
For a financial firm, an IT outage is more than an inconvenience. When systems go down, employees may be unable to access client records, process transactions, communicate with customers, or perform critical business functions.
And the cause doesn’t necessarily have to be a ransomware attack. A failed server, internet outage, software update, cloud service disruption, power failure, or problem with a third-party provider can bring business to a standstill just as quickly.
For financial firms, the question isn’t if an IT disruption will happen. It’s whether the firm is prepared to continue operating when it does.
FINRA requires member firms to maintain written business continuity plans that address mission-critical systems, backup and recovery, alternate communications, regulatory reporting, and other areas necessary to maintain operations during a significant disruption.
Start by Identifying What You Can’t Operate Without
The first step in outage preparedness is identifying your firm’s mission-critical systems.
Consider what happens if employees suddenly cannot access:
- Financial or portfolio management applications
- Client records
- File servers
- Trading or transaction systems
- Accounting systems
- Authentication and Microsoft 365
- Internet connectivity
- VoIP phone systems
- Cloud applications
- Critical third-party services
Don’t simply make a list of applications. Determine what the business impact would be if each system were unavailable for one hour, four hours, eight hours, or an entire business day.
This helps establish two important recovery objectives: how quickly a system needs to be restored and how much data the firm can afford to lose.
On-Premises Servers vs. Cloud-Based Applications
One of the most important considerations is whether your firm’s critical applications run on servers located in your office or are hosted elsewhere.
Firms With On-Premises Application Servers
Firms with on-premises servers have more direct responsibility for their technology infrastructure.
If a server hosting a critical application fails, the firm may need to deal with hardware replacement, operating system recovery, application restoration, network connectivity, and data recovery—all before employees can get back to work.
That makes redundancy and backup especially important.
An effective strategy may include redundant hardware, virtualization, backup power, multiple internet connections, off-site backups, and a documented recovery process. Backups should also be protected from the same event that takes down the primary environment.
For example, if ransomware encrypts the firm’s server and its attached backup system, having “a backup” doesn’t necessarily mean having a usable recovery strategy.
Financial institutions should regularly test recovery procedures, including recovery from offline backups and scenarios in which critical providers or systems are unavailable.
Firms Without On-Premises Application Servers
Moving applications to the cloud can eliminate some of the infrastructure responsibilities associated with maintaining physical servers—but it doesn’t eliminate outage risk.
Instead, the risk changes.
If your firm’s critical applications are hosted by third parties, you need to understand what happens when their systems experience an outage.
Can employees still access their data? Is there an alternate method of communicating with clients? What happens if Microsoft 365, a line-of-business application, a cloud hosting provider, or an internet service provider becomes unavailable?
Third-party risk has become increasingly important. FINRA has specifically highlighted increases in cyberattacks and outages involving technology providers used by financial firms.
Cloud services can provide significant resilience, but firms shouldn’t assume that “it’s in the cloud” automatically means “it’s always available.”
Don’t Forget the Internet
An often-overlooked single point of failure is the firm’s internet connection.
If your critical applications are cloud-based and your primary internet circuit goes down, employees may effectively be locked out of the business.
Financial firms should consider whether they need redundant internet connectivity, preferably using different providers or technologies. A backup connection is only useful if it can actually support the firm’s critical operations when the primary connection fails.
The same principle applies to phones and communications.
If email, Teams, VoIP, and other communication systems are unavailable, employees need another way to communicate internally and with clients.
Make Backups Part of the Recovery Strategy
Backups are important, but simply having backups isn’t enough.
Financial firms should know:
What is being backed up?
Where is it stored?
How frequently is it backed up?
How long does recovery take?
Who is responsible for restoring it?
Has the recovery actually been tested?
A backup that has never been restored is a theory—not a recovery plan.
Backups should also be protected against ransomware and other destructive events. Depending on the firm’s risk profile, this can include immutable, offline, or otherwise isolated backup copies.
Create an Outage Playbook
When an outage happens, people shouldn’t have to figure everything out from scratch.
Create a simple, documented response plan that answers:
- Who declares an IT incident?
- Who contacts the IT provider?
- Who communicates with employees?
- Who communicates with clients?
- What systems get restored first?
- What alternate communication methods are available?
- Who contacts critical vendors?
- When should management or regulators be notified?
- Who makes the decision to move to an alternate operating environment?
The plan should be tested—not simply placed in a binder and forgotten.
FINRA specifically encourages firms to use realistic exercises to strengthen coordination, clarify responsibilities, and identify gaps before an actual disruption occurs.
Your IT Outage Plan Should Include Your Vendors
Your firm may have an excellent internal recovery plan and still be vulnerable if a critical vendor doesn’t.
Review the business continuity and disaster recovery capabilities of important technology providers. Understand their recovery objectives, backup practices, support procedures, and communication processes.
Regulators have emphasized that outsourcing a critical function doesn’t eliminate the financial firm’s responsibility to manage the associated risk.
Prepare Before the Outage Happens
The worst time to develop an outage recovery plan is when employees are staring at blank screens and asking, “How long until we’re back up?”
A resilient financial firm understands its critical technology, knows where its dependencies are, maintains reliable backups, has alternate communication methods, and regularly tests its recovery procedures.
Whether your applications run on servers in your office or primarily in the cloud, the objective is the same:
Keep the business operating when technology doesn’t.
Is Your Financial Firm Prepared for an IT Outage?
Data Troop helps financial firms identify technology risks, strengthen backup and recovery strategies, improve cybersecurity, and develop practical business continuity plans.
Data Troop can review your firm’s IT environment and help identify the gaps that could turn a short technology outage into a serious business disruption.
Contact Data Troop to schedule an IT resilience review and find out how prepared your firm really is.
