DR maturity assessment and recovery architecture for a UK payments processor
The challenge
The client had a DR policy in place but had never conducted a structured maturity assessment. Following an internal audit, the board requested an independent review of their recovery capability ahead of a PCI DSS recertification.
Our approach
We conducted a full Inspect engagement — reviewing infrastructure dependencies, data retention practices, and the existing DR documentation against actual system configurations. We identified 14 gaps, six of which were rated critical. We then moved into an Architect engagement to redesign their recovery architecture, aligning it to ISO 27001 and their 4-hour RTO commitment.
The assessment was uncomfortable reading — which is exactly what we needed. The architecture they designed gave us a credible path to certification.
Head of IT Infrastructure