The recent Amazon Web Services (AWS) outage reminded businesses across industries of an uncomfortable truth: even the largest and most advanced providers aren’t immune to failure.
From data center malfunctions to targeted cyberattacks, outages have become part of the modern operating landscape. The real question is no longer if an incident will happen – it’s how ready your organization is when it does.
Together with Tautvydas Jašinskas, Chief Information Security Officer (CISO) at ConnectPay, let’s look at what often turns a minor outage into a major crisis – and what companies can do to stay resilient.
Business Continuity Plans: written vs. practiced
Many organizations have a Business Continuity Plan (BCP) stored in a shared drive, but few regularly test it.
Why this matters:
- Plans created once and never updated quickly become outdated.
- Staff turnover means that new employees may not be familiar with their role in a crisis.
- Technology and vendor changes often leave recovery steps incomplete.
“The difference between a plan that exists and a plan that works is testing,” explains Jašinskas. “Companies must simulate real-world scenarios – from cloud outages to data corruption – to see how fast they can restore normal operations.”
Running live exercises helps identify weak points, such as unclear responsibilities, missing contacts, or technical dependencies that haven’t been documented and addressed.
The human factor: training turns policy into action
Technology alone doesn’t guarantee resilience – people do. They’re the strongest joint in any organization. During an outage, every minute counts, and confusion spreads quickly if teams haven’t practiced their roles.
Why this remains a challenge:
- IT teams focus heavily on prevention, not recovery drills.
- Decision-making authority during incidents is often unclear.
- Employees assume “someone else” will take action.
“When systems go down, you don’t have time to read instructions,” says Jašinskas. “The instinct to react is built through training – the quiet preparation that turns uncertainty into action.”
Regular tabletop exercises or live simulations ensure that when an outage occurs, teams respond automatically, not reactively.
Third-party dependencies: the hidden weak link
Cloud service providers, payment gateways, and data processors form the backbone of digital operations, but they also create shared risk.
Why it’s critical to manage:
- Most outages originate outside an organization’s direct control.
- Vendors may not disclose downtime quickly or transparently.
- Recovery timelines differ, leaving businesses in limbo.
“Almost every company depends on a chain of providers,” Jašinskas points out. “That means your resilience is only as strong as the weakest link in that chain.”
Firms should map their dependencies, assess vendor resilience, and ensure that SLAs (service-level agreements) clearly define expectations for uptime, response times, and communication during incidents. If one provider fails, there must be a tested backup route, whether that means a secondary cloud region, payment processor, or communications channel.
Testing for reality, not for compliance
Compliance frameworks emphasize operational resilience, but checklists alone don’t prepare firms for real-world disruptions. The goal isn’t just passing an audit, it’s maintaining continuity and business trust when your systems go offline.
“Many organizations approach resilience and business continuity in a bureaucratic way – writing about it more than they actually do it. They create policies, procedures, and documents, but resilience isn’t built on paperwork. It’s built on practice,” Jašinskas notes.
True resilience comes from repetition – from realistic, sometimes uncomfortable testing that exposes weak points and teaches teams how to respond. And the irony is that no real incident ever unfolds exactly like the scenario you’ve rehearsed. But the real value of testing lies in learning how to solve problems – recognizing patterns, finding causes, and restoring order when plans no longer apply. Companies that regularly test and adjust recover faster, communicate more effectively, and experience less business disruption when it strikes.
Building a culture of resilience
Actual readiness extends beyond IT. Finance, operations, customer support, and communications all play a role in minimizing impact.
What defines a resilient organization?
- Prepared teams who know their responsibilities and have their deputies assigned and trained.
- Tested procedures that reflect the current tech environment.
- Transparent communication with partners and clients during incidents.
- Continuous improvement after every drill or real disruption.
“In practice, resilience has to become a habit,” Jašinskas emphasizes. “If you only think about continuity once a year, you’re already behind.”
Embedding resilience thinking into everyday operations, rather than treating it as a once-a-year compliance task—is what separates proactive organizations from those caught off guard.
As Archilochus said, “We don’t rise to the level of our expectations; we fall to the level of our training.” Outages and cyber incidents aren’t going away, but their impact can be mitigated. Companies that recover fastest share one thing in common: they train, test, and adapt continuously.
FAQs: Corporate Cyber Readiness
What’s the difference between having a business continuity plan and actually testing it?
A written BCP that sits untouched quickly becomes outdated as staff, technology, and vendors change. Testing through live simulations, such as practicing responses to cloud outages or data corruption, reveals weak points like unclear responsibilities or missing documentation before a real incident exposes them. The gap between a plan that exists and one that works comes down to regular practice, not paperwork.
Why do employees often struggle to respond effectively during an outage?
When systems go down, there’s no time to read instructions. IT teams tend to focus on prevention rather than recovery drills, decision-making authority during incidents is often unclear, and employees frequently assume someone else will take action. Regular tabletop exercises and live simulations build the instinct to react automatically rather than reactively.
Why are third-party vendors considered a hidden risk in business resilience?
Most outages originate outside a company’s direct control, through cloud providers, payment gateways, or data processors. Vendors may not disclose downtime quickly, and recovery timelines can vary significantly, leaving a business in limbo. A company’s resilience is only as strong as the weakest link in its vendor chain, so mapping dependencies and defining clear SLAs for uptime and communication is essential.
How can companies build resilience beyond just their IT department?
Actual readiness extends across finance, operations, customer support, and communications. A resilient organization has prepared teams with assigned deputies, tested procedures that reflect the current tech environment, transparent communication with partners and clients during incidents, and continuous improvement after every drill or real disruption.
What makes business continuity testing effective rather than just a compliance exercise?
Many organizations approach resilience bureaucratically, writing policies and procedures without practicing them. Real value comes from realistic, sometimes uncomfortable testing that exposes weak points and teaches teams how to respond. No real incident ever unfolds exactly like a rehearsed scenario, but repeated testing builds the pattern-recognition and problem-solving skills needed when plans no longer apply.
How often should a company revisit its business continuity plan?
Resilience has to become a habit rather than an annual task. Companies that only think about continuity once a year are already behind, since staff turnover, technology changes, and vendor relationships shift constantly. Embedding resilience thinking into everyday operations, rather than treating it as a once-a-year compliance exercise, is what separates proactive organizations from those caught off guard.








