Glossary
Business continuity
Business continuity is an organization's capability to keep delivering its products and services at an acceptable level during a disruption, and to return to normal operation afterwards. It spans people, premises, suppliers and processes as well as IT systems.
Why business continuity matters to infrastructure teams
Continuity is usually owned by risk or operations functions, and its language is about processes: payments, claims, production lines, customer support. Every one of those processes runs on shared infrastructure, so the commitments made in a continuity programme land on compute, network, identity and storage. A two-hour recovery target for a trading process becomes a two-hour target for the platforms beneath it, whether or not the infrastructure team was in the room when it was set.
In regulated sectors the commitments are also external. Financial, healthcare and public-sector regulators expect documented continuity arrangements and evidence that they work.
Business continuity and disaster recovery
The two terms are often paired and differ in scope. Disaster recovery restores information systems and data. Business continuity keeps the business functioning, which also needs staff who can work, a place or method to work from, suppliers who still deliver, customers who can be reached, and manual workarounds while systems are down. A disaster recovery capability is one of the means by which a continuity plan is carried out, and the disaster recovery plan is one of the documents beneath the continuity plan. The practical difference shows up in a real event: IT can restore every system on schedule while the business still stalls because staff cannot reach the recovered applications, or a key supplier is affected by the same outage.
How a continuity programme runs
ISO 22301 specifies a business continuity management system: policies, roles, processes and records through which continuity is run as an ongoing activity, and against which organizations can be certified. Programmes repeat a cycle:
- Analysis: a business impact analysis identifies critical activities, how disruption to them escalates over time and what they depend on, alongside a risk assessment.
- Strategy: options are chosen for each activity and resource, balancing cost against the recovery times the analysis requires.
- Plans: documented procedures for response, communication and recovery.
- Exercising: plans are rehearsed, from discussion exercises to live recovery tests.
- Review: results, real incidents and organizational change feed the next cycle.
Continuity also defines who decides during a disruption, typically an incident team for the immediate event, a recovery team for resuming activities, and a crisis team of senior staff for strategic decisions and external communication.
Dependencies and concentration risk
Continuity depends on the least resilient element in a chain. A process with fully redundant applications can still stop because of a shared identity service, a single network carrier or one person with sole knowledge of a procedure. Concentration risk is the case where many activities share one such element, so a single outage disrupts all of them together.
Availability targets do not capture this. A service at 99.9% availability is allowed 8.76 hours of downtime a year in total, and one 12-hour outage breaks that by itself. Continuity planning is concerned with that single prolonged event, which an annual percentage says little about.
What business continuity means for infrastructure teams
Consolidation concentrates risk. Moving forty applications onto one storage platform reduces cost and operational effort, and it also means that one platform outage now touches forty processes at once. That is acceptable when the platform's own resilience matches the strictest requirement among them, and a hidden exposure when it does not. The continuity programme's dependency maps are where that mismatch becomes visible.
Recovery tiers from the analysis translate into infrastructure choices with very different costs: synchronous multi-site storage for the few processes that cannot stop, asynchronous replication for the next tier, and restore from backup for the rest. Placing everything in the top tier is the most expensive answer, and placing everything in the bottom one leaves critical processes waiting days for petabytes to restore.
Continuity strategies also reach beyond the data centre. Alternate sites, cloud regions and suppliers each carry location and jurisdiction, which matters to organizations with sovereignty obligations. For lean infrastructure teams, the people dimension is real: a continuity plan that depends on two specific engineers being reachable is itself a single point of failure, and automation, documentation and platforms that need fewer recovery steps reduce that dependency.
Scality storage in continuity strategies
Scality RING provides software-defined object and file storage on standard x86 servers and can run as a stretched cluster that writes synchronously across two or three sites within 10 Gb/s or greater bandwidth and under 5 ms latency. Scality documents that such a cluster keeps full read-write access through the loss of an entire site plus a further server or disk group, which suits the top recovery tier. For copies that need to outlast logical damage, RING supports S3 Object Lock in governance and compliance modes, with compliance-mode versions protected from deletion by every user until their retain-until date.














