Business Continuity and Disaster Recovery

1. Objective

elyXion‘s continuity approach aims to protect people, maintain critical customer communication, restore priority internal services, and support contracted customer recovery activities during disruption. It is risk-based and proportionate to the company’s size and services.

This public summary does not create RTO, RPO, or availability commitments. Those exist only when stated in an Order Form.

2. Governance

A named continuity owner maintains plans, contact trees, service priorities, dependencies, and exercise records. Management declares major continuity events and sets priorities. Security and privacy obligations continue during disruption.

3. Scenarios

Planning should address:

  • loss or unavailability of key personnel;
  • identity, Portal, support, hosting, internet, power, or communications outage;
  • Microsoft or other systemic provider outage;
  • cyberattack, ransomware, credential compromise, or destructive change;
  • data corruption or backup failure;
  • supplier failure or termination;
  • office inaccessibility and regional disruption; and
  • financial, legal, or reputational crisis affecting operations.

4. Service Prioritisation

Priority Capability Draft Recovery Objective
1 Security incident communication and emergency customer contact [OBJECTIVE]
2 Identity, support intake, and critical managed-service coordination [OBJECTIVE]
3 Portal core access and operational reporting [OBJECTIVE]
4 Internal administration, marketing, and non-critical analytics [OBJECTIVE]

Objectives must be validated through architecture and exercises.

5. People and Communications

Key roles should have deputies, secure remote-work capability, current contact information, and an out-of-band communication option. Customer communications should state known facts, impact, actions, workarounds, and next update time without speculation.

6. Technology Resilience

Resilience may use provider redundancy, infrastructure automation, configuration backups, protected data backups, monitoring, alternate administrative access, and documented restoration. Single points of failure should be identified and accepted or remediated.

7. Backup Strategy

Each critical dataset requires an owner, backup method, frequency, retention, encryption, access control, location, restoration procedure, and test cadence. Backups should be isolated from ordinary administrative failure where proportionate.

8. Customer Environments

elyXion supports Customer continuity only within the contracted scope. Customer RTO, RPO, application dependency, business workaround, and crisis communication remain Customer responsibilities unless expressly transferred.

9. Third Parties

Continuity planning considers provider status channels, escalation paths, data export, alternative suppliers, and contractual exit. elyXion cannot guarantee continuity of a provider it does not control.

10. Exercises

Plans should be tested at least annually and after material change. Exercises may include contact tests, tabletop incidents, backup restoration, access loss, supplier outage, and failover. Findings are tracked to closure.

11. Crisis and Incident Coordination

Continuity, security incident, privacy breach, and major incident processes may run together. A designated incident lead coordinates objectives, decisions, evidence, communications, and recovery.

12. Recovery and Return to Normal

Recovery prioritises safe restoration, validation, monitoring, backlog management, and removal of temporary access. A post-event review identifies lessons, control changes, and customer follow-up.

13. Assurance

Customers may request a continuity summary and evidence of relevant exercises under confidentiality. Detailed plans, contact lists, credentials, and other customers’ information will not be disclosed.

Owner: elyXion
Version: 1.0
Last updated: 11 Aug 2026
Status: Draft for legal and operational review