Step 2 · From $4,900 · 1-2 months
We audit your readiness for two critical scenarios — a ransomware attack and a drone incident with fire — and then raise your survival metrics. The audit is one third of the work. Two thirds is fixing: new plans, new arrangements, measurable recovery.
Every element below is a working document you keep. This is what you are paying for — and what your board, insurer and auditors will see.
Your position against both scenarios — honest, scored, with the three loudest gaps on top
Which process carries which scenario risk, and what one lost day costs — per process
One supplier, one system, one person, one site — found, priced, with the fix decision recorded
How your revenue is actually made, what costs create it, and where a disruption cuts into EBITDA
The tabletop day, documented: what broke when CRM/ERP went dark and the site closed — with timings
The continuity plan and technology recovery plan — short, executable, written for your worst day
Who does what, in which hour, with which authority — from disruption back to normal operations
The dashboard-ready metrics and the plan that raises them — free fixes done, paid ones proven by risk economics
By default: a ransomware attack and a drone incident with fire. Depending on your industry we swap in what threatens you most — loss of a key supplier, departure of key executives, failure of a cornerstone contract.
How much the company earns and from where; financing sources; concentration of clients, suppliers and contractors; technology and raw-material dependence; single points of failure and bottlenecks.
How revenue is formed, which costs create it, how it becomes EBITDA and net profit. Continuity planning that skips this step protects the wrong things.
We find who is actually key, how they generate revenue, and by which principles they work today.
A desk-based stress-test: CRM or ERP goes dark, the warehouse or production block is closed by fire. Nothing is switched off in reality — but the company lives the day in the room, and we watch what it is capable of, in detail.
We build the recovery scheme with your team — not for them. People execute plans they helped write.
We implement survival metrics, then raise them: new plans, new contract clauses, offline backups, fallback registers and channels. Everything fixable for free we fix together immediately; what needs investment we prove through risk economics — and leave you with a working plan.
Your client registry lives in the CRM — which is exactly what the ransomware encrypts. So during the program we export it to a simple offline file, stored away from the office, and agree a fallback channel: a Telegram contact for every key client, collected in advance, with message templates ready. Cost: zero. Effect on day X: sales keep talking to clients while IT recovers. The program is full of fixes like this.
Everything fixable without capital spend is fixed together during the program — plans, registers, fallback channels, contract wording, drills. Measures that need investment come with a risk-economics case proving they pay back; the decision stays yours.
No. The stress-test is desk-based: we simulate the loss of CRM/ERP or the closure of a site in a structured exercise. Production is never touched — but the decisions, gaps and timings the day produces are real.
Yes — the two default scenarios are starting points. For a trading house it may be the failure of a cornerstone contract; for a family business, the departure of key executives; for a manufacturer, a key supplier. We agree the two scenarios that genuinely threaten you at the start.
Leadership: the scenario session, the stress-test day and two reviews. Key people: one interview each, about an hour. The heavy lifting — analysis, modelling, documents — is ours.
You keep the artefacts, the raised metrics and the 90-day plan. Many clients continue with the continuity dashboard — the same metrics, live, on one board-level screen — and an annual exercise. Both are optional.