If something knocked your business offline tomorrow, would your team know exactly what to do? Most leaders assume yes. Then a real disruption hits, and it turns out half the plan was living in someone's head.
September is National Preparedness Month, which makes it a good excuse to find out. Here at Tridium, we sit in on a lot of these conversations with leadership teams, and the pattern is always the same: you don't need a retreat or a consultant in the room. You need 15 minutes, the right people, and five direct questions.
Everyone knows the tools the business runs on. Fewer teams can say, without hesitating, what has to come back online first if everything stopped at once.
Usually it's whatever protects customers, revenue, and the ability to keep working — customer support, payment processing, scheduling, order fulfillment, or the files people need to do their jobs. The specific answer varies by business. The goal doesn't: know what can't sit idle.
Get that priority list straight ahead of time, and your team spends a disruption fixing things instead of arguing about what to fix first.
Pressure has a way of exposing who's really in charge. When ownership isn't clear, people wait for permission, duplicate effort, or pull three different leaders into the same conversation.
Someone should own starting the response. Someone should own updating employees. Someone should own talking to customers, and someone should own working the vendors and IT partners. It's not about building an org chart — it's about making sure nobody's guessing when it matters.
Email and phones feel like permanent fixtures right up until they aren't. Then even basic coordination gets hard.
If employees lost access to email, would they know where to look for instructions? If the phones went down, how would customers reach you? If your team chat disappeared, where would leadership post updates?
The backup plan doesn't need to be elaborate. It just needs to exist, and everyone needs to know it exists.
The riskiest dependencies are usually the quiet ones — the software platform, the internet connection, the vendor, or the one employee who's the only person who really understands a process.
None of that feels risky on a normal Tuesday. It becomes very risky the moment it's unavailable and half the business depends on it. Naming these dependencies is what tells you where documentation, backups, or outside support actually need to go.
This is the question that cuts through assumptions, because it puts you inside the moment you're trying to avoid.
Maybe it's a process that was never written down. Backups that were never tested. A contact list that's two years stale. None of these feel urgent in a normal week — that's exactly why they keep getting pushed to next week.
Preparation is what turns "react" into "respond."
Once you've worked through these five questions, you'll know pretty quickly which answers are solid and which ones you're hoping are true.
That's usually where a vulnerability scan earns its keep — it's one of the first things the Tridium team looks at when we start working with a new business. It doesn't guess at your weak points — it finds them: the outdated system, the unpatched device, the access nobody remembered to revoke. And a short discovery call does the same thing for your operational plan that a scan does for your network — it surfaces the gaps you can't see from the inside, before something forces you to find them the hard way.
Neither one is about alarming you. They're about trading assumptions for answers, on your schedule instead of an attacker's.