In calm times, almost every organisation considers itself prepared for a crisis. Plans are in place, backups are running, and someone tested something at some point. The problem is that being prepared and feeling prepared look exactly the same from the outside. The difference only becomes visible when something serious happens. Fortunately, it can be identified earlier.
It takes just four simple yet uncomfortable questions. Can we lose access to a provider’s services and continue operating? Has anyone on the team actually run through a disaster scenario? Can we restore the system in a different environment? Do we have control over our data beyond the assurances included in contracts? If the answer to any of these questions is “no” or “I don’t know”, the organisation has a problem.

What makes these questions uncomfortable is not their tone, but the fact that they leave no room for interpretation. They do not ask about the security budget, the number of tools implemented or whether someone has been assigned responsibility for the issue. They ask about the outcome. And in business continuity, the outcome is measured by one thing: whether the company can continue operating.
The first question addresses dependency. Losing access to a provider does not necessarily mean that the provider has gone bankrupt. A change in contractual terms, a dispute, or a regulatory or geopolitical decision may be enough. A company that can continue operating has a genuine alternative. A company that cannot is simply hoping that the situation will never arise. And hope is not a business continuity mechanism.
The second question separates documentation from capability. A disaster scenario described in a procedure and one actually tested by the team are two very different things. Only an exercise reveals what is missing from the plan, how long each step really takes and who makes decisions in practice. The word “actually” is the most important part of this question.
The third question determines whether the company is tied to a single environment. The ability to restore a system elsewhere means that no single location, platform or service determines whether the business can continue operating. Without this capability, every recovery plan leads back to the same environment in which the problem began.
The fourth question is often the most uncomfortable. Assurances included in contracts with providers describe intentions and commitments, but they are no substitute for knowledge. Control over data means that the company itself knows where the data is stored, who has access to it and what happens to it. If the contract is the only source of this knowledge, someone else is in control.
These four questions have one thing in common. The answers cannot be improvised for the sake of a meeting. Each one reveals a capability that the organisation either has or does not have. This is precisely why companies should ask themselves these questions before reality asks them instead.
There is another benefit to this assessment. Every “no” and every “I don’t know” identifies a specific area that requires attention. Dependency on a provider can be reduced. A disaster scenario can be tested. A recovery environment can be prepared. The organisation can improve its understanding of where its data is stored, who has access to it and how it is managed. A list of four shortcomings then becomes a plan for the coming quarters, and the feeling of being prepared begins to give way to genuine preparedness.
Four questions, a few minutes of honest conversation and a great deal of insight into your own company. It is difficult to find a less expensive readiness audit. And it is difficult to find a better time to conduct one than before anything goes wrong.
