-
Introduction
- Net Onboard Sdn Bhd is committed to ensuring uninterrupted service availability, data protection, and operational resilience in the event of disasters, cyberattacks, or unforeseen incidents.
-
This Disaster Recovery & Business Continuity Plan (DR & BCP) establishes:
- Preparedness strategies for mitigating service disruptions.
- Procedures for rapid recovery of systems and critical operations.
- Compliance with industry standards for disaster recovery and business continuity.
-
This policy applies to:
- All cloud services, IT infrastructure, databases, and operational processes managed by Net Onboard.
- All employees, customers, vendors, and third-party service providers interacting with Net Onboard’s systems.
-
This policy aligns with:
- ISO 22301 – Business Continuity Management System (BCMS)
- ISO 27001 – Information Security Management
- National Institute of Standards and Technology (NIST) Disaster Recovery Standards
- Bank Negara Malaysia (BNM) Risk Management Standards (for financial service clients)
-
Business Continuity Objectives & Risk Management
-
Objectives of the Business Continuity Plan (BCP):
- Minimize downtime and ensure rapid recovery of IT systems, cloud services, and business operations.
- Safeguard customer data and maintain service availability during crises.
- Comply with regulatory requirements and industry best practices for business continuity.
-
Risk Assessment & Disaster Scenarios Covered:
- Net Onboard has identified and prepared for the following high-impact risks:
- Cybersecurity threats (ransomware, DDoS attacks, hacking incidents).
- Natural disasters (floods, earthquakes, power outages).
- Hardware/software failures (server crashes, database corruption, data loss).
- Human errors or operational failures affecting cloud services.
- Net Onboard has identified and prepared for the following high-impact risks:
-
Objectives of the Business Continuity Plan (BCP):
-
Disaster Recovery (DR) Framework & Implementation
-
Disaster Recovery Plan (DRP) Overview:
- A redundant infrastructure strategy is in place to ensure continuous operations across multiple data centers.
- Automated failover mechanisms allow real-time switching to backup systems in case of failure.
- Disaster recovery is tested quarterly to validate system resilience and recovery speed.
-
Data Backup & Replication Strategy:
- Daily automated backups with geo-redundant storage in two separate data centers.
- Data retention period of 90 days for business-critical systems.
- AES-256 encryption for all stored and transmitted data to prevent data breaches.
-
RTO (Recovery Time Objective) & RPO (Recovery Point Objective) Standards:
- Mission-Critical Systems (Cloud & Hosting Services)
- Recovery Time Objective (RTO): 1 hour
- Recovery Point Objective (RPO): 15 minutes
- Business Operations & Financial Systems
- Recovery Time Objective (RTO): 4 hours
- Recovery Point Objective (RPO): 1 hour
- Non-Critical Internal Systems
- Recovery Time Objective (RTO): 24 hours
- Recovery Point Objective (RPO): 12 hours
- Mission-Critical Systems (Cloud & Hosting Services)
-
Disaster Recovery Plan (DRP) Overview:
-
Business Continuity Plan (BCP) Implementation
-
BCP Activation & Incident Management Process:
- The BCP is triggered in the event of service outages, security incidents, or operational disruptions.
- A dedicated Incident Response Team (IRT) is responsible for coordinating recovery and communication efforts.
- Stakeholders, customers, and regulators will be notified within 2 hours of a critical incident.
-
Alternative Work Arrangements & Remote Operations:
- Employees are equipped with secure remote access and cloud-based collaboration tools.
- Business functions can transition to remote operations within 24 hours in case of facility disruption.
-
Communication Plan & Stakeholder Updates:
- Customers will be updated via:
- Email notifications on service status.
- Public cloud service dashboards for live system updates.
- Dedicated customer support hotlines for high-priority cases.
- Customers will be updated via:
-
BCP Activation & Incident Management Process:
-
Vendor & Third-Party Continuity Compliance
-
Vendor Risk Management & Contingency Planning:
- All third-party vendors must comply with Net Onboard’s DR & BCP policies.
- Cloud and infrastructure vendors must maintain a 99.9% SLA uptime guarantee.
-
Regular Vendor DR Audits:
- Annual disaster recovery tests are conducted to validate vendor compliance and risk management.
- Vendors failing to meet reliability standards may face contract termination.
-
Vendor Risk Management & Contingency Planning:
-
Continuous Improvement & Testing
-
Quarterly Business Continuity Drills:
- Tabletop exercises and simulation drills are conducted to test BCP effectiveness.
- Employees and technical teams participate in emergency response training.
-
Post-Incident Review & Policy Updates:
- After any major disruption, a root cause analysis (RCA) is conducted to improve response strategies.
- The BCP is reviewed and updated annually to align with evolving risks and industry standards.
-
Quarterly Business Continuity Drills:
-
Enforcement & Non-Compliance Consequences
-
Failure to comply with DR & BCP policies may result in:
- Service suspension or termination for vendors failing DR tests.
- Legal or financial penalties if non-compliance leads to business losses.
-
Failure to comply with DR & BCP policies may result in:
-
Governing Law & Dispute Resolution
-
This policy is governed by Malaysian law, including:
- The Communications and Multimedia Act 1998
- Bank Negara Malaysia (BNM) Risk Management Framework
- Personal Data Protection Act (PDPA) 2010
- Disputes related to disaster recovery obligations will be resolved through mediation before arbitration or litigation.
-
This policy is governed by Malaysian law, including:
-
Amendments & Updates
- Net Onboard reserves the right to update this Disaster Recovery & Business Continuity Plan (DR & BCP) at any time.
- Customers, partners, and vendors will be notified of material changes via email or system notifications.
For business continuity inquiries, contact [email protected].