Resilience & Incident Response
Business Continuity
How we plan for business continuity and disaster recovery so we can keep serving customers during a disruption.
Last reviewed: July 2026
We are committed to providing a high level of service to our customers, including during disruptions. This page explains how we plan for business continuity and disaster recovery so that our commitments to customers can continue to be met.
Our approach
Continuity of operations in a secure manner is planned for and embedded in our business continuity management and disaster recovery activities. Our information security processes are designed to preserve the confidentiality, integrity, and availability of critical information assets even in the event of a business disruption or disaster.
- We identify recovery guidelines that serve as a baseline for classifying mission-critical systems and developing recovery and restoration plans.
- We maintain a strategy for our overall business continuity and disaster recovery approach.
- Security controls that apply during business-as-usual operations remain relevant during disaster scenarios, and any exceptions require senior management approval.
Preparing and responding
We maintain an adequate framework to prepare for, mitigate, and respond to a disruptive event, staffed by personnel with the necessary authority, experience, and competence.
- We identify personnel with the responsibility, authority, and competence to manage an incident while maintaining information security.
- We maintain an adequate framework, staffed by people with the necessary authority and competence, to prepare for, mitigate, and respond to a disruptive event.
Testing and review
- Information security controls for all business continuity sites and systems are reviewed and verified.
- Business continuity plans are tested and updated regularly to keep them current and effective.
- Roles and responsibilities for contingency planning and recovery are reviewed and updated at least annually.
Redundancy
- We identify the business requirements for the availability of our information systems.
- Where availability cannot be guaranteed by the existing architecture, we consider redundant components or architectures.
- Redundant systems are tested to confirm successful failover from one component to another.
Questions
If you have any questions about this policy, contact us at [email protected].
Questions about this policy? [email protected]
