Cloud DR and compliance
Disaster recovery with documentation for a ZInfV-1 audit.
For entities in scope that have to show recovery works. You set the recovery targets, the solution in HC Cloud is designed to meet them, and the documentation comes out of the tests. The same team prepares both, under one contract.
Among its measures, the Information Security Act requires business continuity and disaster recovery plans and regular backups. At an audit, what counts is what you can show: the test plan, the measured result, and a record of what was done when a test did not go to plan.
With us this documentation is produced as we go, from the tests we run on your solution. That is why it stays aligned with the real state of the systems.
ZInfV-1
What matters for recovery
Effective from
19 June 2025
The Act transposes the NIS2 Directive.
Entities in scope
around 1,000
organisations, up from around 100 under the previous act.
Deadline for measures
- 19 June 2026for existing entities (now passed)
- 19 December 2026for newly designated ones
Measures
Among others
- 01A business continuity management system
- 02Business continuity and disaster recovery plans
- 03Regular backups
Supervision
URSIVThe Slovenian information security authority.
Supply chain
Entities in scope vet their suppliers, so the requirements also reach companies the Act does not directly apply to, by way of contract.
We use the same approach for DORA with financial entities and for ISO 22301, whether you maintain the standard or are working towards it.
Fines reach €10 million or 2% of total worldwide annual turnover for essential entities, and €7 million or 1.4% for important ones. Each organisation assesses for itself whether it is in scope. A summary for orientation, not legal advice.
Approach
Targets at the start, proof at the end
We start from what the business and the law require: which processes must not stall, how long they can be unavailable and how much data may be lost. If you have a business continuity plan, we work to it; otherwise we set the targets together with you. We design the solution to meet them, and a test confirms it. That same test later serves as evidence at the audit.
Production stays where it is today: with you, in your data centre or with another provider. Replication runs into HC Cloud, and the data stays in Slovenia or within the EU.
The specific values depend on your environment and are determined in the design phase.
Evidence
What we prepare
From each test
Recovery documentation
- A test plan with the scenario, scope and success criteria
- A report with the measured recovery time and recovery point against the agreed target
- Time-stamped evidence of the test carried out
- A register of deviations and the measures taken
- A summary for management and the auditor
Against the law
An evidence map
- Each document is linked to a specific requirement of the framework you are audited against
- When the requirements change, we adjust the map and the programme
- We keep track of regulatory changes
During the audit
Team support
- We take part in the portion of the audit that concerns recovery
- The same people as for the solution itself
- The auditor's follow-up questions are answered from existing documentation
We do not issue a certificate and we do not replace your auditor or lawyers. We cover the part that concerns recovery of the IT systems: that it is in place, tested and documented.
Do you already have an audit in the calendar?
Tell us which framework and when. We will look at what needs to be ready on the recovery side by then.
Process
From requirement to evidence
- 1
Which framework applies to you
What actually applies to you and what it requires for recovery.
- 2
Targets and scope
Which systems must come back and within what time. If you have a business continuity plan, we start from it.
- 3
Solution and test
We set up Cloud DR and carry out an actual switchover to HC Cloud, in an isolated environment. We compare the measured result with the target.
- 4
Documentation and cycle
The report, evidence and register of deviations, then regular tests and refreshing of the documentation. Evidence that is two years old does not count for much at an audit.
Foundation
Cloud DR beneath the documentation
Beneath the documentation is the Cloud DR solution: continuous, agentless replication into HC Cloud, protection of the application as a whole, recovery points up to 30 days by agreement, a prepared switchover procedure and an annual test that is already included in the service. For entities in scope the managed option usually makes sense, because monitoring, running the tests and the reports are then on our side. If the framework requires more frequent tests or a specific scenario, we arrange that together with the programme.
Our clients
Companies already working with us
HC Center looks after the IT infrastructure of Slovenian companies across a range of industries. Recovery rests on the same team that maintains that infrastructure every day.
A conversation with our team
The conversation includes a colleague from the security and compliance team and the engineer who designs the solution. We look at:
- which framework applies to you and what it requires for recovery,
- which systems should be protected and within what time they must come back,
- what needs to be ready by the next audit.