
For two decades, the answer to "where do we go?" in a New York continuity plan was a building across the Hudson, a contract for a set number of seats, and a bus schedule. A hybrid firm has to answer the same question with a spreadsheet of home addresses that nobody on the continuity team has ever visited, connected by internet service the firm does not buy and powered by a grid it does not control.
That is not an argument against hybrid work. It has made many firms more resilient to the classic scenario, losing an office building, because most staff can simply keep working from home. It has also moved the single points of failure somewhere else, and plenty of plans still describe a world where everyone commutes to one place and evacuates to another.
Six assumptions that no longer hold
Most continuity plans written before 2020 rest on assumptions that were reasonable at the time. Here is what has changed:
- "The office is the primary site." For many roles the primary site is now a kitchen table, and the office is an occasional venue. The office has become a recovery option for the home.
- "A disruption hits a building." Disruptions now hit the regions where employees live: power grids, broadband networks, flood zones, wildfire smoke.
- "IT recovery means the data center." Remote staff depend on identity, multi-factor authentication, remote access and endpoint management before they touch a single business application.
- "We know who is on site." Badge data used to tell you who was in the building. It now tells you very little about where people are.
- "Equipment lives at desks." The laptop is now the desk, the workstation and the recovery site, and it travels.
- "The recovery site contract covers us." Many firms cut or dropped work-area recovery contracts after 2020. Some of the roles those seats protected still cannot work from home.
Each of these needs a specific answer.
The home is a recovery site you do not run
A home office depends on things the firm does not control: a single consumer broadband line, a router of uncertain age, household power, and whoever else is streaming in the next room. None of that matters on an ordinary Tuesday. It matters a great deal when a storm takes out the neighborhood or a fiber cut drops a provider across a county.
Plans should set a minimum home setup by role rather than one standard for everyone. For roles in the top recovery tiers, reasonable expectations include:
- A second path to the internet. A phone hotspot with a company-funded data plan is the cheapest option; a second wired provider is better for roles that cannot tolerate dropped calls.
- A small UPS on the router and modem. It will not carry a multi-hour outage, but it stops brief power flickers from dropping a client call or a trading session.
- A known fallback location. The nearest company office, a pre-arranged flexible workspace, or a colleague's home in another area.
Be honest about the limits. In a wide-area power outage, cell sites run on backup batteries and generators that do not last indefinitely, so the hotspot plan can degrade at the same time as the home connection. Planning for a regional event means planning for staff to move, not just to switch networks.
Regional events now land on people, not buildings
The defining continuity events of the past fifteen years were regional. Superstorm Sandy in 2012 left large parts of New York, New Jersey and Long Island without power for days. Winter Storm Uri in 2021 cut power to millions of Texans during a hard freeze, and many lost water as well. Hurricane Ida later that year knocked out power across the New Orleans area, and its remnants then flooded basement apartments in New York City. In California, utilities have used planned public safety power shutoffs during high wildfire risk.
In an office-based model, those events were mainly about whether the building and the commute worked. In a hybrid model they hit staff where they work, and they hit everyone in the same area at once. A payments team whose members all live in the same few suburbs is, for continuity purposes, a single site.
The practical step is to do the geography. Map home locations (a postal code is usually enough) for every role in the top recovery tiers against utility territories, flood zones and the metro area as a whole. Where a critical function is concentrated in one region, the options are the same ones that applied to buildings: split the team across regions, cross-train people elsewhere, or arrange a place for them to go.
People affected by a regional event also have their own emergencies. Expecting someone to keep working while their basement floods is a welfare question as much as a staffing one, and it belongs in the firm's duty of care approach to business continuity.
Identity and remote access are the new building
When most staff are remote, the firm's real front door is its identity provider, its multi-factor authentication service, its VPN or zero-trust access layer, and its endpoint management. If any of those fail, nobody gets in, however healthy the data center is.
The early weeks of COVID-19 exposed remote access sized for a fraction of the workforce. Firms fixed the capacity, but other failure modes remain: an identity provider outage, an MFA push service that stops delivering, an expired certificate on the remote-access gateway, a conditional-access policy change that locks out a whole group. The CrowdStrike Falcon outage of 19 July 2024 added another lesson. Affected Windows machines needed hands-on remediation, and for laptops sitting in employees' homes that often meant IT staff talking people through recovery steps by phone, encryption recovery keys included, one device at a time.
Treat this layer the way you used to treat the building:
- Put it in the BIA as a dependency of every remote-capable process, with its own recovery target.
- Maintain break-glass accounts that do not depend on the primary identity provider or MFA service, keep their credentials offline, and test them on a schedule.
- Provide a second authentication method for staff whose phones are lost, dead or out of signal.
- Test remote access at full concurrency, not at a typical day's load.
- Plan for endpoint recovery outside the office: how you will repair or replace laptops you cannot physically reach.
- Keep an out-of-band way to talk to staff. If the collaboration platform depends on the same identity service that just failed, you need a notification tool that reaches personal phones.
Work-area recovery contracts, reconsidered
Shared-seat recovery contracts were built for a world where losing the office meant losing the ability to work. Many firms reasonably cut them back once most staff could work from home. The mistake is assuming no one needs a controlled seat anymore.
Some work still does: trading and other roles with recorded lines and supervision requirements, check and cash processing, mailrooms and print operations, contact centers handling card data, and anyone whose home the event itself has made unusable. For these, the choices include a smaller dedicated contract, using the firm's own offices as mutual recovery sites (a hybrid office often has spare desks most days), flexible workspace agreements, or mobile recovery units.
Test shared arrangements against regional events. A flexible workspace provider is a fine fallback for a fire in your building and a poor one for a hurricane, when every other firm in the area wants the same desks.
Knowing where people are
Accountability used to start with the badge system and the floor warden's list. In a hybrid firm, the first question after a regional event is who lives in the affected area and whether they are safe, and answering it requires data most continuity teams do not hold.
At minimum, notification lists need current personal mobile numbers and an approximate home location, kept current through HR rather than a spreadsheet the continuity team updates once a year. Agree with HR and privacy counsel what data you hold, why, and how geographic targeting will be used. Build a check-in process with a clear escalation path: who follows up with people who do not respond, and when. Account for travel and "work from anywhere" weeks, which put staff outside their usual area at exactly the wrong moment.
Equipment: the laptop is the desk
If a laptop fails, is stolen or ends up underwater, the employee has no workstation until it is replaced. Keep a pool of spare devices that can be provisioned remotely, and decide how they reach people during an event. Couriers suspend service in disaster zones, so staging spares at regional offices for pickup is often faster. Keep hardware authentication tokens as a backup to phone-based MFA, track who holds which assets, and remember the specialist kit (check scanners, headsets, secure printers) that some roles need.
Policy is part of the plan
The remote work policy and the continuity plan should reference each other. The policy should state the minimum home setup for each tier, what the firm will pay for (backup connectivity, a UPS), what employees must do when their home becomes unusable and how quickly they should tell their manager, how sensitive data is handled at home, and what support the firm offers during a declared event. It should also say plainly that personal safety comes before work.
The continuity plan, in turn, needs its alternate-site section rewritten. If your plan follows a traditional structure like our annotated sample plan table of contents, "alternate site" should become alternate workplace strategies by role: home, fallback location, company office, contracted seat. Much of what firms know about dispersed work came out of pandemic response, and our briefing on pandemic and infectious-disease continuity planning covers the people-side measures that carry over.
For the technical side of remote access, NIST's guide to enterprise telework and remote access security (SP 800-46 Rev. 2) is old but still a sound reference for the controls your security team will want in place.
First 30 days checklist
Week 1: find out where you stand
- Pull home postal codes for all staff in top-tier recovery roles from HR.
- Map them against metro areas, utility territories and flood zones, and flag any critical team concentrated in one area.
- List the roles that cannot work from home, and the reason for each.
Week 2: test the assumptions
- Survey top-tier staff on backup connectivity and power (hotspot, second provider, UPS).
- Confirm break-glass accounts exist, work, and do not depend on the primary identity provider.
- Check remote-access capacity against full headcount, not average load.
Week 3: close the cheap gaps
- Fund hotspot plans and router UPS units for top-tier roles.
- Stage spare laptops and hardware tokens at regional offices.
- Confirm notification lists hold current personal mobile numbers and home areas.
Week 4: rehearse and write it down
- Run a 90-minute tabletop: a multi-day regional power outage that takes out the homes of half of one critical team, followed by an identity provider failure on day two.
- Update the BIA dependencies, the alternate-workplace section of the plan, and the remote work policy with what the exercise found.
- Decide which roles still need contracted or company-owned recovery seats, and size them.



