Does Cyber Crucible have a disaster recovery and business continuity plan?
Short answer: Yes. Cyber Crucible maintains a tested disaster-recovery plan owned by IT management and an architecture built for high availability. Because threat prevention runs locally on the endpoint, endpoint protection continues even during a management-backend outage.
Resilience by architecture
The management backend is built with redundant, replicated storage so that the loss of an individual node does not cause data loss or downtime. The published Service Level Agreement commits to 99.9% monthly availability for the management and reporting backend, exclusive of scheduled maintenance and causes beyond reasonable control. Endpoint protection itself is unaffected by a backend outage.
Backups and contingency planning
Data is continuously replicated and backed up to secure offsite storage using distinct privileged credentials, with backups protected against ransomware through offline or immutable handling and tested on a regular basis. The plan maintains a computer emergency response plan, a succession plan, a data-criticality study, and a criticality-of-service list, and incorporates business-impact analysis, recovery strategies, a communication plan including customer notification, and defined recovery objectives. Testing includes table-top exercises and recovery drills.
Framework alignment and the honest boundary
The plan aligns to NIST SP 800-34 and ISO/IEC 27001:2022 A.5.29–A.5.30. Cyber Crucible defines recovery-point and recovery-time objectives for the backend; the specific target values, and the plan itself, are provided to reviewers under NDA. Because protection executes locally, endpoint defense continues with effectively no recovery-time gap during a backend outage or in an air-gapped deployment.