Security & Compliance
Disaster Recovery Policy
The plans and objectives that allow Skoolfly to restore operations after a major disruption.
1. Policy Statement
Skoolfly plans for the restoration of critical systems and data after major disruptions such as infrastructure failure, data loss, cyber incidents or natural disasters. This policy defines recovery objectives, strategies and testing to enable orderly recovery.
2. Purpose
The purpose of this policy is to ensure that Skoolfly can resume critical operations and recover data within defined objectives, minimising the impact of disruptions on schools, users and business operations.
3. Scope
This policy applies to major disruptions affecting the availability of Skoolfly services, infrastructure or data, and complements the Incident Response Policy, which addresses the immediate handling of security events.
4. Recovery Objectives
Recovery is planned against measurable objectives
5. Business Impact Assessment
Skoolfly assesses the impact of disruptions on critical functions and data, prioritising recovery based on severity, user impact and legal or contractual obligations. Priorities are documented and kept up to date.
6. Disaster Scenarios
Failure of a primary region or cloud provider.
Large-scale data corruption or deletion.
Ransomware or hostile takeover of production systems.
Extended infrastructure or connectivity outages.
Physical site or access incidents affecting operations.
7. Recovery Strategy
Data is protected through backups and replication in line with the Backup Policy.
Critical workloads are designed to be recoverable in a secondary environment or region.
Recovery procedures are documented and versioned.
Recovery priorities follow the business impact assessment.
8. Roles and Responsibilities
9. Testing and Maintenance
Recovery arrangements are tested at least periodically to confirm they work.
Tests validate restoration of data, services and connectivity.
Test findings are documented and remediated.
Plans and objectives are revised after tests, incidents and significant system changes.
10. Communication
During a recovery event, affected schools and users are informed of status and expected restoration times through appropriate channels. Communication is coordinated to be accurate and timely.
11. Review
This policy is reviewed at least annually, after recovery tests and events, and when infrastructure or service architecture changes significantly.
