Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

Disaster Recovery Plan

This document establishes the strategic and tactical Disaster Recovery (DR) framework for anDREa B.V. It outlines the operational steps and restoration procedures required to handle adverse scenarios while maintaining compliance with ISO 27001:2023 (A.05.29* - A.05.30)* and NIS 2 (Article 21 - Business Continuity & Crisis Management).


1. Governance, Scope, & Core Team

  • Classification: Public
  • Scope: Aligned with ISO 27001 Clause 4 (Context of the Organisation), encompassing all critical environments and infrastructures.
  • Review Cycle: Reviewed at least annually or immediately following significant architecture or pipeline modifications.
  • Mandatory Reading: Compulsory for all anDREa employees and active contractors.

Emergency Contact Directory

In a disaster scenario, the Disaster Recovery Team assumes operational control. All standard support communications route through a central secure email alias.

NameRolePrimary Contact
Stefan van AalstDirector / Executive Spokespersonsecurity@andrea-cloud.com / +31 6 2125 3834
Johanna HakonenOperations Managersecurity@andrea-cloud.com
Pascalle BroerBusiness Managersecurity@andrea-cloud.com
Kunal K.Development Teamsecurity@andrea-cloud.com
Timo L.Development Teamsecurity@andrea-cloud.com
Irene StenversCustomer Supportsecurity@andrea-cloud.com

2. Crisis Management & Communication Protocol

The response strategy acts as an adaptable guideline. Emerging discoveries dictate tactical execution. For data breaches, the Data Breach Procedure must override standard paths.

Incident Registration

During a crisis, the team registers timeline updates, actions, and evidence within a dedicated internal ticket. Post-resolution, the DR team compiles a formal incident analysis report.

Stakeholder Matrix & Strategy


                     ┌─────────────────────────┐
                     │   Disaster Recovery     │
                     │     Incident Ticket     │
                     └────────────┬────────────┘
                                  │
       ┌──────────────────────────┼──────────────────────────┐
       ▼                          ▼                          ▼
┌─────────────────┐        ┌─────────────────┐        ┌─────────────────┐
│     Tenants     │        │  Shareholders   │        │ Regulatory/Media│
│ Email & Status  │        │ Direct Call &   │        │ Exec Escalation │
│ Dashboards      │        │ Status Cadence  │        │ & Statements    │
└─────────────────┘        └─────────────────┘        └─────────────────┘

  • Employees: The DR team convenes active personnel for briefings and circulates formal guidance via email or text.
  • Tenants: Communication goes directly to designated Tenant contacts (Security Officers, Local Support, Project Managers). Concurrently, an outage announcement is posted on the mydre.org login panel and support.mydre.org.
note

anDREa does not communicate with the tenant’s individual end-users unless explicitly requested. Local Research Support Teams are responsible for end-user messaging.

  • Shareholders: The Director provides status updates directly to shareholders on an agreed cadence.
  • Authoritative Bodies & Media: Managed exclusively by the Director. Employees must refer all media inquiries to executive leadership.
  • Ransomware Escalation (ISO A.05.26): Immediate notification must be made to our professional liability and cyber insurance providers.

3. Critical Infrastructure & Restoration Paths

Critical resources are vital to anDREa operations. Their impairment directly disrupts platform availability.

Microsoft Entra ID

  • Mitigation: Immediate deployment of a Severity Level A support ticket with Microsoft.

Multi-Factor Authentication (MFA) Failure

  • Mitigation: Immediate deployment of a Severity Level A support ticket with Microsoft.
  • Mapped Risks: R021, R045

Platform Source Code & Deployment Integrity

  • Escrow Safeguards: Source code and deployment configurations are pushed quarterly to an independent Escrow provider. The Escrow agent retains full capacity to compile, deploy, and maintain myDRE independently if anDREa faces insolvency, permanent legal blocks, or catastrophic ransomware events.
  • Recovery Pipelines: Application and infrastructure blueprints are versioned via automated, role-restricted pipelines (GitHub to Azure DevOps service connections). Pipeline executions serve as ongoing, automated recovery tests.
  • Mapped Risks: R002, R003, R004, R035, R042

Data Topology on myDRE

All production data is located in Microsoft Azure Data Centers within the West Europe region (Amsterdam), residing directly on Tenant billing subscriptions.

  • Storage Tier: Locally Redundant Storage (LRS) maintains 3 synchronous copies inside a single datacenter facility to protect against hardware faults.

  • Recovery Point Objective (RPO): Snapshots of Workspace fileshares run every 24 hours and are retained for 30 days, yielding a strict 24-hour RPO.

  • Risk & Mitigation Profiles:

  • Data Center Destruction: LRS leaves data vulnerable to facilities damage. Enhanced redundancy is available as an option. Higher-tier storage must be requested and funded by the individual Workspace Accountable.

  • Malicious/Accidental Deletion: Resource locks protect storage repositories. If a compromise bypasses locks, Microsoft enforces a 14-day soft-delete retention safety net. anDREa maintains documented proof of successful recoveries using this window.

  • Data Egress Without Audit Trails: Authorized users can configure data transfers or allowlist IPs, which bypass parts of the audit path. This configuration prompts an explicit confirmation warning. anDREa monitors for anomalous behavior but does not restrict authorized accounts acting maliciously.

  • Mapped Risks: R008, R021, R022, R035, R036, R047

Google Workspace Ecosystem

Corporate files and messaging sit within Google Workspace.

  • Data Center Loss: Mitigated by Google's native distributed datacenter architecture.
  • Configuration Drift/Human Error: Minimized via strict Role-Based Access Control (RBAC) and recurring entitlement audits.
  • Accidental/Malicious Deletion: Group-level access structures and Google Vault retention policies provide restoration capabilities.
  • Exfiltration Monitoring: File interactions generate unalterable Drive Log Events, which are audited during offboarding or upon anomaly detection.
  • Workspace Outages: Core communications shift temporarily to independent fallback Microsoft accounts.
  • Mapped Risks: R008, R021, R022, R035, R036, R047

Privileged Account Fail-Safes (Account Takeovers)

If a disaster isolates privileged account holders, team redundancy plans dictate delegated stand-in roles. For emergency lockouts:

  1. Break-the-Glass Account: Credentials reside inside a shared 1Password vault.
  2. Identity Takeover: Administrators can trigger an identity reset and register new MFA factors via Azure Privileged Identity Management (PIM). All emergency access requires a pre-authorized justification ticket.
  • Mapped Risks: R022, R048

Corporate Finance & Operations

  • Invoicing: Invoices are routed to a central financial mailbox restricted via Google Groups.
  • Accounting Continuity: An external accounting firm maintains current records on independent software. Continuity and backup guarantees are bound within the supplier service level agreement. Payments staged in accounting systems require executive verification before execution. Financial workflows can revert to manual invoice tracking if systems fail.
  • Mapped Risks: R019

4. Non-Critical Resources

Disruptions to non-critical resources do not impact primary myDRE platform operations.

  • Ticketing & Knowledge Base: Backed up every 6 months into .html file structures stored inside GitHub, allowing restoration onto any standard ticketing platform. Developer documentation is backed up automatically via quarterly Escrow transfers.
  • Virtual Machines (VMs): Classified as temporary resources and are not backed up by default. Data is isolated on independent Workspace fileshares. If a VM fails, it can be quickly redeployed via standardized cloud templates. Higher tiers can be configured upon request.
  • Workspace Configurations: Workspace membership configurations are not permanently archived. Re-assembly can be derived from audit trails and support ticket histories. The system archival tools allow configuration state export via JSON metadata snapshots.
  • Auxiliary SaaS Tools: Governance, recovery metrics, and data integrity parameters are managed via individual supplier contracts and listed within our Record of Processing Activities (ROPA).
  • Mapped Risks: R008, R019, R026, R033