Senior leadership to engage in discussions about potential risks related to new projects and releases during the Weekly Management Meeting. Mitigating factors to be determined and rolled out to minimize potential disruption.
For all major releases, conduct 'pre-mortems' to brainstorm potential risks and develop mitigation strategies. 'Post-mortems' should be conducted for major production problems, focusing on establishing root causes and learning lessons for continuous improvement.
Uhubs runs on Google Cloud Platform for compute and analytics, Supabase for the managed Postgres database, and Vercel for web hosting. Each provider offers redundancy and automated backup. Backup arrangements are set out in section 5.
Implement redundancy and failover systems to reduce the impact of disruptions. This ensures that critical functions can continue in the event of a failure, maintaining operational resilience.
Establish a robust remote work infrastructure to enable seamless business operations in the face of disruptions. This includes secure access to essential systems and data.
Uhubs's recovery time objective for the Platform is 24 hours, measured from declaration of the incident to restoration of full Platform functionality.
Define criteria for assessing the impact of business disruptions. This includes considering the duration, severity, and potential consequences on operations.
Establish clear communication channels and protocols to inform stakeholders promptly in the event of incidents. Transparent communication is critical for maintaining trust and managing expectations.
Data should be regularly backed up, with frequent 'fire drill' restorations to ensure that the backup processes are effective and that the restored data functions as expected.
Uhubs's recovery point objective is 4 hours, being the maximum period of data loss in a disaster.
Section 6 of this policy constitutes Uhubs's Disaster Recovery Plan. It is maintained alongside this Business Continuity Plan and both are available to customers on request.
Promptly identify and assess the nature of the disruption. Designate a primary contact for initial assessment. Communicate the situation to relevant stakeholders.
Activate the disaster response team with predefined roles. Mitigate impact, activate backups, and maintain essential functions.
Communicate transparently with employees, clients, and partners. Designate a spokesperson for consistent updates on the incident and expected resolution timelines.
Initiate recovery procedures. Conduct a post-incident analysis to identify lessons learned. Use insights to update and improve the disaster response plan for future incidents.
Establish rapid response teams responsible for executing the disaster plan promptly. Regular training and simulations should be conducted to ensure the team's preparedness.
This Business Continuity Management and Operational Resilience Policy underscores Uhubs's commitment to proactive risk management, continuous improvement, and maintaining resilience in the face of potential disruptions.
Uhubs is committed to maintaining a resilient workforce through ongoing training programs and awareness initiatives. This includes regular employee training sessions to ensure awareness of the business continuity plan, emergency response procedures, and individual responsibilities during disruptions. Employees will be informed about their roles in the execution of the plan, fostering a culture of preparedness and proactive response to potential incidents.
Uhubs tests its disaster recovery plan at least once every 12 months. Testing covers restoring the production database from backup and verifying data integrity after restore. Results are recorded, and a summary of the most recent test is available to customers on request.
Uhubs recognizes the importance of regulatory compliance in maintaining operational resilience. The Business Continuity Management and Operational Resilience plan aligns with applicable industry standards and legal obligations. Regular reviews will be conducted to ensure ongoing compliance with evolving regulatory requirements, providing assurance that Uhubs operates within the bounds of relevant laws and standards during disruptions.
In acknowledgment of the digital landscape's significance, Uhubs has integrated a comprehensive cybersecurity incident response section into the broader business continuity plan. This includes clear guidelines for identifying, containing, eradicating, recovering from, and learning from cybersecurity incidents. The organization is committed to maintaining the integrity and security of its digital assets, ensuring a resilient response to potential cyber threats.
Effective communication is paramount during disruptions. Uhubs outlines specific communication channels (Slack) and tools to be used for both internal and external communication in the event of an incident. The policy includes contingency plans for potential communication failures, alternative methods for reaching stakeholders, and protocols to ensure transparent and timely communication throughout the organization.
Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.