Skip to content

Business Continuity And Disaster Recovery

This Business Continuity and Disaster Recovery Plan outlines the procedures and processes to be followed in the event of a disaster or significant business disruption. The plan aims to ensure the continuity of critical business functions and the timely recovery of operations.

This plan covers all critical business functions and systems of our organization, with a focus on maintaining service to our customers and protecting our data and assets.

  1. Ensure the safety and well-being of all employees
  2. Minimize disruption to critical business operations
  3. Protect and recover critical data and systems
  4. Maintain communication with employees, customers, and stakeholders
  5. Comply with SOC 2 and any other relevant regulatory requirements
  1. Production application hosted on Fly
  2. Customer data stored in databases on Fly
  3. Building knowledgebase data stored in databases on Fly
  4. Code repository on GitHub
  5. Internal communication systems (Chat Platform)
  6. Customer communication channels (Email)

Recovery Time Objective (RTO) and Recovery Point Objective (RPO)

Section titled “Recovery Time Objective (RTO) and Recovery Point Objective (RPO)”
  1. RTO: 24 hours
  2. RPO: Full availability of the application and all customer data

Primary and backups are identified for each of these roles:

  1. Incident Commander: François Huet, Bomee Jung
  2. Technical Lead: Chuck Lin, François Huet,
  3. Internal Communications Lead: François Huet, Jason Block
  4. Business Continuity Manager: Bomee Jung, Jason Block
  5. Security Lead: Reuben Firmin, François Huet
  1. Any employee who becomes aware of a potential disaster or significant disruption should immediately notify their supervisor or a member of the Emergency Response Team.
  2. The Incident Commander will assess the situation and declare a disaster if necessary.
  3. The Emergency Response Team will be activated and convened (virtually).
  1. The Communications Lead will initiate the emergency communication plan.
  2. Employees will be notified via chat if during business hours, or by Phone/SMS if outside of business hours and urgent communication is necessary.
  3. Customers will be notified via email by the Business Continuity Manager if there is any impact on services.
  4. Regular updates will be provided to all stakeholders throughout the recovery process.
  1. The Technical Lead will assess the extent of the disruption to systems.
  2. If necessary, the production application will be redeployed from GitHub to Fly.
  3. Database snapshots will be restored from Fly backups.
  4. All systems will be tested to ensure proper functionality before being brought back online.
  1. This plan will be tested annually through a simulated disaster recovery exercise.
  2. The plan will be reviewed and updated quarterly or after any significant changes to the business or IT infrastructure.
  3. All members of the Emergency Response Team will receive annual training on their roles and responsibilities.
  1. This plan can be activated by the Incident Commander or CEO.
  2. The plan will be deactivated when all critical systems are restored and normal business operations resume.
  3. Post-incident review will be conducted within one week of plan deactivation to identify lessons learned and areas for improvement.
First Name Last Name Phone Number
Jason Block (609) 519-5377
Francois Huet (831) 239-8570
Bomee Jung (917) 446-2049
Maksym Khrystunov +380 63 640 7452
Charles Lin (646) 201-8770
Ilayda Cavusoglu +905 52 502 1221
Jeffry Luna +63 917 294 0204
Jon Braman
Lubna Asha
Mike Sweeney
Robin Neri (203) 273-9152
Erika Parkins (917) 213-9048
Naina Shah (646) 961-8743
Marc Zuluaga (917) 575-6337
Sara Vasilovski
Stefan Bumbea +40 74 990 6487
  1. Declare the incident
  2. Activate the Emergency Response Team
  3. Initiate emergency communications
  4. Assess damage to systems and data
  5. Begin system recovery procedures
  6. Restore data from backups
  7. Test recovered systems
  8. Notify stakeholders of recovery status
  9. Resume normal operations
  10. Conduct post-incident review

Appendix D: Information-Sharing Subscriptions (A.5.6)

Section titled “Appendix D: Information-Sharing Subscriptions (A.5.6)”

The CISO maintains active subscriptions to the following sources to stay current with the threat landscape and emerging vulnerabilities. The subscription list is reviewed at the annual policy review or sooner if the threat landscape warrants.

Source Channel Purpose
CISA — Emergency Communications Email subscription Time-critical national cyber emergency notifications
CISA — Incident Response Email subscription Incident-response guidance and post-incident lessons
CISA — Cybersecurity Advisories Email subscription Adversary TTPs, sector-specific advisories, joint advisories with allied authorities
CISA — Vulnerability Bulletins Email subscription Weekly bulletin of newly disclosed vulnerabilities, including KEV updates

Relevant advisories are triaged by the CISO and, where action is required, tracked as either an incident (per Incident Response Plan) or a vulnerability remediation task (per Vulnerability Management Policy).

Appendix E: Cyber Incident Notification Register (A.5.5)

Section titled “Appendix E: Cyber Incident Notification Register (A.5.5)”

Cadence OneFive’s notification obligations in the event of a confirmed or suspected security incident affecting customer or regulated data. Recipients must be notified in parallel where the trigger applies — earlier rows do not satisfy later rows.

Customer-contract notification (binding under signed contracts)

Section titled “Customer-contract notification (binding under signed contracts)”
Customer Recipient Channel Required by
NYC Accelerator NYC Cyber Command Citywide Security Operations Center (“Cyber Command Citywide SOC”) Phone: (718) 403-6761 Within 24 hours of discovery
NYC Accelerator NYC Cyber Command Citywide SOC Email: SOC@cyber.nyc.gov and SOC@oti.nyc.gov — written summary including nature/scope, impacted City Data and City Technology Assets, corrective actions taken or planned Within 48 hours of discovery
NYSERDA NYSERDA Information Security Officer Email: information.security@nyserda.ny.gov — phone: (518) 862-1090 x3486 Immediately upon discovery or notification of any security breach or vulnerability

Source documents (linked in the contracting file): NYC_Accelerator_25_Fully_Executed_Contract.pdf §III.9.1–III.9.2 and NYSERDA_249047_Cadence_OneFive-signed.pdf.

Statutory notification — applies whenever NY-resident private information is exposed

Section titled “Statutory notification — applies whenever NY-resident private information is exposed”

Per the NYS Information Security Breach Notification Act (ISBNA, NY General Business Law §899-aa):

Recipient Channel
Affected individuals Direct notice (mail, email, or substitute notice where permitted) — without unreasonable delay
NYS Attorney General https://ag.ny.gov/internet/data-breach
NYS Department of State, Division of Consumer Protection https://dos.ny.gov/consumer-protection
NYS Police intel@nysic.ny.gov / 1-866-SAFE-NYS
Major consumer reporting agencies (Equifax, Experian, TransUnion) Required only if > 5,000 NY residents are affected

NYS lead agency (engaged via the customer, not by C15 directly)

Section titled “NYS lead agency (engaged via the customer, not by C15 directly)”

For incidents affecting NYSERDA-hosted data, NYSERDA’s Information Security Officer is C15’s point of contact; NYSERDA escalates upstream per NYS-S13-005. The NYS lead agency for incidents affecting a public-benefit corporation like NYSERDA is DHSES Cyber Incident Response Team (CIRT); C15 will support NYSERDA’s coordination with DHSES CIRT and the NYS Intelligence Center Cyber Analysis Unit (NYSIC CAU) as requested.

Recipient When Channel
CISA Significant cyber incidents report@cisa.gov / https://www.cisa.gov/report / 1-888-282-0870
FBI IC3 Suspected criminal activity https://www.ic3.gov

This register is reviewed at the annual policy review. Contractual entries are updated within 30 days of any new customer contract execution or amendment that changes notification terms. The CISO is responsible for maintaining the register.

  • This policy will be reviewed annually and updated as necessary to reflect changes in technology, business needs, or regulatory requirements.
  • Last reviewed/updated: 2026-08-25

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.