Guide / Operational & Financial Resilience

When One Person or Platform Holds the Business Together

A practical continuity guide for revealing key-person and platform dependencies, testing recovery paths and reducing single points of failure.

A business can appear distributed while one person controls every recovery path, or appear portable while its data, identity and workflow remain bound to one platform.

Continuity begins by revealing those dependencies without assuming that a backup exists merely because someone remembers creating one.

Fact: continuity is a managed and tested capability

ISO 22301 provides a framework for organisations to plan, operate, monitor, review, maintain and improve a business continuity management system. NIST’s contingency-planning guidance likewise focuses on evaluating systems and operations to set recovery requirements and priorities.

These sources are frameworks, not evidence that a particular business can recover. Evidence comes from current ownership, usable instructions, accessible alternatives and successful exercises.

Signal: the recovery route depends on the thing that failed

Test these signals against actual access and recovery evidence:

  • One person is the only administrator, signer, customer contact or holder of essential process knowledge.
  • Account recovery routes back to that person’s device, phone number or email.
  • A “backup” sits in the same platform, tenant or credential boundary as the live data.
  • Data can be viewed but has never been exported and restored in a usable form.
  • Critical automations, integrations, domain settings or licences are undocumented.
  • The vendor contract, plan tier or technical design makes migration slow, costly or uncertain.
  • The continuity plan names people who have left, suppliers that have changed or steps no one has tested.

Counter-signals include named and trained alternates, independent recovery access, tested restores, current vendor contacts, documented emergency authority and an exit path exercised by someone other than the usual operator.

Action: test two absences, not one generic disaster

First identify the minimum products or services that must continue, the longest tolerable interruption and the information needed to resume them. Government guidance on developing an emergency management plan recommends identifying critical areas, continuity arrangements and recovery steps.

Build a dependency register for each critical activity:

Dependency Primary Alternate Recovery evidence Last test
Decision authority Named role Valid delegate Current delegation Date
Process knowledge Procedure owner Trained operator Operator completed task Date
Identity and access Admin account Break-glass route Recovery exercise Date
Data Live system Independent copy Restore and reconciliation Date
Platform or supplier Current service Workaround or substitute Exit or outage exercise Date
Communication Main channel Alternate channel Contact drill Date

Then run two bounded exercises:

  1. Key person unavailable: assume the usual operator cannot be contacted for ten business days. Can the alternate make authorised decisions, reach customers, pay essential suppliers and perform the critical workflow?
  2. Platform unavailable: assume the service, tenant or primary credentials cannot be used for 48 hours. Can the team locate current data, communicate, operate a minimum process and begin recovery or transition?

Record failures as open variables with an owner and retest date. Keep sensitive credentials in an appropriate secrets-management system, not in the continuity document. Give the plan only the locations, roles and authorised recovery process needed to find them.

Limitations: resilience has context and cost

No continuity design removes every single point of failure. Recovery targets, redundancy and substitutes must reflect the business’s size, obligations, risk appetite and resources. ISO and NIST materials do not certify a plan or resolve local employment, privacy, security, financial or contractual requirements. A paper exercise can reveal gaps but cannot replace a controlled technical restore or operational drill.

This is general information, not legal or professional advice. Law and facts vary. Consult qualified advisers for a specific situation.

Primary source

ISO 22301 Business Continuity Management Systems. This source supports the identified facts; Paraveilux signals and recommendations remain interpretation.