Disaster recovery and the quality of computerized systems - QFINITY
QFINITY · Pharmaceutical Engineering

When IT goes down, preparation decides.

In the January/February 2024 issue of ISPE Pharmaceutical Engineering, Frank Henrichmann, Oliver Herrmann, Maximilian Stroebe and Marcus Schwabedissen use a case study to show what matters in disaster recovery in a GxP-regulated environment - and why a cyberattack is not just an IT problem but a question of product quality, patient safety and data integrity.

The article

Disaster recovery is a quality task.

As digitalization advances, pharmaceutical business and decision processes depend on IT systems and data being continuously available - criminal activity, political unrest and environmental risks make disaster recovery and business continuity planning indispensable. Using a hypothetical case study - a successful ransomware attack on a mid-sized pharmaceutical company - the article walks through the typical pitfalls and shows how to restore operations and compliance, with the quality function becoming the "enabler" that creates robust documentation for accountable releases.

A backup is not a plan. Only when plans, roles and recovery paths are defined, accessible and tested before the emergency does technology become real resilience.
The growing need

Ransomware as a time bomb.

Cyberattacks have been rising for years; ransomware and phishing are the biggest threats to the industry. The central question is not how to achieve 100 % security - there is no such thing - but how a backup stays reliable:

  • The landscape: 66 %

    A 2023 survey found that 66 % of organizations had experienced at least one ransomware attack.

  • The time-bomb tactic

    Attackers increasingly design malware as a "time bomb": instead of encrypting data immediately, it infects it over weeks or months - until the backups archived along the way are compromised too.

  • The consequence

    A backup stays reliable through verification and monitoring - set up before the emergency arrives.

Standards & guidance

GAMP 5 Second Edition and the ISO standards.

  • Appendix O9 - Backup and Restore

    Since most companies base their DR strategy on backup and restore, how backups are set up, verified and monitored must be addressed - no exceptions.

  • Appendix O10 - Business Continuity Management

    Guidance for keeping operations running during a disaster.

  • Appendix O11 - Security Management

    Requirements and measures to prevent security incidents in the first place.

  • ISO standards as a complement

    ISO/IEC 27000:2018 gives an overview of information security management systems (incl. ISO 27031 on IT disaster recovery); ISO 22301 defines the requirements for a business continuity management system.

The human factor

The preparedness paradox.

People tend to believe disasters only happen to others ("Why would anyone attack us?") - the article calls this pattern the "preparedness paradox". Its building blocks and consequences:

Over-optimism and normalcy bias push the risk aside
Known short-term costs are overweighted, unknown long-term benefits underweighted
Too little time and readiness - plans are not fit for purpose, not accessible, or not current in an emergency
Half of all companies test their DR only annually or less often, 7 % not at all
Preparedness Paradox Over-optimism Normalcy Bias Critical Thinking
The distinction

Three disciplines, one lifecycle.

The three disciplines are closely intertwined and are managed across the entire system and data lifecycle - as a continuously maintained capability, not a one-off project. In an emergency, work runs in parallel and documentation is less controlled than in normal operation: a risk- and judgment-based approach is indispensable.

  • Anticipate

    Disaster recovery assesses the impact of disasters - IT-related, personnel or site-related - and develops recovery strategies.

  • Keep operating

    Business continuity addresses how business processes stay operational during a disruption.

  • Restore

    Backup & restore is typically the key to restoring systems, data and services after IT-related incidents.

The authors

Written from practice.

The article comes from a QFINITY author team - Frank Henrichmann (Senior Executive Consultant), Oliver Herrmann (Founder and CEO) and Marcus Schwabedissen (COO and Senior Executive Consultant) - together with Maximilian Stroebe (PhD, Senior Manager, Janssen Vaccines & Prevention, A J&J Company). It was a Finalist for the ISPE Article of the Year 2024 (Roger F. Sherwood Award) and is an in-house publication - QFINITY's own position, written by practitioners who have supported disaster recovery scenarios in the GxP environment.

Finalist ISPE Article of the Year 2024 Roger F. Sherwood Award Computer System Validation Data Integrity Business Continuity
Quality Considerations in Disaster Recovery: A Case Study - ISPE Pharmaceutical Engineering
Related topics

From emergency to lived practice.

Is your disaster recovery more than a backup?

We work with you, risk-based, to determine whether plans, roles and recovery paths hold in an emergency. Free initial consultation, about 30 minutes, directly with one of the authors.

Arrange an initial consultation