Protection Research

Business Continuity & Disaster Recovery Policy

Effective Date: 3 August 2026

Contents

  • Purpose
  • Scope
  • Objectives
  • Governance and Responsibilities
  • Risk Assessment
  • Business Continuity Planning
  • Backup Strategy
  • Disaster Recovery
  • Testing and Review
  • Communication During Incidents
  • Policy Review
  • Contact

1. Purpose

This Business Continuity & Disaster Recovery Policy ("Policy") describes the principles and processes adopted by Protection Research Ltd ("Protection Research", "we", "our" or "us") to maintain the resilience of our business operations and support the recovery of critical systems following disruptive events. The objectives of this Policy are to: minimise operational disruption; support the availability of our Services; protect customer information; enable timely recovery of critical business functions; reduce the impact of unforeseen incidents; and support the long-term resilience of our organisation.

This Policy complements our:

Information Security Policy;

Security & Privacy Overview;

Data Processing Agreement;

Privacy Policy; and

Terms of Service.

2. Scope

This Policy applies to the systems, infrastructure, information assets and operational processes that support the delivery of Protection Research's Services. It covers events that may affect business operations, including but not limited to: infrastructure failures; cloud service disruptions; cyber security incidents; hardware failures; software failures; loss of critical data; network outages; utility interruptions; natural disasters; supplier failures; and other events that could materially affect business operations. The Policy applies to all individuals responsible for operating or supporting Protection Research's Services.

3. Objectives

Protection Research seeks to:

  • maintain continuity of critical business operations
  • restore affected systems as efficiently as reasonably practicable
  • minimise disruption to customers
  • protect the confidentiality, integrity and availability of information
  • maintain appropriate backup arrangements
  • establish clear recovery procedures
  • support effective communication during major incidents; and

continually improve operational resilience through review and testing. Business continuity planning is based on a risk-based approach that balances operational resilience with the size and complexity of our organisation.

4. Governance and Responsibilities

Protection Research is responsible for maintaining appropriate business continuity and disaster recovery arrangements.

Responsibilities include:

  • maintaining this Policy
  • identifying critical business functions
  • assessing operational risks
  • maintaining recovery procedures
  • coordinating responses to major incidents
  • reviewing lessons learned following significant disruptions; and

periodically reviewing the effectiveness of continuity arrangements.

Individuals supporting Protection Research's operations are expected to:

  • understand their responsibilities during operational incidents
  • report issues promptly
  • follow documented recovery procedures where applicable; and

support recovery activities when requested.

5. Risk Assessment

Business continuity planning is informed by ongoing assessment of operational risks.

Risk assessments may consider:

  • critical business processes
  • dependencies on third-party suppliers
  • cloud infrastructure
  • information assets
  • cyber security threats
  • operational resilience
  • likelihood of disruption; and

potential business impact. Risk assessments are reviewed periodically and whenever significant operational changes occur.

6. Business Continuity Planning

Protection Research maintains business continuity arrangements designed to support the continued delivery of critical Services during significant operational disruptions. Our business continuity planning seeks to: identify critical business functions; establish priorities for service restoration; reduce the impact of operational incidents; maintain appropriate communication procedures; support the protection of customer information; and enable an organised and effective response to disruptive events. Business continuity procedures are reviewed periodically and updated where necessary to reflect changes in our business operations, infrastructure or risk profile.

7. Backup Strategy

Protection Research maintains backup arrangements appropriate to the Services we provide. Our backup strategy may include: regular backups of critical systems and business data; secure storage of backup data; encryption of backups where appropriate; geographically resilient storage where practicable; restricted access to backup repositories; and periodic verification that backups can be successfully restored. Backup frequency, retention periods and recovery procedures are determined according to operational requirements and the nature of the information being protected.

8. Disaster Recovery

Protection Research maintains disaster recovery procedures intended to support the restoration of critical systems following significant operational incidents.

Disaster recovery activities may include:

  • assessment of the incident and its operational impact
  • activation of appropriate recovery procedures
  • restoration of infrastructure and applications
  • validation of restored systems
  • verification of data integrity
  • controlled return to normal operations; and

review of the incident following recovery. Recovery priorities are determined according to business impact, customer needs and operational risk. While Protection Research seeks to restore Services as efficiently as reasonably practicable, recovery times may vary depending on the nature and complexity of the incident.

9. Testing and Review

Protection Research recognises that effective business continuity planning requires periodic review and validation. Where appropriate, we may: review recovery procedures; verify backup restoration processes; assess operational readiness; evaluate lessons learned from operational incidents; update recovery documentation; and improve continuity arrangements based on evolving business requirements. Testing activities are proportionate to the size and operational complexity of the organisation.

10. Communication During Incidents

Where a significant operational incident affects the availability, confidentiality or integrity of our Services, Protection Research seeks to communicate with affected customers in an appropriate and timely manner. Communications may include, where appropriate: confirmation that an incident has occurred; the nature of the disruption where suitable to disclose; expected service impacts; available mitigation measures; progress updates during recovery; and confirmation when normal operations have been restored. Certain information may be withheld where disclosure could compromise security, ongoing investigations or legal obligations.

11. Policy Review

Protection Research reviews this Policy periodically to ensure that it remains appropriate for: our operational environment; technological developments; evolving cyber security risks; legal and regulatory requirements; and recognised industry good practice. This Policy may be updated from time to time to reflect changes in our business operations or resilience strategy. The latest version will be made available through our website or otherwise provided upon request.

12. Contact

Questions regarding this Business Continuity & Disaster Recovery Policy should be directed to:

Protection Research Ltd

Company Number: 17366537

  • Registered Office: 41 Colwyn Road, Stockport, Cheshire, England, SK7 2JG
  • Email: support@protectionresearch.com

End of Business Continuity & Disaster Recovery Policy

Effective Date: 3 August 2026

© Protection Research Ltd. All rights reserved.