1. Purpose
This policy sets out Murzo Group's approach to business continuity, disaster recovery, and operational resilience.
The purpose is to help Murzo Group continue or restore important activities after disruption, protect people and information, support customers and partners, and reduce legal, financial, safety, security, and reputational impact.
2. Scope
This policy applies to Murzo Group operations, digital services, suppliers, contractors, offices, remote work, logistics, product activity, data, communications, and international work where disruption could materially affect the organisation.
It applies to incidents including cyber attack, IT outage, data loss, supplier failure, premises loss, utility interruption, severe weather, public health issue, product incident, transport failure, financial disruption, geopolitical disruption, or loss of key personnel.
3. Critical Activities
Murzo Group will identify critical activities and dependencies using a proportionate business impact approach.
- Safety, security, legal, regulatory, and data protection obligations
- Customer, supplier, and partner communications
- Digital systems, domain names, email, website, client platforms, backups, and authentication
- Product safety, traceability, recall readiness, logistics, and stock control
- Finance, banking, insurance, payroll, contracting, and key records
- Key suppliers, hosting providers, professional advisers, laboratories, warehouses, and fulfilment partners
4. Continuity Planning
Murzo Group may maintain practical continuity arrangements for critical activities, including responsible owners, recovery priorities, emergency contacts, alternative communication routes, manual workarounds, supplier escalation routes, and authority contact details.
Continuity plans should be simple enough to use during pressure and detailed enough to support decision-making, record-keeping, and recovery.
5. Disaster Recovery & Technology Resilience
Technology recovery arrangements should reflect the importance of the affected system, the sensitivity of data, and the operational impact of downtime.
- Important data should be backed up using controlled and tested arrangements where practicable
- Access to recovery tools, administrator accounts, domain services, email, and cloud platforms should be protected
- Recovery steps should consider malware, ransomware, unauthorised access, corruption, accidental deletion, and supplier outages
- Systems should not be restored from untrusted backups or compromised environments without suitable review
- Significant technology incidents should be handled alongside cybersecurity and data breach procedures
6. Incident Activation & Decision Making
A continuity or recovery response may be activated where normal operations are materially disrupted, where a critical activity is at risk, or where senior management considers coordinated recovery necessary.
Murzo Group will prioritise life safety, legal compliance, containment of harm, protection of confidential information, customer and authority communication, and restoration of critical services.
7. Suppliers & Third Parties
Murzo Group relies on selected third parties and will take a risk-based approach to supplier continuity.
- Critical suppliers may be asked for continuity, security, insurance, incident notification, and recovery information
- Contracts may include requirements for service continuity, data return, audit cooperation, and notification of serious disruption
- Alternative suppliers, contingency routes, or manual workarounds may be considered where dependency risk is material
- Murzo Group may suspend or change a supplier where resilience is inadequate or disruption creates unacceptable risk
8. Communication
Internal and external communication during disruption must be factual, controlled, and aligned with the Crisis Communications & Incident Response Policy.
Public statements, customer notices, authority notifications, and media responses should be approved by authorised representatives wherever practicable.
9. Testing, Training & Improvement
Murzo Group may test continuity and disaster recovery arrangements through desktop exercises, contact-list checks, backup checks, supplier checks, scenario reviews, and lessons-learned exercises.
Findings from incidents, near misses, tests, audits, supplier failures, and cyber events should be used to improve resilience.
10. Records, Review & Responsibilities
Murzo Group will keep proportionate records of continuity plans, incidents, key decisions, recovery actions, communications, test results, supplier reviews, and corrective actions.
Directors, managers, system owners, product owners, operations leads, and authorised representatives are responsible for implementing continuity arrangements within their areas. This policy will be reviewed periodically and after significant disruption.