Consulting project
DRP concept
DRP – Disaster Recovery Planning – creates a structured framework that enables companies to resume operations as quickly as possible after cyberattacks, natural disasters, or power outages.
Customer profile
Location: NRW, Germany
Employees: Approximately 3,800 employees
Revenue range: 3.5+ billion euros
Industry: Process industry
Locations:
- 11 production sites
- 13 office locations
Initial situation at the customer's site
Our client, a globally operating company in the process industry with complex, interdependent IT and OT environments, needed to immediately improve its disaster recovery and business continuity measures after realizing it was increasingly threatened by cyberattacks, ransomware, and infrastructure failures.
Realistic, verifiable recovery plans and binding coordination between IT stakeholders and the responsible OT experts were required. Implementing these measures necessitated the provision of a competent and professional team of cybersecurity experts capable of collaborating with stakeholders in a complex and global environment.
To meet this challenge, the client launched a competitive procurement and tendering process. Speed, flexibility, and pragmatic implementation were very important to the client.
Tasks
1. Assessment – Stakeholder Coordination – Planning
The team began by establishing cooperative collaboration with stakeholders (IT teams and SMEs). System information and process risks were documented, and a structured risk management process was defined. Furthermore, the following were carried out:
- a risk assessment of IT services
- a threat/probability analysis
- the identification of critical systems
- the prioritization and strategy for risk reduction
The deliverables included a stakeholder map, an engagement plan, a risk report, a risk mitigation plan, and compliance assets.
2. IT Emergency Plans (ISCPs) for critical services
The eAces-DRP team developed Information System Contingency Plans (ISCPs) for critical services such as Exchange, Office 365, and identity management. These were prioritized according to their respective business impact to enable rapid recovery.
3. Testing and continuous improvement
The eAces DRP team:
- set up a realistic test environment,
- validated recovery procedures,
- conducted gap analyses
- optimized the ISCPs based on the results and stakeholder feedback.
The results included the optimized or newly created test procedures, as well as the corresponding documentation of the test results.
4. Tabletop Exercise Program (TTX) for IT
The eAces DRP team designed a complete TTX package that included the following elements:
- realistic scenarios (e.g., in the case of ransomware),
- role-based runbooks,
- Preliminary discussions and
- Real-time monitoring and documented findings.
The results included the exercise design, the scenario, the runbook, the briefing materials, the documentation of the lessons learned, and the need for corrective actions.
5. OT Emergency Planning
For the OT sector, the eAces DRP team addressed data recovery requirements in the event of data loss during extended power outages exceeding UPS capacity. Dependencies were mapped, and practical, implementable plans were developed in collaboration with OT vendors. OT-ISC scenarios were developed to mitigate hardware failures.
6. PMO and Quality Assurance
The eAces DRP team worked closely with the client, based on milestones and regular "Jour fixe" governance meetings. QA planning, review cycles, and quality controls were integrated and documented.
These results are not solely attributable to standard consulting frameworks. They are the result of the rapid adaptability of the eAces expert team:
Operational, field-tested emergency plans for critical IT and selected OT services that have proven themselves in realistic tests and do not just exist in theoretical documentation.
Significantly increased resilience against cyberattacks, ransomware, and widespread service disruptions.
Clear alignment between IT, OT, and management teams enables faster, coordinated decision-making under pressure.
A scalable disaster recovery framework designed for continuous testing, optimization, and future growth.
The roughly ten years of collaboration demonstrate that successfully staffing complex IT projects goes far beyond simply placing individual specialists. Crucial factors include a deep understanding of the technological requirements, the precise selection of experts, and long-term support for the teams.