Working in a fast-paced environment like the University of Iowa means staff are often multi-tasking. During a busy day, a rushed click on an email suddenly could lead to a critical application going offline due to a cybersecurity risk.
How should a unit prepare for what happens when technology goes offline?
Backups and redundant systems matter, but a business continuity and disaster recovery plan goes further. It defines who makes decisions, how teams communicate, which services are most important, how manual workflows operate, and how long the organization can continue to function with limited capabilities.
Building a plan
Disaster recovery testing and tabletop exercises are key to creating and maintaining a business continuity and disaster recovery plan. Testing uncovers weak spots before a real outage surfaces them. A tabletop exercise is a discussion-based practice session where people work through a realistic scenario to understand how they respond, communicate, and make decisions. during an actual incident.
Good discussion questions include:
- What patient, student, research, or business functions must continue?
- Who has the authority to declare downtime procedures?
- Who do we need to notify, and how will those notifications be made?
- How do we communicate if email, phones, or a vendor platform is unavailable?
- Which third-party systems do we depend on, and what happens if they are the source of the disruption?
- Do we know where critical data lives, how it is backed up, and how quickly it can be restored?
Resilience is not just about technology. It is about coordination, clarity, and preparedness across the entire university. When systems fail, people and processes must be ready to carry the mission forward.
When it comes to reducing cybersecurity risks, everyone has a role. Here are some steps you can take to help:
- Pause before clicking a link in an unexpected or suspicious email.
- Know where your department’s critical data is stored and make sure it is a secure location before storing it.
- Make sure continuity plans are tested, funded, and connected to real operations. If something seems wrong—a suspicious email, unexpected system behavior, lost device, exposed data, vendor concern, or possible IT incident—report it promptly to the Information Security and Policy Office, the ITS Help Desk, or the HCIS Help Desk.
Cybersecurity is not an abstract concern. It’s an issue for delivery of patient care, research continuity, payroll, communications, and public trust. Early reporting and preparing a plan help the university investigate, contain, and recover to keep our mission moving forward.