The Link Source Logo
    The Link Source
    Free Business Continuity Resource

    The Ultimate IT Hurricane Readiness Package

    Protect your people, systems, and data before the storm. Hurricanes can disrupt power, internet service, communications, facilities, vendors, and access to critical business systems. A well-tested IT continuity plan can reduce downtime, protect company data, and help your team resume essential operations safely.

    Your IT Readiness Priorities

    A resilient hurricane plan should address six core priorities.

    People

    Keep employees safe and ensure they know how, when, and where to work.

    Data

    Maintain recoverable, protected copies of critical business information.

    Systems

    Identify the applications and infrastructure that must be restored first.

    Connectivity

    Prepare alternatives for internet, voice, and remote access.

    Security

    Maintain cybersecurity controls during remote work and recovery.

    Communication

    Establish reliable ways to reach employees, customers, vendors, and your IT provider.

    Hurricane IT Readiness Checklist

    Use these six sections to prepare before a storm, operate during disruption, and recover in a controlled manner.

    1

    Assign Roles and Define Decision Authority

    • Name an Incident Lead who can activate the continuity plan.
    • Identify a primary and alternate IT decision-maker.
    • Assign owners for employee communications, vendor coordination, facilities, cybersecurity, and insurance documentation.
    • Document who can authorize emergency purchases, equipment relocation, system shutdowns, and disaster recovery actions.
    • Maintain an offline copy of the emergency contact list.
    • Confirm that The Link Source has current contacts and escalation instructions.

    Minimum contact list

    Include names, mobile numbers, personal email addresses when appropriate, role, backup contact, and escalation order for: executive leadership, IT support and MSP, internet and telecom providers, cloud and software vendors, building management and security, electrician/generator/restoration vendors, cyber and property insurance contacts, payroll/banking/key suppliers.

    2

    Identify Critical Business Systems

    • List each critical system, what it supports, who owns it, where it is hosted, how long the business can operate without it, and the order in which it should be restored.

    Suggested recovery tiers

    Tier 1 (restore first): Identity and authentication, email and emergency communications, internet/firewall/secure remote access, core line-of-business application, file access and collaboration, customer service or dispatch systems, payroll/timekeeping when deadlines are near. Tier 2 (restore after essential operations stabilize): accounting and reporting, departmental applications, printing/scanning, secondary databases. Tier 3 (restore when normal operations resume): archives, test systems, nonessential devices, convenience applications.

    Define recovery objectives

    For every critical platform, document: Recovery Time Objective (maximum acceptable time to restore the service), Recovery Point Objective (maximum acceptable data loss measured in time), system owner and recovery owner, dependencies such as identity, internet, DNS, vendors, databases, or licensing, and a manual workaround if the system is unavailable.

    3

    Verify Backups and Recovery

    • Confirm all critical servers, cloud data, databases, applications, and configurations are included in backup scope.
    • Use multiple protected copies, including one that is offsite and isolated or otherwise resistant to unauthorized deletion.
    • Encrypt backup data in transit and at rest.
    • Protect backup administration with multifactor authentication and separate privileged credentials.
    • Confirm backup retention supports operational, legal, and insurance requirements.
    • Verify that cloud services such as Microsoft 365 and industry applications have appropriate retention, backup, and recovery coverage.
    • Test restoration of representative files, a critical application, and at least one full system.
    • Record the date, duration, result, and owner of each recovery test.
    • Keep recovery instructions and essential credentials accessible if the primary network is unavailable.

    Ask these questions before the storm

    What was the date of our last successful restore test? Can we recover if the office, server room, or primary administrator is unavailable? How quickly can each critical system be restored? Who can authorize recovery actions? Are backup alerts monitored during nights, weekends, and storm closures?

    4

    Prepare for Power Loss and Physical Damage

    • Test uninterruptible power supplies and replace weak batteries.
    • Confirm safe shutdown procedures for servers, storage, network equipment, and specialized devices.
    • Document how long UPS and generator power can support essential systems.
    • Test generators and confirm fuel, maintenance, ventilation, and safe operating procedures.
    • Move equipment, spare devices, and paper records above expected water exposure.
    • Keep technology away from windows, exterior walls, roof leaks, and floor-level cabling where practical.
    • Photograph equipment, serial numbers, wiring, and the server room for insurance and reconstruction.
    • Update the asset inventory and identify equipment that may need priority replacement.
    • Use surge protection appropriate for critical infrastructure.
    • Do not ask employees to remain onsite solely to protect technology.

    Safety first: Follow instructions from local authorities and qualified facilities professionals. Never enter a flooded or structurally damaged building, touch wet electrical equipment, or operate a generator indoors.

    5

    Establish Connectivity and Communication Alternatives

    • Document internet carrier account numbers, circuit IDs, support contacts, and escalation paths.
    • Evaluate a secondary connection that uses a different carrier or delivery path.
    • Prepare business-grade cellular hotspots where coverage and capacity support them.
    • Keep charging cables, approved portable power banks, and vehicle chargers available.
    • Configure cloud-based voice, call forwarding, auto attendants, and emergency messages in advance.
    • Maintain an alternate employee communication channel outside the corporate network.
    • Create customer-facing service interruption and recovery message templates.
    • Download or print contact lists and essential procedures for offline use.
    • Test the communications tree at least annually and before peak hurricane activity.

    Suggested communication cadence

    Preparedness notice (explain remote-work expectations and deadlines), activation notice (confirm closure, evacuation, or continuity-plan activation), status update (provide a fixed update time even when there is no material change), recovery notice (state which services are available and what remains limited), return notice (explain when, where, and how employees may resume normal operations).

    6

    Secure Remote Work

    • Verify that every remote worker can sign in before the storm.
    • Require multifactor authentication for email, VPN, cloud applications, and administrative access.
    • Apply current security updates to laptops and mobile devices.
    • Confirm endpoint protection, encryption, device management, and remote support are functioning.
    • Provide company-managed devices to employees performing sensitive work.
    • Limit administrator privileges and use separate administrative accounts.
    • Review conditional access and remote-access capacity.
    • Instruct staff not to bypass controls or share credentials during outages.
    • Warn employees about storm-related donation scams, fake vendor requests, fraudulent payment changes, and password-reset phishing.
    • Provide one trusted method for reporting suspicious messages or lost devices.

    Remote-work rules employees should know

    Avoid public or shared computers. Use approved applications and storage locations. Do not send sensitive information through personal email or consumer messaging apps. Verify urgent payment, banking, payroll, and vendor-change requests through a known secondary channel. Report lost or damaged devices immediately. Protect screens and conversations when working in shared evacuation locations.

    Readiness Timeline

    What to do and when to do it — from before hurricane season through post-storm recovery.

    Before Hurricane Season

    • Complete the business impact assessment.
    • Review cyber and property insurance requirements.
    • Validate backup scope and perform a recovery exercise.
    • Test remote work, call routing, emergency notifications, UPS units, and generators.
    • Review vendor support agreements and emergency replacement procedures.
    • Update network diagrams, asset inventories, licenses, warranties, and contact lists.
    • Run a tabletop exercise with leadership, operations, communications, and IT.
    • Resolve gaps and assign deadlines.

    When a Storm Enters the Gulf or Threatens Your Area

    • Begin daily monitoring of official forecasts and local emergency guidance.
    • Convene the incident team and establish the next decision time.
    • Confirm employee locations, remote-work readiness, and evacuation expectations.
    • Verify the latest backup results and resolve failures.
    • Freeze nonessential infrastructure changes.
    • Confirm carrier, cloud, MSP, insurance, and building contacts.
    • Charge devices and approved backup power supplies.
    • Stage spare laptops, hotspots, cables, and critical documentation.
    • Confirm the timing and ownership of customer and employee communications.

    72–48 Hours Before Impact

    • Perform an additional backup and validate completion.
    • Test access to critical cloud applications from outside the office.
    • Forward phones and publish approved service messages if needed.
    • Secure or relocate vulnerable equipment without putting employees at risk.
    • Confirm safe shutdown timing for onsite infrastructure.
    • Record current system health, configuration, and open incidents.
    • Ensure executives and recovery personnel have offline access to the plan.

    24 Hours Before Impact

    • Prioritize people and follow evacuation or closure instructions.
    • Complete planned equipment shutdowns before conditions become unsafe.
    • Send a final pre-impact employee and customer update.
    • Confirm the next scheduled check-in.
    • Stop all nonessential technical work.
    • Document systems intentionally taken offline.

    Recovery Runbook

    Use this sequence to reduce confusion after a disruption.

    1

    Assess

    • Confirm employee safety and authorized recovery personnel.
    • Determine facility accessibility and utility status.
    • Identify affected systems, locations, vendors, and business processes.
    • Start an incident log with times, decisions, owners, and evidence.
    2

    Contain

    • Keep water-damaged or unsafe equipment powered off.
    • Isolate compromised devices or accounts.
    • Preserve logs and evidence associated with damage or suspicious activity.
    • Restrict recovery access to authorized personnel.
    3

    Restore Foundations

    • Power and environmental controls.
    • Internet and firewall services.
    • DNS and network connectivity.
    • Identity and multifactor authentication.
    • Endpoint security and monitoring.
    4

    Recover Applications & Data

    • Follow the approved recovery tiers.
    • Restore from known-good recovery points.
    • Check data integrity, permissions, integrations, and dependencies.
    • Document deviations and temporary configurations.
    5

    Validate

    • Technical owner verifies stability and security.
    • Business owner confirms usable data and workflow.
    • Incident lead approves release to users.
    6

    Communicate & Improve

    • Inform employees and customers about restored services and limitations.
    • Track remaining issues through closure.
    • Capture costs, damaged assets, screenshots, vendor records, and recovery actions.
    • Hold an after-action review within two weeks.

    Emergency IT Information Worksheet

    Complete this worksheet and keep protected digital and offline copies. Store sensitive details securely — do not place passwords, recovery keys, or full privileged credentials in an unprotected printed plan.

    Organization

    • Company name
    • Primary location(s)
    • Incident lead
    • Alternate incident lead
    • Plan activation authority
    • Emergency operations location or virtual meeting point

    IT and Vendors

    • The Link Source primary contact
    • The Link Source emergency contact
    • Internet provider and circuit ID
    • Secondary internet provider
    • Voice provider
    • Cloud provider(s)
    • Critical application vendor(s)
    • Cyber insurance carrier and policy number
    • Property insurance carrier and policy number

    Recovery Targets

    • Tier 1 systems
    • Required recovery time
    • Acceptable data loss
    • Last successful backup
    • Last successful restore test
    • Backup location(s)
    • Authorized recovery decision-maker

    Communications

    • Employee notification method
    • Alternate employee method
    • Customer status channel
    • Vendor escalation method
    • Next scheduled plan test

    Leadership Questions

    Executives should be able to answer these questions without relying on one employee or one device.

    1

    What are the five systems our business needs first?

    2

    How long can we operate without each one?

    3

    Has recovery been tested, not merely backed up?

    4

    Can employees work securely if the office is closed for a week?

    5

    What happens if power, internet, and cellular service fail at the same time?

    6

    Who can activate the plan and authorize emergency spending?

    7

    How will we communicate if corporate email is unavailable?

    8

    Which vendors have contractual recovery commitments?

    9

    Are cyber and property insurance requirements reflected in the plan?

    10

    When did leadership last participate in an exercise?

    A Practical 60-Minute Test

    Tabletop Exercise

    Scenario

    A hurricane causes a multi-day power outage. The office is inaccessible, the primary internet carrier is down, cellular service is congested, and one employee reports a suspicious password-reset message.

    Discussion Prompts

    1.Who activates the plan?
    2.How are employees notified?
    3.Which services must be available in the first four hours?
    4.Can the team access the applications securely from alternate locations?
    5.How are customer calls and messages handled?
    6.What manual workarounds are available?
    7.Who communicates with carriers, insurers, and vendors?
    8.How is the suspicious message investigated during the disruption?
    9.What evidence and expenses must be documented?
    10.What conditions must be met before the office reopens?

    Success Criteria

    Clear decisions and named owners
    Known recovery priorities
    Working alternate communications
    Verified access to critical systems
    No dependence on one individual
    Documented gaps with owners and due dates

    How The Link Source Can Help

    We can help turn this checklist into a tested, business-specific continuity program.

    IT Hurricane Readiness Review

    • Business impact and technology risk review
    • Backup and recovery validation
    • Microsoft 365 and cloud resilience review
    • Remote-work and multifactor authentication assessment
    • Internet, voice, firewall, and power-dependency review
    • Asset inventory and documentation review
    • Recovery priority workshop
    • Tabletop exercise facilitation
    • Remediation roadmap with owners and priorities

    Managed Readiness & Recovery Support

    • Proactive system monitoring
    • Backup oversight and recovery testing
    • Security monitoring and incident escalation
    • Vendor and carrier coordination
    • Emergency remote support
    • Recovery planning and documentation
    • Post-event review and improvement planning

    Trusted Preparedness Resources

    This resource provides general business and technology preparedness information. It does not replace instructions from emergency management officials, electrical or structural professionals, insurers, legal counsel, or other qualified advisors.

    Take the Next Step

    Do not wait until a storm is days away to discover that a backup cannot be restored or that employees cannot connect remotely. Contact The Link Source to schedule an IT Hurricane Readiness Review.