How [TeamTalk Ltd] keeps the TeamTalk service running, and what happens if it cannot. Written for a customer's continuity or procurement reviewer.
As at [date] TeamTalk has one director and no employees. Where this policy names a second role or a review cycle, it takes effect when that person is engaged. External escalation: [accountant / solicitor, name and telephone].
This summary describes how [TeamTalk Ltd] maintains the TeamTalk service through disruption, and how it recovers if the service is lost. It covers the production environment, the company's people and its critical suppliers. The full plan is held at [location] and is available to a customer under a confidentiality undertaking.
The company is small and says so. This plan is written for a business of that size: it depends on reproducible infrastructure and tested backups rather than on standby sites and duty rotas that a company of this size cannot staff.
| Objective | Target |
|---|---|
| Recovery time objective (application) | [4] hours from a confirmed loss of the production server |
| Recovery point objective (data) | [24] hours, or [5 minutes] where point-in-time recovery is enabled |
| Maximum tolerable period of disruption | [24] hours |
| Backup frequency and retention | [Daily], encrypted, retained [30] days in the same UK region |
| Restore testing | [Quarterly] full restore to a scratch environment, with date, duration and outcome recorded |
Each customer has a named contact and each has named a contact within its own organisation. During a disruption the company communicates by telephone and email to that person, gives the facts it has confirmed rather than waiting for a complete picture, and states when the next update will come. Status is also published at [status page URL]. The company does not use the affected platform as its only channel for telling customers that the platform is affected.
The restore procedure is tested [quarterly] and the incident response procedure is walked through [annually], with findings recorded and acted on. This summary is reviewed at least annually and after any incident or material change to the architecture.
What this plan does not claim. There is no hot standby environment and no automatic failover to a second region. There is no 24-hour staffed operations centre. The company is not certified to ISO 22301. These are the honest limits of a business of this size, and a customer requiring more should say so during evaluation, when the cost of providing it can be discussed, rather than discovering it during an incident.