Skip to main content
VOIMAR Group policy

Business Continuity and Disaster Recovery Policy

VOIMAR-POL-004 · Version 1.0 · Effective 9 October 2026 · Approved by VOIMAR (Pty) Ltd

Purpose

VOIMAR keeps its services running through disruption, and recovers them quickly when they fail. This policy sets the standard for continuity planning, backup, recovery and communication.

Scope

All VOIMAR services, platforms, networks, offices and data centres, and the continuity design of client platforms that VOIMAR builds and operates.

Priorities

VOIMAR's customer platforms, voice services and customer internet access come first. Every plan and every change is judged by its effect on them.

Design for resilience

  • A business impact analysis ranks each service and sets its recovery time (RTO) and recovery point (RPO) objectives.
  • Critical services are designed without single points of failure, and across more than one site where their tier requires it.
  • VOIMAR is completing its own three-site platform in Johannesburg (primary), Cape Town (secondary) and Durban (tertiary), with progress tracked on its network map.

Backups

  • Servers and virtual machines are backed up every night, and network device configurations every day.
  • The 3-2-1 rule applies: at least three copies of important data, on two kinds of media, with one copy offsite or offline.
  • Backups are monitored and protected from tampering.
  • Every quarter, a server and a device configuration are restored as a test, and the time taken is recorded.

Incident response

Incidents are managed by severity:

  • P1, a customer platform, voice or customer access is down, or an attack is under way: response starts immediately, and VOIMAR management and the NOC are notified.
  • P2, service is degraded, or one site or customer group is affected: response within 1 hour.
  • P3, an internal tool is affected with no customer impact: next working day.

In an emergency, engineers act to restore service first through a documented emergency procedure, record what they do as they go, and obtain approval afterwards within 24 hours.

Communication

Each major incident has a named incident lead. Customers are kept informed through agreed channels until service is restored. Every P1 and P2 incident gets a blameless root-cause review within 5 working days, and its corrective actions are tracked to closure.

Client platforms

Platforms that VOIMAR builds for clients are designed to the client's own continuity requirements. Examples include geo-redundant replication between the client's data centres with tested takeover, and offline backups kept under the client's security rules.

Testing and improvement

Continuity and recovery plans are tested at least once a year. Lessons from tests and real incidents are built back into the plans.

Review

This policy is reviewed every year, and after any major incident.

All company policies