1. Objective
elyXion‘s continuity approach aims to protect people, maintain critical customer communication, restore priority internal services, and support contracted customer recovery activities during disruption. It is risk-based and proportionate to the company’s size and services.
This public summary does not create RTO, RPO, or availability commitments. Those exist only when stated in an Order Form.
2. Governance
A named continuity owner maintains plans, contact trees, service priorities, dependencies, and exercise records. Management declares major continuity events and sets priorities. Security and privacy obligations continue during disruption.
3. Scenarios
Planning should address:
- loss or unavailability of key personnel;
- identity, Portal, support, hosting, internet, power, or communications outage;
- Microsoft or other systemic provider outage;
- cyberattack, ransomware, credential compromise, or destructive change;
- data corruption or backup failure;
- supplier failure or termination;
- office inaccessibility and regional disruption; and
- financial, legal, or reputational crisis affecting operations.
4. Service Prioritisation
| Priority | Capability | Draft Recovery Objective |
|---|---|---|
| 1 | Security incident communication and emergency customer contact | [OBJECTIVE] |
| 2 | Identity, support intake, and critical managed-service coordination | [OBJECTIVE] |
| 3 | Portal core access and operational reporting | [OBJECTIVE] |
| 4 | Internal administration, marketing, and non-critical analytics | [OBJECTIVE] |
Objectives must be validated through architecture and exercises.
5. People and Communications
Key roles should have deputies, secure remote-work capability, current contact information, and an out-of-band communication option. Customer communications should state known facts, impact, actions, workarounds, and next update time without speculation.
6. Technology Resilience
Resilience may use provider redundancy, infrastructure automation, configuration backups, protected data backups, monitoring, alternate administrative access, and documented restoration. Single points of failure should be identified and accepted or remediated.
7. Backup Strategy
Each critical dataset requires an owner, backup method, frequency, retention, encryption, access control, location, restoration procedure, and test cadence. Backups should be isolated from ordinary administrative failure where proportionate.
8. Customer Environments
elyXion supports Customer continuity only within the contracted scope. Customer RTO, RPO, application dependency, business workaround, and crisis communication remain Customer responsibilities unless expressly transferred.
9. Third Parties
Continuity planning considers provider status channels, escalation paths, data export, alternative suppliers, and contractual exit. elyXion cannot guarantee continuity of a provider it does not control.
10. Exercises
Plans should be tested at least annually and after material change. Exercises may include contact tests, tabletop incidents, backup restoration, access loss, supplier outage, and failover. Findings are tracked to closure.
11. Crisis and Incident Coordination
Continuity, security incident, privacy breach, and major incident processes may run together. A designated incident lead coordinates objectives, decisions, evidence, communications, and recovery.
12. Recovery and Return to Normal
Recovery prioritises safe restoration, validation, monitoring, backlog management, and removal of temporary access. A post-event review identifies lessons, control changes, and customer follow-up.
13. Assurance
Customers may request a continuity summary and evidence of relevant exercises under confidentiality. Detailed plans, contact lists, credentials, and other customers’ information will not be disclosed.
| Owner: | elyXion |
| Version: | 1.0 |
| Last updated: | 11 Aug 2026 |
| Status: | Draft for legal and operational review |
