Your Systems Go Down at 10:17 Tuesday Morning: 5 Questions Your Team Better Be Able to Answer
It is 10:17 on a Tuesday morning. People are working. Customers are calling. Production is moving. Project teams are collaborating. Invoices are being processed. Then something stops.
Maybe Microsoft 365 is unavailable. Maybe the internet connection fails. Maybe a server goes down. Maybe ransomware is suspected. Maybe a cloud platform your company depends on is having an outage.
The first fifteen minutes will tell you more about business continuity than a fifty-page plan nobody has opened in two years.
The goal is not to predict every possible failure. It is to make important decisions before stress, uncertainty, and business pressure make them for you. Here are five questions every leadership team should be able to answer.
1. Who Is in Charge of the Business Response?
IT may lead the technical recovery, but a business interruption is not only an IT event. Someone needs authority to coordinate decisions across operations, leadership, communications, vendors, customers, insurance, legal, and employees.
That role should be clear before the incident. If the owner is unavailable, who takes over? If the IT leader is troubleshooting, who communicates with the rest of the company? If there is a suspected cyber incident, who decides when outside specialists or insurance contacts are engaged?
A useful continuity plan names decision-makers and alternates rather than relying on “we all know who to call.”
2. What Can Employees Still Do Without the Systems They Normally Use?
Most organizations understand which systems they depend on. Fewer have defined what work can continue when those systems are unavailable.
A manufacturer may need a manual process for production scheduling, receiving, quality records, or shipping. An architecture or construction firm may need alternative access to current drawings, project contacts, or field documentation. A professional-services firm may need a way to reach clients, track urgent work, and record time when core applications are unavailable.
This is where continuity becomes an operational exercise rather than a technical one. Every critical department should know its minimum viable way of working.
3. How Will We Communicate If Our Normal Communication Tools Are Down?
A continuity plan that depends on email becomes a problem when email is the outage. The same is true for Teams, VoIP, a collaboration platform, or the corporate network.
The organization needs a secondary communication path for leaders and employees. That may include verified mobile numbers, an emergency notification system, a documented call tree, or another approved method that does not depend on the same systems as normal operations.
Customer communication matters too. Who decides whether clients should be notified? Who approves the message? Where are contact lists stored if the CRM is unavailable?
4. What Gets Restored First – And Who Decided That?
Disaster recovery becomes difficult when every department says its system is the most important.
Recovery priorities should be based on business impact. Which system keeps production moving? Which application contains the information employees need to serve customers? Which service supports payroll, cash flow, safety, compliance, or contractual obligations?
The answer may not be the system that is most technically complex. It may be the system whose absence causes the fastest business damage.
Those priorities should be documented and reviewed as the organization changes. A new cloud application, acquisition, location, customer requirement, or production process can change the order.
5. How Long Can We Actually Operate This Way?
Every workaround has a shelf life. Employees may be able to operate manually for two hours but not two days. A manufacturer may tolerate one production system being unavailable briefly but face major scheduling or shipment problems if the outage continues. A design firm may work locally for a period of time but eventually need central project data. A professional-services firm may continue client work but struggle with billing, records, or communication.
Leadership should define acceptable downtime in business terms. What begins happening after two hours? Four hours? One day? Three days? Which customers, contractual commitments, or revenue streams are affected?
A Tabletop Exercise Is Better Than a Binder
The fastest way to discover gaps is to rehearse the conversation. Run a tabletop exercise with leadership and your technology provider. Pick a realistic scenario. Remove one or two critical systems. Ask leadership what happens next. Then keep asking “and then what?” until the team reaches the point where the answer is unclear.
You will usually find issues that no security product can solve by itself: outdated contact lists, unclear authority, undocumented workarounds, untested restores, forgotten dependencies, vendor confusion, or two departments assuming the other owns the same decision.
That is useful information. It gives the business a chance to fix uncertainty before uncertainty becomes downtime.
Frequently Asked Questions
What is business continuity planning?
Business continuity planning defines how an organization will continue critical operations during and after a disruption, including technology outages, cyber incidents, facility problems, vendor failures, and other events.
What is the difference between business continuity and disaster recovery?
Business continuity focuses on keeping the organization operating. Disaster recovery focuses more specifically on restoring technology, systems, applications, and data.
What is a tabletop exercise?
A tabletop exercise is a discussion-based simulation in which leaders walk through a realistic incident scenario, make decisions, identify gaps, and improve response plans without causing an actual outage.
How often should a business continuity plan be tested?
Testing should occur on a regular schedule and after significant changes to systems, locations, leadership, vendors, business processes, or regulatory and contractual requirements.
Who should participate in a continuity exercise?
Depending on the organization, participants may include executive leadership, operations, finance, HR, communications, legal, IT, cybersecurity, facilities, and key third-party providers.