By Stan Kreydin, Managing Director of Cyber Risk and Technology Advisory
A disaster recovery plan should be evaluated not just on whether a document exists, but on whether the organization can actually execute it. During IT due diligence, buyers should compare stated recovery objectives with activation procedures, responsible personnel, system dependencies, testing history, and the evidence supporting the plan. A questionnaire may ask whether the company has a disaster recovery plan. The company checks “yes.” That confirms the existence of a disaster recovery plan. It does not establish whether the plan will work. The difference becomes clear when the underlying documentation is reviewed.
In one engagement, a recovery plan set a four-hour recovery objective but did not activate until after 48 hours of continuous downtime. Both provisions appeared in the same document. The recovery objective and the activation trigger were incompatible. In another case, the disaster recovery plan assigned system restoration responsibilities to an internal IT team that no longer existed. If the plan had been activated, the organization would have relied on personnel who were no longer there. In a separate review, a company confirmed in its questionnaire that it maintained a vendor risk management program. When supporting documentation was requested, the document provided was a food safety compliance review. There was no corresponding technology vendor risk management program. None of these examples necessarily indicate deception. In each case, the organization had something that resembled what it believed the question was asking about. The problem was that the questionnaire established the representation. It did not test the evidence.
What Should Buyers Review?
A useful review should go beyond confirming that the policy exists. Buyers should understand which systems are critical, how quickly they are expected to be restored, what event triggers the recovery process, who is responsible for each task, whether those individuals are still with the organization, where backups are stored, and when the plan was last tested. The goal is to determine whether the organization could execute the plan under real-world operating conditions.
What Buyers Often Ask:
- What is a recovery time objective? A recovery time objective, or RTO, defines the targeted amount of time within which a system or business function should be restored after a disruption.
- How do you know whether a disaster recovery plan works? The plan should contain realistic procedures, current responsible parties, defined system priorities, tested backups, and evidence that the organization has exercised or validated the recovery process.
- Why does disaster recovery matter in M&A? Weak recovery capabilities can create operational, cybersecurity, customer, and financial risks that transfer to the buyer at close.
For any questions regarding disaster recovery services or cyber risk and technology advisory services, contact Stan Kreydin at [email protected].