Trust & Resilience

Business Continuity Statement

Raeburn Consulting maintains business-continuity and disaster-recovery arrangements intended to protect critical services, support controlled recovery and maintain appropriate customer communications during material disruption. Recovery procedures are periodically tested.

Last reviewed: 27 August 2026

Backups and recoverability

Critical information and service components are protected using backup, versioning or recoverability capabilities appropriate to the service and its underlying providers. Backup and recovery requirements are considered alongside data sensitivity, service criticality and applicable retention obligations. Technical backup restore testing has been completed to validate that recovery is operational rather than relying solely on documented procedures.

Recovery objectives

Recovery priorities and objectives are set according to service criticality, customer impact and technical dependencies. Internal recovery objectives guide restoration and prioritisation; customer-specific commitments are governed by the applicable contract or service terms rather than this public statement.

Provider resilience

Raeburn Consulting uses established cloud and technology providers and considers provider resilience, recoverability and dependency risk as part of service design. Where supported by the architecture and proportionate to the service, redundancy, managed-provider recovery capabilities, controlled redeployment or alternative service paths reduce reliance on a single component.

Incident escalation

Material availability, security and operational incidents are assessed and escalated according to impact. Response activities include incident ownership, containment where required, recovery coordination, security validation, stakeholder assessment and post-incident review.

Exercises and testing

Business-continuity and disaster-recovery procedures are exercised periodically. This includes technical backup restore testing as well as continuity and incident-response exercises. Testing is used to validate recoverability, escalation, decision-making, recovery sequencing, provider-failure response, security checks, communications and follow-up actions. Findings are incorporated into the relevant recovery procedures.

Supplier contingency

Material suppliers and technology dependencies are considered through supply-chain risk management. Contingency planning can include alternative operating procedures, controlled service degradation, redeployment, manual processes, provider-supported recovery or migration to another approved capability where feasible and appropriate.

Customer communications

Where a material incident affects customer services, communications are coordinated according to the nature, severity and duration of the event and applicable contractual, legal or regulatory obligations. Updates are intended to provide useful information without exposing sensitive security or recovery details.

Continuous improvement

Lessons from incidents, restore tests, exercises, supplier changes and material service changes feed into continuity and recovery planning. Detailed internal recovery procedures, credentials, infrastructure diagrams and other security-sensitive operational information are not published in this customer-facing statement.