If you have previously unsubscribed from Huntington marketing emails, subscribing reaffirms your agreement to receive email. This will not impact servicing email related to account activity. For questions, please consult Huntington’s Privacy and Security policy.

How to build a business resiliency plan for your company
Technology disruptions can happen for many reasons: severe weather events, cyberattacks, fraud, equipment failure, or a third-party outage. A practical resiliency plan can help your organization protect its people, prioritize essential operations, and make informed decisions when normal processes are interrupted.
Key takeaways
Proactive planning could help avoid costly disruptions
Identify your organization’s top risks
Put safeguards in place before a disruption occurs
Establish ways to recognize and escalate incidents quickly
Prioritize and practice communication plans
Revisit your plans and apply lessons learned
If the technology at your organization should fail—whether as the result of a natural disaster, cyberattack, or fraudulent activity—do you have a plan to help you recover quickly and sustain business operations?
Technology disruptions can have serious operational and financial consequences.
In 2026, the average organization lost approximately $15,000 per minute of downtime, roughly $900,000 per hour, with aggregate losses across the world's largest companies reaching $600 billion annually, up 50% in just two years1. The increasing sophistication of cyberattacks, especially those enabled by AI, and the growing frequency of severe weather events, are highlighting the increasing need for business leaders to better prepare for the unknown.
Business continuity, disaster recovery, and incident response plans are designed to prepare businesses for events that could disrupt operations. These plans are key elements of your organization’s resiliency strategy.
Understanding the top cybersecurity and weather-related threats to your business
Examples of cybersecurity threats that can compromise your data and systems include ransomware attacks, business email compromise (BEC), and third-party vulnerabilities. Threat actors can manipulate employees into infecting your business’ network or even providing access to secure systems. Successful cyberattacks may interrupt critical systems, services, or business processes. A strong business continuity plan sets priorities in these situations, outlining which data to keep, which systems to focus on first, and which areas need the most protection.
Extreme weather events, defined as a trend of severe weather events in frequency and intensity, remain a significant threat to businesses. Examples include wildfires, flooding, extreme temperatures, and storms, which can cause property damage and prolonged outages or disruptions. According to the latest data from the Cybersecurity & Infrastructure Security Agency (CISA), severe storms alone have caused more than $455 billion in total damages since 19802. More than a third of those events occurred in the past five years. Protecting your employees, understanding what to do if employees cannot go into an office or plant, and knowing how to handle infrastructure damage are all part of a business continuity plan.
No organization is completely immune. Focus first on the disruptions most likely to affect your people, facilities, technology, and critical services.
Preparing for a technology failure after a disaster or cybersecurity attack
Companies should take a risk management approach in preparing for a technology and facility failure. An organization’s resiliency strategy should address cybersecurity and business continuity needs, incident response plans, and disaster recovery procedures. The National Institute of Standards and Technology (NIST) developed a framework for protecting critical infrastructure against weather-related threats and cybersecurity risks, which includes the following pillars3:
1. Govern: Set ownership and connect resilience decisions to business priorities
Establish clear ownership for business resilience and cybersecurity risk. Leadership should understand the organization’s most important services, confirm who can make decisions during a disruption, and regularly review whether plans, resources, and third-party expectations remain aligned with business priorities.
Define who has authority to activate the plan, approve temporary workarounds, contact customers or regulators, and make time-sensitive business decisions.
2. Identify: Determine which services, systems, data, facilities, and third parties matter most
Consider the data, infrastructure, and assets at your company that could be at risk.
- What sensitive data do you have, and what data do you need to protect?
- Identify the vendors and service providers that support critical operations. What happens if one becomes unavailable, how your organization will communicate with that provider, and what reasonable alternative or manual process is available?
- What data have you collected from employees that you’re obligated to protect, such as healthcare information and bank account information for direct deposit of paychecks?
- What physical assets, such as manufacturing plants or office buildings, could be impacted in the event of a tornado, hurricane, or other natural disaster?
- What is the most critical infrastructure at your organization? What would you do if it was severely damaged? (Consider secure rooms, hardware, service connectivity, or data.) Take an inventory of the systems your organization relies upon. Knowing the servers, devices, and software you have is necessary for insurance purposes in case of disaster. You can also use this information to build contingency plans for shifting work to another area when needed.
3. Protect: Put safeguards and education in place before a disruption occurs
Effective business continuity programs combine cybersecurity, fraud prevention, physical security, and emergency preparedness to help employees respond confidently when unexpected events occur.
Reduce risk with technical safeguards like keeping operating systems, software, and applications up to date, applying security patches promptly, and addressing known vulnerabilities before they can be exploited.
Employee education is equally important. Provide regular education, webinars, and awareness resources so employees understand how to recognize potential threats and know what actions to take during an emergency. Participating in initiatives such as Cybersecurity Awareness Month can help reinforce good security habits throughout the year.

Privacy and security center
Huntington’s security center provides resources for fraud protection, identity theft support, and account security. Explore tools, tips, and guidance to help protect what matters most.
4. Detect: Establish ways to recognize and escalate unusual activity quickly
An incident response plan defines what an organization should do in the event of a data breach or other form of security incident. Periodically review these plans and make sure the right people within your organization know the answers to questions such as:
- What happens if malware gets on computers?
- What if there is a ransomware demand?
- What if there is a situation where remote or in-person operations are interrupted?
- What do you do if a known weather event is approaching?
- How will you communicate about outages to employees, customers, vendors, and manufacturers?
Set up systems to detect an intrusion into your system and integrate checks and balances into all processes. Also, ensure antivirus, endpoint encryption, and data loss prevention software are up to date.
Conducting a risk assessment of offices, warehouses, manufacturing plants, and other physical locations can help identify potential emergency situations your employees might face.
5. Respond: Give decision-makers and response teams clear roles and communication paths
When a crisis emerges, revisit the plans you created—and practiced—to respond strategically.
Knowing you cannot predict every scenario, the goal is to give your teams a clear starting point, defined responsibilities, and practiced options so they can adapt as conditions change.
In the instance of a data breach or a prolonged outage that may impact customers, you will also need a communication plan for any media response required. Make sure you are prepared to make a statement and plan to contact any individuals affected by the breach or outage. These communications should also include your board of directors, regulators, and customers.
6. Recover: Prioritize restoration, communicate progress, and apply lessons learned
Business resiliency is an ongoing project. Start with the services most important to your customers and employees and document practical options. Then strengthen the plan through regular conversations and using lessons learned.
Periodically refine your plan and consider an independent review to challenge assumptions and help prioritize future improvements.
Cyber liability insurance may be one component of a broader risk management strategy. Review coverage, exclusions, notification requirements, and available response services with qualified insurance and legal professionals.
Five questions to discuss with your team
The most effective plans are reviewed regularly, tested through exercises, and discussed across the organization so everyone understands their role.
As you evaluate your organization's readiness, consider using these questions to start a conversation with your leadership team, operations staff, and technology partners:
- Which business services, processes, or systems must we restore first to continue day-to-day operations?
- Who has the authority to make critical decisions during a disruption or emergency?
- How will we communicate with employees, customers, vendors, and other stakeholders if normal systems are unavailable?
- When was the last time we tested our business continuity, disaster recovery, or incident response plans?
- What internal or third-party dependencies could prevent us from maintaining critical operations if they became unavailable?
Answering these questions today can help your organization strengthen resilience, identify potential gaps, and respond with confidence in the future.
Subscribe
Huntington Business Insights
Financial news, insights, and guidance delivered right to your inbox.
Sign up to receive emails about our latest articles, case studies, and events on topics that matter to your business.
Featured insights with industry expertise
Tap into insights designed to help you navigate today’s decisions and tomorrow’s opportunities.


Business Cyber Resilience
Midyear cybersecurity and fraud threat report


Business Cyber Resilience
Vendor vulnerabilities: Understanding third-party risk management


Recovery & Response
Cyber liability insurance: How it works and how to assess policies
1 Splunk (a Cisco company) with Oxford Economics. May 2026. The Hidden Costs of Downtime 2026: A $600 Billion Wake-Up Call. Accessed September 16, 2026.
2 Cybersecurity & Infrastructure Security Agency. “Extreme Weather: Severe Storms.” U.S. Department of Homeland Security. Accessed September 15, 2026.
3 National Institute of Standards and Technology. “Framework for Improving Critical Infrastructure Cybersecurity.” United States Department of Commerce. Accessed September 15, 2026.
The information provided in this document is intended solely for general informational purposes and is provided with the understanding that neither Huntington, its affiliates nor any other party is engaging in rendering financial, legal, technical or other professional advice or services, or endorsing any third-party product or service. Any use of this information should be done only in consultation with a qualified and licensed professional who can take into account all relevant factors and desired outcomes in the context of the facts surrounding your particular circumstances. The information in this document was developed with reasonable care and attention. However, it is possible that some of the information is incomplete, incorrect, or inapplicable to particular circumstances or conditions. NEITHER HUNTINGTON NOR ITS AFFILIATES SHALL HAVE LIABILITY FOR ANY DAMAGES, LOSSES, COSTS OR EXPENSES (DIRECT, CONSEQUENTIAL, SPECIAL, INDIRECT OR OTHERWISE) RESULTING FROM USING, RELYING ON OR ACTING UPON INFORMATION IN THIS DOCUMENT EVEN IF HUNTINGTON AND/OR ITS AFFILIATES HAVE BEEN ADVISED OF OR FORESEEN THE POSSIBILITY OF SUCH DAMAGES, LOSSES, COSTS OR EXPENSES.
Third-party product, service and business names are trademarks/service marks of their respective owners.