Logo featuring the text 'Data Protection Matters' with a shield and circuit design.

Four tiers isn’t enough

502 BC/DR leaders told DPM that their orgs average 3.4 tiers of IT workloads to recover in a crisis — here are the two things most of them forgot to count.

video transcript

Before I tell you why this stat is wrong, let me share what 502 BC/DR leaders said during DPM’s last Organizational Resilience survey.

The average organization has 3.4 tiers of workloads to recover during a large-scale event — a natural disaster, a fire, a flood, a tornado, or a cyber event. Many folks oversimplify in terms of “high-priority” and “normal” (the rest of IT) workloads. But folks who’ve lived it say 3.4, so let’s round up and talk about what four layers of workloads could look like — then I’ll tell you why 3.4 gets you in trouble.

  • TIER ONE is your mission-critical, business-critical workloads. When these are offline, your business processes suffer.
  • TIER TWO is the majority of your “normal” IT; it needs to run, but it might be offline a day or two depending on the scale of the crisis.
  • TIER THREE you’ll want up eventually … it’s a priority to somebody, just not to the business overall.

A lot of folks forget TIER ZERO: the plumbing. DNS, so your servers can find each other. Identity, so you, your apps, and your AI agents can actually log on. This is still not the part folks are underestimating, but it is the management frameworks your whole IT foundation sits on. Now maybe you’re thinking “oh yeah, that counts too” — but did you build recovery time into your strategy for that layer to get reconstituted? Because a lot of KPIs presume you’re starting at tier one.

Here’s the dangerous part — because all four of these assume the infrastructure is ready to restore to. Tier one, tier three, tier zero — they all gotta go someplace: clean metal for physical workloads, virtualization hosts for your VMs, and cloud infrastructure (storage, networking, and all the dependencies) all have to be live before your recovery clock can even begin.

Call it “tier negative one” if you want. It’s the layer most folks assume exists when they set their resilience KPIs and SLAs. So, when 502 BC/DR folks tell me they’ve got 3.4 in their plan, my response is “That’s good, but if they forgot to plan for the foundation, then their plan is wrong and they aren’t as resilient as they think.”

Leave your thoughts on the LinkedIn article.

Next ›

Discover more from Data Protection Matters

Subscribe now to keep reading and get access to the full archive.

Continue reading