Frontrow Technology

Free tool · 10 minutes · Cyclone season readiness

CYCLONE SEASON IT —
CONTINUITY CHECK.

Northern Australian businesses plan for cyclone season — they board up, stock water, and brief staff. Few have a plan for their systems. Score whether this business can keep operating, and recover, when the power is out for days and the office is inaccessible, in about ten minutes.

20 questions · 5 domains

Cyclone Season IT Continuity Check

Score how well this business would keep operating, and recover, if cyclone season brought an extended power outage, an inaccessible office, and scattered staff. Twenty questions across five domains. Pick the option closest to how things actually work today, not how they're meant to work.

Domain 1

Premises and power

Whether on-site equipment survives an extended power outage, and whether anything the business depends on is exposed to flood risk it hasn't planned for.

  • When mains power goes and doesn't come back within the hour, what happens to your on-site equipment?

    Source: General practice for planned equipment shutdown ahead of an extended power outage.

  • Is anything the business can't operate without still sitting on-site in a flood-prone building?

    Source: General practice for the physical placement of critical IT equipment in flood-exposed premises.

  • What surge and outage protection is in place for on-site equipment?

    Source: Standard practice for uninterruptible power supply and surge protection in small business IT.

  • If the office is without power for several days, is there any alternative power arrangement for critical systems?

    Source: General business continuity practice — arranging alternative power ahead of an extended outage.

Domain 2

Connectivity and communications

How staff and customers reach each other when the office phone line and site internet are both down.

  • If the office landline and site internet both go down, how do staff and customers reach the business?

    Source: General practice for keeping a primary business number reachable during a site outage.

  • If the office internet connection is down, can staff still get online?

    Source: General practice for connectivity redundancy — a secondary path independent of the primary site connection.

  • Who is responsible for telling customers the business is operating differently, and how?

    Source: General customer-communications practice during a service disruption.

  • How do staff know what's expected of them when normal channels (email, Teams, the office phone) are down?

    Source: General practice for internal emergency contact trees that don't depend on primary office systems.

Domain 3

Data and systems recovery

Whether business data is genuinely protected outside the building, and whether recovery has actually been tested.

  • Where does your business data actually live, physically?

    Source: General backup practice — a copy of data needs to be genuinely independent of the primary site to survive a site-level event.

  • Does the business depend on a single on-site server for a core system (accounting, job management, files)?

    Source: General IT continuity practice — single points of failure on core business systems.

  • When did you last actually test restoring data from backup, rather than just checking that the backup ran?

    Source: General backup practice — a backup that has never been restored is unproven.

  • If the business lost access to its systems today, roughly how long would it take to be operating again?

    Source: General disaster recovery practice — recovery time objective.

Domain 4

People and dispersed working

Whether staff can keep working from home, from another town, or wherever they end up, and whether that's ever been rehearsed.

  • If the office is inaccessible but staff have power and connectivity elsewhere, can they keep working?

    Source: General practice for dispersed working capability as a continuity control.

  • Do staff have the devices and access details with them if they need to evacuate or relocate at short notice?

    Source: General practice for personal readiness ahead of a known seasonal hazard.

  • If staff end up scattered across different towns or evacuated, how does work get coordinated?

    Source: General practice for task continuity when a workforce is geographically dispersed.

  • Has dispersed or remote working actually been rehearsed, or is it theoretical?

    Source: General continuity practice — an untested plan is an assumption, not a control.

Domain 5

Plan, roles and rehearsal

A written continuity plan, a named decision-maker, and a habit of reviewing it before the season starts.

  • Does the business have a written IT and systems continuity plan, separate from a general emergency or evacuation plan?

    Source: General business continuity practice — a documented continuity plan distinct from a physical emergency plan.

  • Is it clear who makes the call to activate the continuity plan, and who can approve action or spend money without waiting for someone unreachable?

    Source: General practice for delegated decision-making authority during a disruption.

  • Is there a record of IT equipment, software licences and data assets that would support an insurance claim if equipment were damaged or lost?

    Source: General practice for maintaining an asset register to support insurance and recovery.

  • Is the continuity plan reviewed and updated before each cyclone season, or does it sit unopened?

    Source: General continuity practice — reviewing a plan ahead of a known seasonal risk period, broadly November to April in northern Australia.

This is an indicative self-assessment. It is not a substitute for a documented, tested business continuity plan. For a structured pre-season review, Frontrow Technology offers an IT continuity check for the businesses it supports across regional Queensland and South Australia.

What the check covers

Five domains. One continuity score.

Domain 1

Premises and power

Cyclone season brings power outages that can run for days, not hours, and premises that flood or become inaccessible. A UPS sized for a five-minute blip won't carry a business through a multi-day outage. This domain checks whether on-site equipment has a shutdown procedure, whether anything critical still sits under a desk in a flood-prone building, and whether there's a real alternative if mains power doesn't come back quickly.

Domain 2

Connectivity and communications

The office landline and the site internet connection often fail together in a cyclone-driven outage, because they typically share the same local infrastructure. This domain checks whether the main business number can still be reached, whether staff have a working fallback to get online, and whether someone is responsible for telling customers what's happening.

Domain 3

Data and systems recovery

A server in the office with backups on a drive in the same office protects against very little. This domain checks whether data lives somewhere genuinely independent of the primary site, whether restoring it has actually been tested rather than assumed to work, and whether anyone knows how long recovery would realistically take.

Domain 4

People and dispersed working

Cyclone season scatters people as much as it disrupts systems. Staff may be at home without power, evacuated to another town, or simply unable to reach the office for days. This domain checks whether they have the devices and access to work from wherever they are, and whether that's been rehearsed rather than assumed.

Domain 5

Plan, roles and rehearsal

The first four domains only hold together if someone owns them. This domain checks whether there's a written plan distinct from the physical emergency plan, whether it's clear who can make decisions and spend money without waiting for someone unreachable, and whether the plan gets reviewed each year rather than written once and forgotten.

Frequently asked questions

What Australian businesses in cyclone-exposed regions ask.

Why does a business need an IT continuity plan for cyclone season specifically?

General emergency plans cover people and premises — evacuation routes, first aid, structural safety. They rarely cover what happens to the phone system, the accounting software, or the file server when the power is out for days and nobody can get to the office. Cyclone season is the one part of the year northern Australian businesses can see coming. The systems side of readiness deserves the same seasonal attention as boarding up windows and briefing staff, because an inaccessible office with no plan for its data and communications can keep a business shut long after the weather clears.

Is Microsoft 365 backed up automatically, so this doesn't matter if we use it?

Microsoft 365 protects the platform and gives you retention windows for deleted items, but that's different to the continuity problem this tool scores. Even with data safely in the cloud, a business can still struggle during cyclone season if the office phone number can't be reached, staff have no way to work from wherever they end up, or nobody is clear on who makes decisions while the usual manager is unreachable. Cloud-hosted data is a strong foundation for the data and systems recovery domain, but it doesn't answer the premises, communications, people and planning questions this check covers.

We're a small business — do we really need a written plan, or is a shared understanding enough?

A shared understanding works until the people who share it are unreachable, exhausted, or dealing with their own household during a disruption. A short written plan doesn't need to be long — a page naming the systems that matter, who's responsible for them, and the basic recovery steps is enough for most small operations. What matters is that it exists somewhere accessible other than one person's memory, so someone else can act on it if the usual person can't.

How is this different to a general business continuity or disaster recovery plan?

A general continuity plan usually covers people, premises, and how the business keeps trading. This check narrows in on the IT and systems layer specifically — power to equipment, connectivity for staff and customers, where data actually lives, whether staff can work remotely, and who is authorised to make decisions about systems during a disruption. It's meant to sit inside a broader continuity plan, or to be the starting point for one, for businesses that haven't yet turned their attention to the technology side.

What's the realistic first step if we score poorly?

Start with whichever domain scored lowest, not all five at once. For most businesses that's either getting a genuine off-site copy of data in place, or writing down who's responsible for a decision when the usual person can't be reached. Both are achievable in a week without buying anything. The domains build on each other — a documented plan is much easier to write once you already know where the data lives and how staff would reach each other, so tackling the practical gaps first often makes the planning easier, not harder.

Does this apply to a business with only one site, or is it just for multi-site operators?

It applies either way. A single-site business actually has less redundancy by default — if that one office is inaccessible, there's no other location to fall back on, which makes off-site data, remote-capable staff and a clear decision-maker more important, not less. Multi-site operators have an advantage in that another location can sometimes absorb the load, but only if systems and access are set up in advance to allow that, which is exactly what several of the domains in this check test for.

How often should this be reviewed?

Once a year, before the season builds, is the practical minimum — treat it the same way you'd treat checking the generator or renewing insurance. Businesses that have been through a real disruption often find gaps the plan didn't anticipate, so the review after a season is at least as valuable as the one before it. A plan that was accurate two years ago and hasn't been touched since is close to as risky as having no plan, because staff, systems and contact details all drift over time.

We use a managed IT provider — shouldn't they have this covered already?

A managed IT provider is usually responsible for the technical layer — backups running, servers patched, security maintained — but continuity planning also needs business input only the business can provide: which systems actually matter most if only one could be prioritised, who's authorised to make a call during a disruption, and how customers should be told what's happening. The strongest results come from the business and its IT provider working through this together, rather than assuming either side has it fully covered alone.

Is this only relevant to businesses in cyclone-prone areas?

The scenario is written for northern Australian and comparable flood- and cyclone-exposed regions, because that's a known, seasonal and specific risk — power out for days, an inaccessible office, and staff scattered. The same underlying gaps, such as data trapped on one server, no fallback communication path, or no named decision-maker, cause outages from other causes too, in any region. Businesses outside cyclone-exposed areas can still use it as a general IT continuity check; the seasonal framing is simply what makes the timing concrete for the businesses it's written for.

What does Frontrow's pre-season continuity review include?

A structured session with your team working through each of the five domains against what's actually in place today, not what's assumed. The outcome is a short written continuity plan naming the systems that matter, the recovery steps, and who is responsible for each one, along with a practical list of the gaps worth closing before the season builds.