Business Continuity And Disaster Recovery
Introduction
Section titled “Introduction”This Business Continuity and Disaster Recovery Plan outlines the procedures and processes to be followed in the event of a disaster or significant business disruption. The plan aims to ensure the continuity of critical business functions and the timely recovery of operations.
This plan covers all critical business functions and systems of our organization, with a focus on maintaining service to our customers and protecting our data and assets.
Objectives
Section titled “Objectives”- Ensure the safety and well-being of all employees
- Minimize disruption to critical business operations
- Protect and recover critical data and systems
- Maintain communication with employees, customers, and stakeholders
- Comply with SOC 2 and any other relevant regulatory requirements
Critical Business Functions and Systems
Section titled “Critical Business Functions and Systems”- Production application hosted on Fly
- Customer data stored in databases on Fly
- Building knowledgebase data stored in databases on Fly
- Code repository on GitHub
- Internal communication systems (Chat Platform)
- Customer communication channels (Email)
Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
Section titled “Recovery Time Objective (RTO) and Recovery Point Objective (RPO)”- RTO: 24 hours
- RPO: Full availability of the application and all customer data
Emergency Response Team
Section titled “Emergency Response Team”Primary and backups are identified for each of these roles:
- Incident Commander: François Huet, Bomee Jung
- Technical Lead: Chuck Lin, François Huet,
- Internal Communications Lead: François Huet, Jason Block
- Business Continuity Manager: Bomee Jung, Jason Block
- Security Lead: Reuben Firmin, François Huet
Disaster Recovery Procedures
Section titled “Disaster Recovery Procedures”Incident Declaration
Section titled “Incident Declaration”- Any employee who becomes aware of a potential disaster or significant disruption should immediately notify their supervisor or a member of the Emergency Response Team.
- The Incident Commander will assess the situation and declare a disaster if necessary.
- The Emergency Response Team will be activated and convened (virtually).
Communication
Section titled “Communication”- The Communications Lead will initiate the emergency communication plan.
- Employees will be notified via chat if during business hours, or by Phone/SMS if outside of business hours and urgent communication is necessary.
- Customers will be notified via email by the Business Continuity Manager if there is any impact on services.
- Regular updates will be provided to all stakeholders throughout the recovery process.
System Recovery
Section titled “System Recovery”- The Technical Lead will assess the extent of the disruption to systems.
- If necessary, the production application will be redeployed from GitHub to Fly.
- Database snapshots will be restored from Fly backups.
- All systems will be tested to ensure proper functionality before being brought back online.
Testing and Maintenance
Section titled “Testing and Maintenance”- This plan will be tested annually through a simulated disaster recovery exercise.
- The plan will be reviewed and updated quarterly or after any significant changes to the business or IT infrastructure.
- All members of the Emergency Response Team will receive annual training on their roles and responsibilities.
Plan Activation and Deactivation
Section titled “Plan Activation and Deactivation”- This plan can be activated by the Incident Commander or CEO.
- The plan will be deactivated when all critical systems are restored and normal business operations resume.
- Post-incident review will be conducted within one week of plan deactivation to identify lessons learned and areas for improvement.
Appendices
Section titled “Appendices”Appendix A: Emergency Contact List
Section titled “Appendix A: Emergency Contact List”| First Name | Last Name | Phone Number |
|---|---|---|
| Jason | Block | (609) 519-5377 |
| Francois | Huet | (831) 239-8570 |
| Bomee | Jung | (917) 446-2049 |
| Maksym | Khrystunov | +380 63 640 7452 |
| Charles | Lin | (646) 201-8770 |
| Ilayda | Cavusoglu | +905 52 502 1221 |
| Jeffry | Luna | +63 917 294 0204 |
| Jon | Braman | |
| Lubna | Asha | |
| Mike | Sweeney | |
| Robin | Neri | (203) 273-9152 |
| Erika | Parkins | (917) 213-9048 |
| Naina | Shah | (646) 961-8743 |
| Marc | Zuluaga | (917) 575-6337 |
| Sara | Vasilovski | |
| Stefan | Bumbea | +40 74 990 6487 |
Appendix B: Vendor Contact Information
Section titled “Appendix B: Vendor Contact Information”Appendix C: Recovery Checklist
Section titled “Appendix C: Recovery Checklist”- Declare the incident
- Activate the Emergency Response Team
- Initiate emergency communications
- Assess damage to systems and data
- Begin system recovery procedures
- Restore data from backups
- Test recovered systems
- Notify stakeholders of recovery status
- Resume normal operations
- Conduct post-incident review
Appendix D: Information-Sharing Subscriptions (A.5.6)
Section titled “Appendix D: Information-Sharing Subscriptions (A.5.6)”The CISO maintains active subscriptions to the following sources to stay current with the threat landscape and emerging vulnerabilities. The subscription list is reviewed at the annual policy review or sooner if the threat landscape warrants.
| Source | Channel | Purpose |
|---|---|---|
| CISA — Emergency Communications | Email subscription | Time-critical national cyber emergency notifications |
| CISA — Incident Response | Email subscription | Incident-response guidance and post-incident lessons |
| CISA — Cybersecurity Advisories | Email subscription | Adversary TTPs, sector-specific advisories, joint advisories with allied authorities |
| CISA — Vulnerability Bulletins | Email subscription | Weekly bulletin of newly disclosed vulnerabilities, including KEV updates |
Relevant advisories are triaged by the CISO and, where action is required, tracked as either an incident (per Incident Response Plan) or a vulnerability remediation task (per Vulnerability Management Policy).
Appendix E: Cyber Incident Notification Register (A.5.5)
Section titled “Appendix E: Cyber Incident Notification Register (A.5.5)”Cadence OneFive’s notification obligations in the event of a confirmed or suspected security incident affecting customer or regulated data. Recipients must be notified in parallel where the trigger applies — earlier rows do not satisfy later rows.
Customer-contract notification (binding under signed contracts)
Section titled “Customer-contract notification (binding under signed contracts)”| Customer | Recipient | Channel | Required by |
|---|---|---|---|
| NYC Accelerator | NYC Cyber Command Citywide Security Operations Center (“Cyber Command Citywide SOC”) | Phone: (718) 403-6761 | Within 24 hours of discovery |
| NYC Accelerator | NYC Cyber Command Citywide SOC | Email: SOC@cyber.nyc.gov and SOC@oti.nyc.gov — written summary including nature/scope, impacted City Data and City Technology Assets, corrective actions taken or planned | Within 48 hours of discovery |
| NYSERDA | NYSERDA Information Security Officer | Email: information.security@nyserda.ny.gov — phone: (518) 862-1090 x3486 | Immediately upon discovery or notification of any security breach or vulnerability |
Source documents (linked in the contracting file): NYC_Accelerator_25_Fully_Executed_Contract.pdf §III.9.1–III.9.2 and NYSERDA_249047_Cadence_OneFive-signed.pdf.
Statutory notification — applies whenever NY-resident private information is exposed
Section titled “Statutory notification — applies whenever NY-resident private information is exposed”Per the NYS Information Security Breach Notification Act (ISBNA, NY General Business Law §899-aa):
| Recipient | Channel |
|---|---|
| Affected individuals | Direct notice (mail, email, or substitute notice where permitted) — without unreasonable delay |
| NYS Attorney General | https://ag.ny.gov/internet/data-breach |
| NYS Department of State, Division of Consumer Protection | https://dos.ny.gov/consumer-protection |
| NYS Police | intel@nysic.ny.gov / 1-866-SAFE-NYS |
| Major consumer reporting agencies (Equifax, Experian, TransUnion) | Required only if > 5,000 NY residents are affected |
NYS lead agency (engaged via the customer, not by C15 directly)
Section titled “NYS lead agency (engaged via the customer, not by C15 directly)”For incidents affecting NYSERDA-hosted data, NYSERDA’s Information Security Officer is C15’s point of contact; NYSERDA escalates upstream per NYS-S13-005. The NYS lead agency for incidents affecting a public-benefit corporation like NYSERDA is DHSES Cyber Incident Response Team (CIRT); C15 will support NYSERDA’s coordination with DHSES CIRT and the NYS Intelligence Center Cyber Analysis Unit (NYSIC CAU) as requested.
Voluntary federal information sharing
Section titled “Voluntary federal information sharing”| Recipient | When | Channel |
|---|---|---|
| CISA | Significant cyber incidents | report@cisa.gov / https://www.cisa.gov/report / 1-888-282-0870 |
| FBI IC3 | Suspected criminal activity | https://www.ic3.gov |
Review and maintenance
Section titled “Review and maintenance”This register is reviewed at the annual policy review. Contractual entries are updated within 30 days of any new customer contract execution or amendment that changes notification terms. The CISO is responsible for maintaining the register.
Policy Review
Section titled “Policy Review”- This policy will be reviewed annually and updated as necessary to reflect changes in technology, business needs, or regulatory requirements.
- Last reviewed/updated: 2026-08-25
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
