Trust & Resilience
Business Continuity Statement
Raeburn Consulting maintains business-continuity and disaster-recovery arrangements intended to protect critical services, support controlled recovery and maintain appropriate customer communications during material disruption. Recovery procedures are periodically tested.
Last reviewed: 27 August 2026
Backups and recoverability
Critical information and service components are protected using backup, versioning or recoverability capabilities appropriate to the service and its underlying providers. Backup and recovery requirements are considered alongside data sensitivity, service criticality and applicable retention obligations. Technical backup restore testing has been completed to validate that recovery is operational rather than relying solely on documented procedures.
Recovery objectives
Recovery priorities and objectives are set according to service criticality, customer impact and technical dependencies. Internal recovery objectives guide restoration and prioritisation; customer-specific commitments are governed by the applicable contract or service terms rather than this public statement.
Provider resilience
Raeburn Consulting uses established cloud and technology providers and considers provider resilience, recoverability and dependency risk as part of service design. Where supported by the architecture and proportionate to the service, redundancy, managed-provider recovery capabilities, controlled redeployment or alternative service paths reduce reliance on a single component.
Incident escalation
Material availability, security and operational incidents are assessed and escalated according to impact. Response activities include incident ownership, containment where required, recovery coordination, security validation, stakeholder assessment and post-incident review.
Exercises and testing
Business-continuity and disaster-recovery procedures are exercised periodically. This includes technical backup restore testing as well as continuity and incident-response exercises. Testing is used to validate recoverability, escalation, decision-making, recovery sequencing, provider-failure response, security checks, communications and follow-up actions. Findings are incorporated into the relevant recovery procedures.
Supplier contingency
Material suppliers and technology dependencies are considered through supply-chain risk management. Contingency planning can include alternative operating procedures, controlled service degradation, redeployment, manual processes, provider-supported recovery or migration to another approved capability where feasible and appropriate.
Customer communications
Where a material incident affects customer services, communications are coordinated according to the nature, severity and duration of the event and applicable contractual, legal or regulatory obligations. Updates are intended to provide useful information without exposing sensitive security or recovery details.
Continuous improvement
Lessons from incidents, restore tests, exercises, supplier changes and material service changes feed into continuity and recovery planning. Detailed internal recovery procedures, credentials, infrastructure diagrams and other security-sensitive operational information are not published in this customer-facing statement.