Business Continuity and Disaster Recovery Policy
VOIMAR-POL-004 · Version 1.0 · Effective 9 October 2026 · Approved by VOIMAR (Pty) Ltd
Purpose
VOIMAR keeps its services running through disruption, and recovers them quickly when they fail. This policy sets the standard for continuity planning, backup, recovery and communication.
Scope
All VOIMAR services, platforms, networks, offices and data centres, and the continuity design of client platforms that VOIMAR builds and operates.
Priorities
VOIMAR's customer platforms, voice services and customer internet access come first. Every plan and every change is judged by its effect on them.
Design for resilience
- A business impact analysis ranks each service and sets its recovery time (RTO) and recovery point (RPO) objectives.
- Critical services are designed without single points of failure, and across more than one site where their tier requires it.
- VOIMAR is completing its own three-site platform in Johannesburg (primary), Cape Town (secondary) and Durban (tertiary), with progress tracked on its network map.
Backups
- Servers and virtual machines are backed up every night, and network device configurations every day.
- The 3-2-1 rule applies: at least three copies of important data, on two kinds of media, with one copy offsite or offline.
- Backups are monitored and protected from tampering.
- Every quarter, a server and a device configuration are restored as a test, and the time taken is recorded.
Incident response
Incidents are managed by severity:
- P1, a customer platform, voice or customer access is down, or an attack is under way: response starts immediately, and VOIMAR management and the NOC are notified.
- P2, service is degraded, or one site or customer group is affected: response within 1 hour.
- P3, an internal tool is affected with no customer impact: next working day.
In an emergency, engineers act to restore service first through a documented emergency procedure, record what they do as they go, and obtain approval afterwards within 24 hours.
Communication
Each major incident has a named incident lead. Customers are kept informed through agreed channels until service is restored. Every P1 and P2 incident gets a blameless root-cause review within 5 working days, and its corrective actions are tracked to closure.
Client platforms
Platforms that VOIMAR builds for clients are designed to the client's own continuity requirements. Examples include geo-redundant replication between the client's data centres with tested takeover, and offline backups kept under the client's security rules.
Testing and improvement
Continuity and recovery plans are tested at least once a year. Lessons from tests and real incidents are built back into the plans.
Review
This policy is reviewed every year, and after any major incident.
