Disaster Recovery Plan
This document establishes the strategic and tactical Disaster Recovery (DR) framework for anDREa B.V. It outlines the operational steps and restoration procedures required to handle adverse scenarios while maintaining compliance with ISO 27001:2023 (A.05.29* - A.05.30)* and NIS 2 (Article 21 - Business Continuity & Crisis Management).
1. Governance, Scope, & Core Team
- Classification: Public
- Scope: Aligned with ISO 27001 Clause 4 (Context of the Organisation), encompassing all critical environments and infrastructures.
- Review Cycle: Reviewed at least annually or immediately following significant architecture or pipeline modifications.
- Mandatory Reading: Compulsory for all anDREa employees and active contractors.
Emergency Contact Directory
In a disaster scenario, the Disaster Recovery Team assumes operational control. All standard support communications route through a central secure email alias.
| Name | Role | Primary Contact |
|---|---|---|
| Stefan van Aalst | Director / Executive Spokesperson | security@andrea-cloud.com / +31 6 2125 3834 |
| Johanna Hakonen | Operations Manager | security@andrea-cloud.com |
| Pascalle Broer | Business Manager | security@andrea-cloud.com |
| Kunal K. | Development Team | security@andrea-cloud.com |
| Timo L. | Development Team | security@andrea-cloud.com |
| Irene Stenvers | Customer Support | security@andrea-cloud.com |
2. Crisis Management & Communication Protocol
The response strategy acts as an adaptable guideline. Emerging discoveries dictate tactical execution. For data breaches, the Data Breach Procedure must override standard paths.
Incident Registration
During a crisis, the team registers timeline updates, actions, and evidence within a dedicated internal ticket. Post-resolution, the DR team compiles a formal incident analysis report.
Stakeholder Matrix & Strategy
┌─────────────────────────┐
│ Disaster Recovery │
│ Incident Ticket │
└────────────┬────────────┘
│
┌──────────────────────────┼──────────────────────────┐
▼ ▼ ▼
┌─────────────────┐ ┌─────────────────┐ ┌─────────────────┐
│ Tenants │ │ Shareholders │ │ Regulatory/Media│
│ Email & Status │ │ Direct Call & │ │ Exec Escalation │
│ Dashboards │ │ Status Cadence │ │ & Statements │
└─────────────────┘ └─────────────────┘ └─────────────────┘
- Employees: The DR team convenes active personnel for briefings and circulates formal guidance via email or text.
- Tenants: Communication goes directly to designated Tenant contacts (Security Officers, Local Support, Project Managers). Concurrently, an outage announcement is posted on the
mydre.orglogin panel andsupport.mydre.org.
anDREa does not communicate with the tenant’s individual end-users unless explicitly requested. Local Research Support Teams are responsible for end-user messaging.
- Shareholders: The Director provides status updates directly to shareholders on an agreed cadence.
- Authoritative Bodies & Media: Managed exclusively by the Director. Employees must refer all media inquiries to executive leadership.
- Ransomware Escalation (ISO A.05.26): Immediate notification must be made to our professional liability and cyber insurance providers.
3. Critical Infrastructure & Restoration Paths
Critical resources are vital to anDREa operations. Their impairment directly disrupts platform availability.
Microsoft Entra ID
- Mitigation: Immediate deployment of a Severity Level A support ticket with Microsoft.
Multi-Factor Authentication (MFA) Failure
- Mitigation: Immediate deployment of a Severity Level A support ticket with Microsoft.
- Mapped Risks: R021, R045
Platform Source Code & Deployment Integrity
- Escrow Safeguards: Source code and deployment configurations are pushed quarterly to an independent Escrow provider. The Escrow agent retains full capacity to compile, deploy, and maintain myDRE independently if anDREa faces insolvency, permanent legal blocks, or catastrophic ransomware events.
- Recovery Pipelines: Application and infrastructure blueprints are versioned via automated, role-restricted pipelines (GitHub to Azure DevOps service connections). Pipeline executions serve as ongoing, automated recovery tests.
- Mapped Risks: R002, R003, R004, R035, R042
Data Topology on myDRE
All production data is located in Microsoft Azure Data Centers within the West Europe region (Amsterdam), residing directly on Tenant billing subscriptions.
-
Storage Tier: Locally Redundant Storage (LRS) maintains 3 synchronous copies inside a single datacenter facility to protect against hardware faults.
-
Recovery Point Objective (RPO): Snapshots of Workspace fileshares run every 24 hours and are retained for 30 days, yielding a strict 24-hour RPO.
-
Risk & Mitigation Profiles:
-
Data Center Destruction: LRS leaves data vulnerable to facilities damage. Enhanced redundancy is available as an option. Higher-tier storage must be requested and funded by the individual Workspace Accountable.
-
Malicious/Accidental Deletion: Resource locks protect storage repositories. If a compromise bypasses locks, Microsoft enforces a 14-day soft-delete retention safety net. anDREa maintains documented proof of successful recoveries using this window.
-
Data Egress Without Audit Trails: Authorized users can configure data transfers or allowlist IPs, which bypass parts of the audit path. This configuration prompts an explicit confirmation warning. anDREa monitors for anomalous behavior but does not restrict authorized accounts acting maliciously.
-
Mapped Risks: R008, R021, R022, R035, R036, R047
Google Workspace Ecosystem
Corporate files and messaging sit within Google Workspace.
- Data Center Loss: Mitigated by Google's native distributed datacenter architecture.
- Configuration Drift/Human Error: Minimized via strict Role-Based Access Control (RBAC) and recurring entitlement audits.
- Accidental/Malicious Deletion: Group-level access structures and Google Vault retention policies provide restoration capabilities.
- Exfiltration Monitoring: File interactions generate unalterable Drive Log Events, which are audited during offboarding or upon anomaly detection.
- Workspace Outages: Core communications shift temporarily to independent fallback Microsoft accounts.
- Mapped Risks: R008, R021, R022, R035, R036, R047
Privileged Account Fail-Safes (Account Takeovers)
If a disaster isolates privileged account holders, team redundancy plans dictate delegated stand-in roles. For emergency lockouts:
- Break-the-Glass Account: Credentials reside inside a shared 1Password vault.
- Identity Takeover: Administrators can trigger an identity reset and register new MFA factors via Azure Privileged Identity Management (PIM). All emergency access requires a pre-authorized justification ticket.
- Mapped Risks: R022, R048
Corporate Finance & Operations
- Invoicing: Invoices are routed to a central financial mailbox restricted via Google Groups.
- Accounting Continuity: An external accounting firm maintains current records on independent software. Continuity and backup guarantees are bound within the supplier service level agreement. Payments staged in accounting systems require executive verification before execution. Financial workflows can revert to manual invoice tracking if systems fail.
- Mapped Risks: R019
4. Non-Critical Resources
Disruptions to non-critical resources do not impact primary myDRE platform operations.
- Ticketing & Knowledge Base: Backed up every 6 months into
.htmlfile structures stored inside GitHub, allowing restoration onto any standard ticketing platform. Developer documentation is backed up automatically via quarterly Escrow transfers. - Virtual Machines (VMs): Classified as temporary resources and are not backed up by default. Data is isolated on independent Workspace fileshares. If a VM fails, it can be quickly redeployed via standardized cloud templates. Higher tiers can be configured upon request.
- Workspace Configurations: Workspace membership configurations are not permanently archived. Re-assembly can be derived from audit trails and support ticket histories. The system archival tools allow configuration state export via JSON metadata snapshots.
- Auxiliary SaaS Tools: Governance, recovery metrics, and data integrity parameters are managed via individual supplier contracts and listed within our Record of Processing Activities (ROPA).
- Mapped Risks: R008, R019, R026, R033