This document is under active development and has not been finalized.
Skip to content

Business Continuity

LEGAL BASIS

§30(2) No. 3 BSIG – Business continuity, including backup management and disaster recovery, and crisis management

Backup Strategy

BAUER GROUP applies the 3-2-1 rule:

PrincipleImplementation
3 copiesProduction data + 2 backups
2 different mediaLocal storage + cloud/offsite
1 offsite copyGeographically separated location

Backup Intervals

Data TypeIntervalRetentionEncryption
DatabasesDaily (incremental), weekly (full)90 daysAES-256
ConfigurationsOn change (Git-based)Unlimited (versioning)Repository-level
Customer dataDailyPer contract, min. 30 daysAES-256
EmailDaily90 daysAES-256

Recovery Objectives

ServiceRTO (Recovery Time)RPO (Recovery Point)
Critical production systems< 4 hours< 1 hour
Internal systems< 24 hours< 24 hours
Archive / documentation< 72 hours< 1 week

Disaster Recovery

  • Regular restore tests – Quarterly verification of recoverability
  • Documented recovery procedures per system
  • Failover systems for business-critical services
  • Escalation plan with clear responsibilities and communication channels

Crisis Management

In the event of a crisis (e.g. ransomware, total outage):

  1. Activate crisis team (ISO, management, IT lead)
  2. Establish situational awareness and document
  3. Activate communication plan (internal, customers, authorities)
  4. Restore per documented DR plan
  5. Post-incident review with lessons learned and plan adjustment

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT