Why does a business need an IT continuity plan for cyclone season specifically?
General emergency plans cover people and premises — evacuation routes, first aid, structural safety. They rarely cover what happens to the phone system, the accounting software, or the file server when the power is out for days and nobody can get to the office. Cyclone season is the one part of the year northern Australian businesses can see coming. The systems side of readiness deserves the same seasonal attention as boarding up windows and briefing staff, because an inaccessible office with no plan for its data and communications can keep a business shut long after the weather clears.
Is Microsoft 365 backed up automatically, so this doesn't matter if we use it?
Microsoft 365 protects the platform and gives you retention windows for deleted items, but that's different to the continuity problem this tool scores. Even with data safely in the cloud, a business can still struggle during cyclone season if the office phone number can't be reached, staff have no way to work from wherever they end up, or nobody is clear on who makes decisions while the usual manager is unreachable. Cloud-hosted data is a strong foundation for the data and systems recovery domain, but it doesn't answer the premises, communications, people and planning questions this check covers.
We're a small business — do we really need a written plan, or is a shared understanding enough?
A shared understanding works until the people who share it are unreachable, exhausted, or dealing with their own household during a disruption. A short written plan doesn't need to be long — a page naming the systems that matter, who's responsible for them, and the basic recovery steps is enough for most small operations. What matters is that it exists somewhere accessible other than one person's memory, so someone else can act on it if the usual person can't.
How is this different to a general business continuity or disaster recovery plan?
A general continuity plan usually covers people, premises, and how the business keeps trading. This check narrows in on the IT and systems layer specifically — power to equipment, connectivity for staff and customers, where data actually lives, whether staff can work remotely, and who is authorised to make decisions about systems during a disruption. It's meant to sit inside a broader continuity plan, or to be the starting point for one, for businesses that haven't yet turned their attention to the technology side.
What's the realistic first step if we score poorly?
Start with whichever domain scored lowest, not all five at once. For most businesses that's either getting a genuine off-site copy of data in place, or writing down who's responsible for a decision when the usual person can't be reached. Both are achievable in a week without buying anything. The domains build on each other — a documented plan is much easier to write once you already know where the data lives and how staff would reach each other, so tackling the practical gaps first often makes the planning easier, not harder.
Does this apply to a business with only one site, or is it just for multi-site operators?
It applies either way. A single-site business actually has less redundancy by default — if that one office is inaccessible, there's no other location to fall back on, which makes off-site data, remote-capable staff and a clear decision-maker more important, not less. Multi-site operators have an advantage in that another location can sometimes absorb the load, but only if systems and access are set up in advance to allow that, which is exactly what several of the domains in this check test for.
How often should this be reviewed?
Once a year, before the season builds, is the practical minimum — treat it the same way you'd treat checking the generator or renewing insurance. Businesses that have been through a real disruption often find gaps the plan didn't anticipate, so the review after a season is at least as valuable as the one before it. A plan that was accurate two years ago and hasn't been touched since is close to as risky as having no plan, because staff, systems and contact details all drift over time.
We use a managed IT provider — shouldn't they have this covered already?
A managed IT provider is usually responsible for the technical layer — backups running, servers patched, security maintained — but continuity planning also needs business input only the business can provide: which systems actually matter most if only one could be prioritised, who's authorised to make a call during a disruption, and how customers should be told what's happening. The strongest results come from the business and its IT provider working through this together, rather than assuming either side has it fully covered alone.
Is this only relevant to businesses in cyclone-prone areas?
The scenario is written for northern Australian and comparable flood- and cyclone-exposed regions, because that's a known, seasonal and specific risk — power out for days, an inaccessible office, and staff scattered. The same underlying gaps, such as data trapped on one server, no fallback communication path, or no named decision-maker, cause outages from other causes too, in any region. Businesses outside cyclone-exposed areas can still use it as a general IT continuity check; the seasonal framing is simply what makes the timing concrete for the businesses it's written for.
What does Frontrow's pre-season continuity review include?
A structured session with your team working through each of the five domains against what's actually in place today, not what's assumed. The outcome is a short written continuity plan naming the systems that matter, the recovery steps, and who is responsible for each one, along with a practical list of the gaps worth closing before the season builds.