology your company uses. Instead, identify the business functions that must be restored first.

For example:

  • What systems are required to serve customers?
  • What systems are required to process payments?
  • What applications are required to schedule appointments?
  • Where are critical documents stored?
  • Which systems are required to communicate with employees?
  • What technology is required to manufacture or deliver your products?
  • What systems contain regulated or sensitive information?

Your goal is to identify your organization’s mission-critical systems and processes.

NIST’s guidance on contingency planning emphasizes identifying critical business functions and determining how quickly systems and data need to be restored following a disruption.

This is where effective IT support becomes more than simply having someone available to fix a computer.

Your IT environment should be designed around the needs of the business.

If your accounting software is more critical than your email, for example, your recovery priorities should reflect that.

If your medical practice cannot operate without its electronic health record system, that system should have a clearly defined recovery strategy.

If your manufacturing operation depends on specific workstations, servers, or applications to fulfill defense contracts, those systems should be identified and prioritized before an emergency occurs.

You cannot recover what you have not identified.


2. Who Is Responsible for Making Decisions During a Business Disruption?

When something goes wrong, uncertainty becomes expensive.

If nobody knows who has authority to make decisions, employees may wait for instructions while managers try to determine who is responsible.

Your leadership team should identify:

  • Who initiates the emergency response?
  • Who communicates with employees?
  • Who communicates with customers?
  • Who contacts your IT provider?
  • Who communicates with insurance providers?
  • Who contacts critical vendors?
  • Who determines when systems can safely return to production?
  • Who has authority to make business continuity decisions?

These responsibilities don’t need to create a complicated organizational chart.

They simply need to be clear.

Imagine a ransomware incident at 8:00 a.m.

Employees cannot access files. Email is unavailable. Several workstations display unusual messages. Customers are beginning to call.

Who makes the decision to shut down systems?

Who contacts your computer support provider?

Who communicates with employees?

Who determines whether backups are safe to use?

Who contacts your cyber insurance carrier?

If your leadership team needs 30 minutes to figure out who is responsible for these decisions, the incident is already costing you valuable time.


3. How Would We Communicate If Our Normal Technology Wasn’t Available?

Email works great—until it doesn’t.

The same is true for your phone system, Microsoft 365, collaboration software, internet connection, and other communication platforms.

Ask your team:

If our normal communication tools stopped working right now, how would we communicate with employees?

Then ask:

How would customers reach us?

And:

Where would leadership provide instructions and updates?

This is especially important during a cybersecurity incident.

An organization may have an excellent incident response plan, but if the plan exists only inside the email system that has been compromised, employees may not be able to access it when they need it most.

Your backup communication plan doesn’t have to be complicated.

It simply needs to work.

Document alternative contact information. Identify alternate communication methods. Make sure key employees know where emergency instructions are located.

And don’t assume everyone remembers the plan.

Test it.


4. What Is Our Biggest Operational Dependency?

Every business has dependencies.

The problem is that many businesses don’t realize how dependent they are on a particular system, vendor, employee, or technology until that dependency disappears.

Your biggest dependency might be:

  • A cloud application
  • Your internet connection
  • A phone system
  • A specific software platform
  • A third-party vendor
  • A single server
  • A database
  • A key employee
  • A proprietary manufacturing system
  • A Microsoft 365 environment
  • A process known by only one person

Now ask the uncomfortable question:

What happens if that dependency isn’t available tomorrow?

This is particularly important for organizations with regulatory requirements.

Healthcare organizations subject to HIPAA Compliance requirements must have contingency procedures for emergencies that damage systems containing electronic protected health information, including data backup and recovery procedures.

Organizations covered by the FTC Safeguards Rule must also maintain an information security program that includes appropriate safeguards and a written incident response plan.

For organizations involved in the defense industrial base, CMMC requirements add another layer of cybersecurity responsibility. Current federal acquisition rules require applicable contractors to maintain the CMMC status required by their contracts for systems handling FCI or CUI.

The point isn’t that every business needs the same technology.

The point is that your technology needs to match your business risk and regulatory obligations.

That is one reason a proactive Managed IT Services strategy can be valuable. Instead of waiting for a system to fail, your IT team or provider can identify dependencies, vulnerabilities, backup requirements, lifecycle issues, and recovery priorities before they become emergencies.


5. If a Major Disruption Happened Tomorrow, What Would We Wish We’d Prepared Today?

This may be the most revealing question of all.

Imagine that the disruption already happened.

What would you wish you had done yesterday?

Maybe you would wish you had:

  • Tested your backups.
  • Documented your recovery procedures.
  • Updated employee contact information.
  • Established emergency decision-making authority.
  • Documented critical vendor information.
  • Identified mission-critical applications.
  • Created an alternative communication method.
  • Replaced an aging server.
  • Implemented stronger security controls.
  • Completed a cybersecurity risk assessment.
  • Documented your compliance requirements.
  • Trained employees to recognize phishing attacks.
  • Established recovery time objectives.
  • Tested your disaster recovery plan.

None of these activities are particularly exciting when everything is working normally.

That’s precisely why organizations postpone them.

But when the business is down, preparation stops being an expense and becomes an asset.

NIST describes contingency planning as a coordinated process for recovering information systems, operations, and data after a disruption and emphasizes planning, testing, training, and maintaining those plans.

The question isn’t whether you can afford to prepare.

The better question is:

Can you afford to discover that you weren’t prepared after the disruption has already happened?


What Does IT Support Have to Do With Business Continuity?

Business continuity isn’t just an IT problem.

It’s a business leadership issue.

However, technology is now connected to nearly every critical business function. That means your IT support, cybersecurity, backup, and recovery strategies can have a direct effect on whether your organization continues operating after an incident.

A strong Managed IT Services strategy can help your organization:

  • Identify critical systems.
  • Monitor technology infrastructure.
  • Maintain and patch devices.
  • Protect endpoints and networks.
  • Maintain reliable backups.
  • Test recovery procedures.
  • Document technology environments.
  • Identify cybersecurity risks.
  • Support compliance requirements.
  • Reduce unnecessary downtime.
  • Establish technology recovery priorities.

For organizations that need more than basic computer troubleshooting, proactive IT support can become part of the organization’s overall risk-management strategy.

Learn more about Managed IT Services and IT Support

The goal isn’t to make preparedness complicated.

The goal is to make sure your people, technology, and business processes are working together before something goes wrong.


Preparedness Matters Even More When Compliance Is Required

Some businesses can choose how much cybersecurity and business continuity planning they want to implement.

Others have regulatory or contractual obligations that make cybersecurity a requirement.

Healthcare organizations, for example, must address specific safeguards under the HIPAA Security Rule. The Security Rule’s contingency planning requirements include procedures for responding to emergencies that damage systems containing electronic protected health information.

Financial organizations covered by the FTC Safeguards Rule must develop, implement, and maintain a written information security program appropriate to their circumstances. The rule also requires covered organizations to address incident response.

Defense contractors may have CMMC requirements incorporated into their contracts, depending on the information and systems involved. Current DFARS provisions specify that contractors must maintain the required CMMC status for applicable systems handling FCI or CUI.

And organizations handling payment card information may have obligations under PCI DSS.

The important takeaway for a business owner is simple:

Compliance isn’t just about having a policy sitting in a filing cabinet.

Your organization needs to be able to demonstrate that appropriate safeguards, processes, documentation, and technical controls are actually being implemented and maintained.

That’s where a structured compliance and cybersecurity program can help.

Explore Compliance+ IT Services


Backups Are Not the Same as Recovery

One of the biggest misconceptions we encounter is:

“We have backups, so we’re protected.”

Not necessarily.

A backup is only one part of a recovery strategy.

You also need to know:

  • What is being backed up?
  • How frequently is it backed up?
  • Where are backups stored?
  • Are backups protected from ransomware?
  • How long would restoration take?
  • Who can initiate recovery?
  • Have the backups actually been tested?
  • Can critical applications be restored?
  • What happens if the primary infrastructure is unavailable?

NIST guidance identifies backup and recovery as important components of contingency planning and emphasizes matching recovery strategies to the organization’s business impact and recovery requirements.

For healthcare organizations, HHS specifically identifies a data backup plan, disaster recovery planning, emergency operations, criticality analysis, and periodic testing as components of contingency planning.

Learn about Managed Data Backup & Recovery

The real question isn’t “Do we have backups?”

It’s:

“Can we recover the business when we need to?”


Your 15-Minute Leadership Exercise

Before your next leadership meeting ends, take 15 minutes and answer these five questions:

1. What must be restored first?

Identify your most critical business systems, applications, data, and processes.

2. Who makes decisions?

Identify who is responsible for leading the response and communicating with employees, customers, vendors, and technology partners.

3. How will we communicate?

Determine how your team will communicate if email, phones, internet, or collaboration platforms are unavailable.

4. What is our biggest dependency?

Identify the system, vendor, employee, application, or infrastructure component that could create the greatest operational disruption if it failed.

5. What would we wish we had prepared?

Identify the one or two preparedness gaps you would regret not addressing before an incident.

Don’t try to solve everything during this meeting.

Identify the gaps.

Then prioritize them.


Don’t Let the First Test of Your Recovery Plan Be a Real Disaster

A disaster recovery plan that has never been tested is an assumption.

A backup that has never been restored is an assumption.

An employee who has never been trained is an assumption.

A compliance program that hasn’t been reviewed is an assumption.

And assumptions are dangerous when your business is under pressure.

Your leadership team doesn’t have to become cybersecurity experts.

You do, however, need to understand what your business depends on, what could interrupt operations, and whether your current IT support and cybersecurity strategy is capable of helping you recover.

That’s where an experienced technology partner can provide value.

See how iSAFE Complete helps businesses with IT, cybersecurity, and compliance

Learn about HIPAA Compliance IT Services


Schedule Your 15-Minute Preparedness Conversation

You don’t need to spend an entire day creating a complicated business continuity plan.

Start with 15 minutes.

Bring your leadership team together. Ask the five questions. Write down the answers. Circle the areas where nobody is completely confident.

Those circles are your starting point.

If your organization is in Lexington, Richmond, Winchester, or elsewhere in Central Kentucky and you need help evaluating your computer support, cybersecurity, backup, disaster recovery, HIPAA Compliance, CMMC, or other technology requirements, iSAFE Complete can help you identify where your current strategy may have gaps.

Call 859-200-0428 or visit iSAFE Complete to schedule a conversation.

The best time to find out whether your business can recover from a disruption is before you have to recover from one.


References & Resources

  1. NIST — Contingency Planning Guide for Federal Information Systems
    Guidance on developing and maintaining information-system contingency plans, including recovery priorities and testing.
  2. HHS — Summary of the HIPAA Security Rule
    Official information regarding HIPAA Security Rule requirements, including contingency planning.
  3. FTC — Safeguards Rule: What Your Business Needs to Know
    Official FTC guidance concerning information security programs, risk assessments, safeguards, and incident response.
  4. Acquisition.gov — CMMC Policy
    Current federal acquisition requirements concerning CMMC status for applicable DoD contracts.
  5. FEMA — National Preparedness Month
    Federal preparedness information recognizing September as National Preparedness Month.

FREE REPORT

Image representing the Managed IT services Buyers guide free download

The Kentucky Business Guide To IT Support Services And Compliance

What You Should Expect To Pay For IT Support For Your Small Business (And How To Get Exactly What You Need Without Unnecessary Extras, Hidden Fees And Bloated Contracts)
 

You Can Also Email Us

Just fill out and submit the form below and someone will contact you as soon as possible.