Cookies & Privacy

We use cookies to keep the site working, understand how it is used and improve your experience. You can accept all or choose which ones to enable.Cookie Policy.

Back to About

Policy

Business Continuity and Disaster Recovery Policy

FORFIRM maintains Business Continuity and Disaster Recovery principles to protect Core Operations, Client Deliverables and Service Resilience during disruption scenarios.

Purpose

The purpose of this Business Continuity and Disaster Recovery Policy is to establish a high-level operational framework that ensures the Company can prevent, prepare for, respond to, and recover from significant operational disruptions. This policy aims to minimize financial loss, protect critical client deliverables, guarantee human safety, and maintain core business operations during crisis events, in absolute alignment with ISO/IEC 27001:2022 and ISO 22301 standards.

Applicability

This policy applies to all business units, physical facilities, technical platforms, networks, cloud infrastructures, and core processes operated or managed by the Company. It is binding for all employees, executive leaders, and third-party vendors who support or maintain critical components of the corporate ecosystem.

Business Continuity Commitment

The Company recognizes that operational resilience is a fundamental parameter of market trust and governance. The Company commits to identifying critical business functions, maintaining redundant capabilities, and allocating appropriate resource budgets to safeguard organizational viability, intellectual assets, and client services against prolonged technical, environmental, or logistical disruptions.

Compliance Obligations

The Company guarantees that its continuity architectures, alternative processing facilities, and backup strategies comply with all applicable legal, regulatory, and contractual obligations. This includes strict adherence to the Swiss Federal Act on Data Protection (nLPD) and explicit Service Level Agreements (SLAs) executed with corporate clients.

Continual Improvement

The Company is committed to the continuous improvement of its Business Continuity Management System (BCMS) and Disaster Recovery (DR) readiness. Recognizing that operational environments and threat landscapes evolve rapidly, continuity plans, technical recovery playbooks, and disaster simulation methodologies are systematically reviewed, tested, and updated.

Business Continuity Principles and Performance Management

The Company structures its continuity and disaster recovery strategies around specific technical and operational methodologies: • Business Impact Analysis (BIA) & Risk Assessment: The Company conducts regular BIAs to identify critical business processes, determine their interdependencies, and formally establish metrics for maximum acceptable downtime: • Recovery Time Objective (RTO): The target time allowed for a system or process to be restored after a disruption • Recovery Point Objective (RPO): The maximum acceptable age of data that can be lost due to an incident • Redundancy and Cloud Architecture: Core client-facing delivery spaces, code repositories, and operational systems must be deployed using highly available, multi-zone cloud architectures to eliminate Single Points of Failure (SPOFs) • Disaster Recovery (DR) Activation: A formalized DR activation workflow is maintained to trigger secondary infrastructure processing environments immediately if the main production platforms suffer catastrophic, non-remediable failures • Crisis Testing and Simulation: Technical and logical recovery plans must not rely solely on theoretical assumptions. The Crisis Management Team must coordinate simulated disaster testing and infrastructure switch-over exercises at least annually to verify RTO/RPO limits under pressure

Roles and Responsibilities

• Executive Management (Managing Partners) holds ultimate accountability for crisis response governance, authorizes disaster declaration budgets, and directs corporate recovery priorities • The Crisis Management Team (CMT) is a dedicated cross-functional group responsible for coordinating physical and technical operations during an active emergency • IT Operations & Infrastructure Teams are responsible for executing technical DR playbooks, verifying automated system replication metrics, and conducting structural continuity testing • All Personnel are responsible for understanding their specific roles during a disruption and maintaining individual readiness

Awareness, Training and Culture

The Company fosters a culture of operational readiness. Technical teams undergo continuous training on crisis response procedures and system recovery methods. General employees receive routine guidance on alternative remote working arrangements, emergency escalation paths, and physical evacuation rules to optimize alignment during unexpected situations.

Communication and Stakeholder Engagement

During an active disruption, all official communications are tightly managed. No staff member may issue public comments or unapproved disclosures regarding an ongoing crisis. The Company maintains dedicated, secure communication channels to update affected clients and regulatory bodies transparently, fulfilling contractual SLA obligations.

Monitoring, Review and Continuous Alignment

The Company monitors its resilience status through ongoing system availability metrics, infrastructure health check logging, and testing results. This policy is formally evaluated at least annually by Executive Management and the Security Team or immediately after a real disaster scenario to ensure ongoing alignment with corporate operational targets.