Disasters ā physical or digital ā are a fact of life, so preparing well for them should be on the priority list
The one thing companies canāt afford is to lose revenue, and yet, disaster recovery is still not a priority for many.
One hundred percent. Thatās how many companies have reported revenue loss from downtime in the last year. And enterprises are now experiencing around 86 hours of IT outages a year. In South Africa, the cost of breaches is as high as R350 million in direct losses over three years, says PwC, with threats gaining momentum alongside digital and cloud adoption. On the flip side, companies that invest in disaster recovery (DR) solutions and have clearly defined DR metrics experience a reduction in fraud and cyber-related losses and minimise revenue loss. They also have better relationships with customers and stakeholders.
Then, thereās the R40 trillion cost of disaster. The United Nations Office for Disaster Risk Reduction estimates that this is now the annual bill that comes due for DR, and points out that intelligent planning and investment play a significant role in offsetting the risk. Whether the disaster is digital or physical, planning has become everything.
However, implementing DR strategies and policies can be challenging. Compliance, for example, is complex and can have a negative impact on the business. According to PwC, 77% of respondents felt that compliance was too complicated, underscoring the need for the move towards solutions that made it simpler and faster. Itās needed ā only 7% of those surveyed felt they were leading with compliance. When a company can co-ordinate its compliance and DR activities, its confidence levels increase, as does its operational resilience.
Hoping for the best
Another challenge is far more human ā companies donāt have a great attitude towards DR. Many still believe it is either a luxury or an unnecessary expense, one that only becomes relevant after an incident. When it comes to DR, companies tend to fall into three groups: those who donāt know what it is; those who think a disaster wonāt happen to them; and those who view it as an avoidable cost.
Unfortunately, this mindset is one of the biggest contributors to prolonged outages. Companies underestimate the frequency of failure and the financial impact of downtime, not really recognising how DR is actually less of a cost centre and more of a resilience mechanism. They also often donāt realise that thereās a chasm-wide difference between backups and DR.
Backups can only take a business to a point. They can help the company recover data, but not operations. They donāt have the systems and capabilities to recreate a functioning environment, spin up infrastructure or restore customer-facing services. Critically, they donāt meet the recovery time objectives required in regulated or high-availability sectors.
Companies canāt afford to be comfortable with backups. It doesnāt matter how well the business understands its systems or how expert the IT team is, a day lost to downtime while the backup is being restored is a day of lost transactions, productivity and reputation.
Quick renewal
Disaster recovery, on the other hand, is designed to lift the company straight back into business. It involves replicated environments, automated orchestration, defined failover plans and continuous synchronisation. The technology and the strategy behind DR restore the entirety of the business extremely quickly, not just the data. And this neatly brings the conversation back to compliance ā often, it is exactly this requirement that brings companies to the DR doorway, knocking to find out how they can remain compliant and competitive in a highly regulated market.
Companies, especially those in the financial services sector, increasingly require regulator-aligned DR architecture. And many have had unexpectedly unpleasant experiences when their DR systems have failed or havenāt met regulatory requirements and theyāve been expected to rebuild from scratch. In sectors like financial services, thereās almost zero tolerance for downtime and weakly designed systems.
Fortunately, technology has caught up, as have metrics that allow companies to better define their DR practices against global standards. Companies need visibility into their Recovery Time Objective (RTO), so that they know how long they can afford to be down, then into their Recovery Point Objective (RPO), which determines how much data they can afford to lose. These metrics then need to feed data from testing under pressure, so that companies know how their systems will react and how long it takes for them to achieve full operational recovery.
And that full recovery today? Try seven minutes. There are DR tests that have spun up entire production environments, including firewalls, virtual machines, databases and networking, in under 10 minutes. Not hours. Compared to a traditional backup restore, which can take hours under ideal conditions, DR as a service is lightning fast.
It also protects revenue, underpins compliance and directly influences customer and stakeholder trust.
Text | Mandi Matthews
Photography | Sutthiphong Chandaeng
Mandi Matthews is a Solutions Architect: Azure at Braintree.
For more information, go to braintree.co.za
