The call never started
I was in Tier1's Gisborne office and about to join a team video call when Cyclone Gabrielle took the region offline. The power went first. Fibre was gone. Mobile service was gone too. A normal workday became an immediate lesson in how cut off a connected business can be when several systems fail together. The first lesson was that a backup is not a product sitting in a cupboard or a green tick in a dashboard. A backup is a complete, tested path from the failure to the work you still need to do. That path includes power, communications, equipment, credentials, people, and a decision about what matters first.
One genuinely different connection changed what we could do
Gisborne Net were brilliant. Our office already had their service as failover, using infrastructure that was independent of the failed fibre path. They stood up VoIP over that connection, and I was able to make some external calls. That small window of communication mattered. It let us coordinate a flight carrying fuel, cash, and activated Starlink kits into Gisborne. A second invoice from the same failure domain would not have helped; the value came from a connection able to fail differently.
- Map which physical and upstream paths each connection depends on
- Confirm whether local towers and network equipment have backup power
- Include voice and secure administration in the failover design
- Test by disconnecting the primary circuit—not by reading a status page
The Starlink kits had to arrive ready
We learned something important about emergency satellite equipment: Starlink kits that had not already been activated could not simply be brought online once the ordinary internet was gone. The hardware existed, but the activation path it depended on did not. That is the difference between owning emergency equipment and maintaining an emergency capability. Current Starlink offerings include Standby Mode and reactivation features, but a business still needs to confirm what its specific plan supports, who controls the account, whether the terminal is current, and how reactivation will work when the normal link is unavailable.
- Keep the customer account, billing, and authorised contacts current
- Use an appropriate active or standby plan rather than a cancelled assumption
- Allow the terminal to receive software updates
- Record and test the activation or plan-change procedure
We shifted from restoring IT to moving what the region needed
I met another Tier1 team member at Gisborne Airport, collected them and the incoming supplies, and we started delivering cash, fuel, and activated Starlink kits. Equipment went to Gisborne District Council, Chorus, the Muriwai area, and other locations where communications could support the wider response. This was not a tidy disaster-recovery exercise with a single failed server. Roads, suppliers, power, money, communications, staff, and public need were all moving at once. The priority was whatever restored the most useful capability next.
Cloud payroll with no internet: what do you do?
Gisborne District Council had Starlink online. The building was crowded with people trying to contact loved ones and let them know they were safe, alongside business owners trying to complete basic work such as payroll. Their payroll might have been safely hosted in the cloud, but without internet, power, a working device, and usable authentication, the business still could not reach it. This is why a backup strategy must start with the outcome. If wages, deliveries, animal welfare, health and safety, or customer communication cannot wait, write down the minimum information and authority needed to keep that work moving when normal systems are unreachable.
- Which payments must be made and who can authorise them?
- Which contacts, rosters, balances, and supplier details are needed offline?
- Which authentication methods fail when phones, email, or mobile networks fail?
- Which manual process can run safely until systems return?
Prepare to trade for one week—and then for two
A useful planning session asks how the business would operate for one week with no grid power and no terrestrial communications, then repeats the exercise for two weeks. Do not assume every person, building, road, supplier, or cloud service is available. The answer will be different for a professional office, packhouse, farm, medical provider, workshop, or community organisation, but the dependencies are remarkably consistent.
- A safely installed generator, tested connection point, fuel plan, and named operators
- UPS coverage for the terminal, firewall, switches, Wi-Fi, phones, and essential devices
- An active or appropriate standby Starlink service with a clear sky view
- Automatic or documented manual failover with critical traffic prioritised
- Offline copies of emergency contacts, procedures, rosters, and essential records
- A payroll, payment, and approval process that does not rely on one unavailable person
- Spare charged devices, cables, power supplies, radios, and printed instructions
- A scheduled exercise that tests the complete path under realistic conditions
Back up the ability to operate, not only the data
Cyclone Gabrielle taught me that resilience is the ability to assemble a working minimum business from whatever remains available. Data backup is essential, but it is only one layer. Power without fuel runs out. Satellite without an activated service stays dark. Cloud payroll without communications remains out of reach. A plan nobody has printed or practised becomes another unavailable file. Start with the work your people and community cannot wait for. Trace every dependency needed to perform it. Then remove single points of failure, document the fallback, and test it while the roads are open and the phones still work. Make the review part of ordinary business planning: new staff, new applications, changed suppliers, moved equipment, and expired accounts can quietly invalidate an emergency procedure long before the next storm arrives.
Frequently asked questions
Is a cloud backup enough for an East Coast business?
No. Cloud backup protects data, but the recovery path also needs power, connectivity, devices, credentials, people, and a tested procedure. Plan for how the business operates when the cloud is safe but temporarily unreachable.
Should we keep a Starlink only for emergencies?
It can be a useful standby, but do not leave an untested cancelled kit in a cupboard. Confirm the current plan, account access, software state, power, installation, reactivation path, and firewall configuration before relying on it.
How large should our generator or UPS be?
Size it from the equipment and runtime the continuity plan requires. Include the internet terminal, firewall, switches, Wi-Fi, phones, essential computers, safe generator operation, and fuel—not only one device.
What business information should we keep offline?
Keep the minimum needed for safe operation: emergency contacts, staff and supplier details, escalation paths, account recovery instructions, rosters, critical procedures, and the information needed for payroll or urgent payments. Protect offline copies from unauthorised access.
How often should failover be tested?
Test on a schedule and after material changes to circuits, firewalls, accounts, power systems, or staff responsibilities. The useful test disconnects the primary path and confirms critical work can continue.
Can Tier1 design and manage a Starlink failover system?
Yes. Tier1 assesses and manages the solution, coordinates dedicated installers for physical installation, configures firewall failover and monitoring, and tests the complete path. The customer owns the Starlink account and subscription.