Security & Compliance

Disaster Recovery Policy

The plans and objectives that allow Skoolfly to restore operations after a major disruption.

1. Policy Statement

Skoolfly plans for the restoration of critical systems and data after major disruptions such as infrastructure failure, data loss, cyber incidents or natural disasters. This policy defines recovery objectives, strategies and testing to enable orderly recovery.

2. Purpose

The purpose of this policy is to ensure that Skoolfly can resume critical operations and recover data within defined objectives, minimising the impact of disruptions on schools, users and business operations.

3. Scope

This policy applies to major disruptions affecting the availability of Skoolfly services, infrastructure or data, and complements the Incident Response Policy, which addresses the immediate handling of security events.

4. Recovery Objectives

Recovery is planned against measurable objectives

Recovery Point Objective (RPO)The maximum acceptable amount of data loss, defining how frequently backups and replication occur.
Recovery Time Objective (RTO)The maximum acceptable time to restore critical services after a disruption.
Service levelsObjectives are set by data criticality and reviewed periodically.

5. Business Impact Assessment

Skoolfly assesses the impact of disruptions on critical functions and data, prioritising recovery based on severity, user impact and legal or contractual obligations. Priorities are documented and kept up to date.

6. Disaster Scenarios

Failure of a primary region or cloud provider.

Large-scale data corruption or deletion.

Ransomware or hostile takeover of production systems.

Extended infrastructure or connectivity outages.

Physical site or access incidents affecting operations.

7. Recovery Strategy

Data is protected through backups and replication in line with the Backup Policy.

Critical workloads are designed to be recoverable in a secondary environment or region.

Recovery procedures are documented and versioned.

Recovery priorities follow the business impact assessment.

8. Roles and Responsibilities

Disaster recovery coordinatorLeads recovery efforts and declares recovery events.
Engineering / DevOpsExecute technical recovery and restoration of services.
Product / SupportCommunicate status and restore user-facing functionality.
CommunicationsManage internal and external status communication.
Security ownerEnsures recovery actions preserve security and compliance.

9. Testing and Maintenance

Recovery arrangements are tested at least periodically to confirm they work.

Tests validate restoration of data, services and connectivity.

Test findings are documented and remediated.

Plans and objectives are revised after tests, incidents and significant system changes.

10. Communication

During a recovery event, affected schools and users are informed of status and expected restoration times through appropriate channels. Communication is coordinated to be accurate and timely.

11. Review

This policy is reviewed at least annually, after recovery tests and events, and when infrastructure or service architecture changes significantly.