Disaster Recovery Policy

Effective Date: August 17, 2025

1. Purpose

The purpose of this Disaster Recovery Policy is to define the framework for responding to major disruptions to Atfenix’s services caused by natural disasters, cyber incidents, hardware failures, or other emergencies. The goal is to minimize downtime, ensure data availability, and restore critical services as quickly as possible.

2. Scope

This policy applies to:

  • All Atfenix-owned and operated data centres.
  • Infrastructure supporting colocation, cloud, hosting, and managed services.
  • Employees, contractors, and vendors involved in critical service operations.
  • Customer workloads hosted on Atfenix infrastructure.

3. Objectives

  • Recovery Point Objective (RPO): Maximum data loss tolerance is < 4 hours for critical systems.
  • Recovery Time Objective (RTO): Critical services to be restored within 4–12 hours, full restoration within 24–48 hours, depending on service level agreements.
  • Business Continuity: Ensure customer operations experience minimal disruption.
  • Compliance: Align recovery processes with ISO 27001, SOC 2, and GDPR requirements.

4. Disaster Recovery Strategy

Atfenix employs a multi-layered disaster recovery strategy:

4.1 Data Backup

  • Automated daily backups of customer data.
  • Backups stored in multiple geographically distinct locations.
  • Encrypted storage using AES-256.
  • Regular testing of backup integrity and restorations.

4.2 Redundant Infrastructure

  • Tier 3 certified facilities with N+1 redundancy for power and cooling.
  • Multiple network providers (multi-homed architecture).
  • Failover capabilities across different availability zones.

4.3 Replication & Failover

  • Real-time replication for mission-critical workloads.
  • Hot-standby and warm-standby recovery environments depending on service tier.
  • Automated failover mechanisms for critical services.

4.4 Incident Response Integration

  • Disaster Recovery plan is tightly integrated with the Incident Response Plan (IRP).
  • Immediate incident classification and severity assessment.
  • Communication protocols for customers, partners, and regulators.

5. Roles & Responsibilities

  • Disaster Recovery Team (DRT): Core team responsible for executing recovery procedures.
  • IT Operations: Ensures backup, replication, and system restores.
  • Facility Management: Handles physical infrastructure continuity.
  • Security Team (SOC): Monitors and mitigates cyber-related disasters.
  • Communications Team: Keeps customers informed with timely updates.

6. Communication Plan

  • Customers notified via email, customer portal, and status page within 1 hour of disaster declaration.
  • Regular updates provided until full restoration.
  • Post-incident report shared within 72 hours, detailing cause, impact, and corrective measures.

7. Testing & Maintenance

  • DR drills conducted bi-annually (twice a year).
  • Scenario-based recovery tests (cyber-attack, power outage, natural disaster).
  • Documentation reviewed and updated after each drill.
  • Continuous improvement process to strengthen resilience.

8. Customer Responsibilities

  • Ensure their workloads are configured for redundancy if required.
  • Define custom RPO/RTO requirements if standard tiers are insufficient.
  • Maintain updated contact information for DR communications.

9. Continuous Improvement

Atfenix is committed to ongoing evaluation of disaster recovery capabilities, leveraging emerging technologies such as AI-driven monitoring, predictive analytics, and cloud-based failover to reduce downtime further.

Contact Us

For Disaster Recovery inquiries, please contact us.