IT Disaster Recovery Checklist for Philippine Typhoon Season 2026

July to October is peak typhoon season in the Philippines. PAGASA tracks an average of 20 tropical cyclones entering the Philippine Area of Responsibility annually, with 8–9 making landfall. Super Typhoon Odette (2021) caused multi-week grid outages across Cebu and Bohol. Typhoon Egay and Falcon hit within days of each other in 2023. The pattern is not new — but many Philippine businesses still treat disaster recovery as a document that sits in a folder rather than a capability that gets tested.
This is your pre-season checklist. Run it now, before July becomes September.
What Philippine Typhoons Actually Do to IT Systems
Before getting into the checklist, it helps to understand the failure sequence. Typhoons do not just cut power — they create a cascade:
Grid failure hits first, usually hours before landfall. Distribution utilities shed load to protect transmission infrastructure. This triggers your UPS, then your generator.
Physical damage follows: flooding of ground-floor server rooms, antenna and satellite dish damage cutting internet and WAN links, fibre cuts from fallen trees and poles.
Personnel disruption compounds everything. Your IT team cannot get to the office. Remote access becomes the only option — and remote access depends on infrastructure that may itself be down.
Extended restoration is the part most DR plans underestimate. Major typhoons in Luzon, Visayas, and Mindanao regularly leave provinces without grid power for 3–14 days. Your DR plan must account for this, not just the first 24 hours.
Before the Typhoon: The IT Readiness Checklist
1. Validate Your Backup — Not Just That It Runs, That It Restores
Running backups and having working backups are different things. Before typhoon season:
- Perform a full restore test on at least one critical system. Restore to an isolated environment and verify data integrity.
- Check your RPO. How much data can you afford to lose? If your backup runs nightly and a typhoon hits at 11pm, you may lose a full day of transactions. Move to continuous or hourly snapshots for critical data if your RPO cannot tolerate that.
- Verify off-site copies. On-premise backups in the same building as your primary servers do not protect against flooding or structural damage. At minimum, your backup data should be in a geographically separate location — Microsoft Azure Backup, Azure Blob Storage, or a colocation facility outside your primary typhoon corridor.
For businesses using Microsoft 365, verify that Microsoft 365 Backup is configured and that you understand what it covers. Microsoft 365's built-in retention is not a substitute for a backup policy — see our Microsoft 365 Backup guide for Philippine businesses.
2. Know Your RTO and Test Against It
Recovery Time Objective (RTO) is how long your business can survive without a system before revenue or operations are critically affected. Most Philippine SMEs have never formally defined this — and find out their actual tolerance only when a crisis forces the answer.
For each critical system, document:
- RTO: Maximum acceptable downtime (e.g., "email must be back within 4 hours, ERP within 24 hours")
- Current recovery time: How long does it actually take to restore from your last backup to a working state?
If your current recovery time exceeds your RTO, you have a gap that needs to be closed before typhoon season — not during it.
Azure Site Recovery can dramatically reduce RTO for on-premises workloads by replicating servers to Azure and enabling failover in minutes rather than hours. See our Azure Site Recovery guide for Philippines.
3. Audit Remote Access Infrastructure
If your team cannot get to the office, they need to work remotely. During and after a typhoon, that means:
- VPN reliability: Is your VPN server on-premises? If so, it may be unreachable. Consider a cloud-hosted VPN or zero-trust network access solution.
- MFA without SMS: BSP Circular 1213 has already flagged SMS OTP vulnerabilities. If your VPN or corporate systems use SMS-based MFA, typhoon conditions (cell towers damaged, network congestion) make this unreliable. Switch to authenticator apps (Microsoft Authenticator, Google Authenticator) before the season peaks. See our Entra ID Conditional Access guide.
- Bandwidth at home: Can your team actually work effectively from residential internet? Test this on a normal day. If the answer is no, consider what minimum viable connectivity looks like.
4. Document the Runbook — and Make Sure More Than One Person Has It
A DR plan that only the IT manager knows about is not a DR plan. Before typhoon season:
- Print a physical copy of critical system recovery steps. During a typhoon, power may be intermittent and devices may be uncharged.
- Store emergency contact lists (ISP support numbers, cloud vendor hotlines, generator service contacts, UPS supplier) in multiple formats: printed, cloud-synced, and on personal phones.
- Designate a backup IT contact in case your primary IT person is unreachable. For small businesses without internal IT, this is your managed service provider — confirm their typhoon-season availability policy now.
Technica provides managed IT and cloud services with defined SLAs that include typhoon-season coverage. If you are managing IT entirely on your own, this is the time to evaluate whether that is sustainable.
5. Check Physical Infrastructure
- UPS runtime: Run a full battery discharge test. If your UPS batteries are 3+ years old, runtime may be significantly below the nameplate spec. Replace before season.
- Generator fuel: Verify fuel storage capacity and schedule a pre-season service check. Ensure fuel contracts cover emergency top-up during extended outages.
- Server room flood risk: Is your server room on the ground floor? What is the flood risk at your specific location? PHIVOLCS and LGU hazard maps can help — but site-specific assessment by a qualified engineer is the only reliable answer.
- Cable runs and patch panels: Check for water ingress points above server racks.
During the Typhoon: Operational Protocol
Signal No. 1 Raised (TCWS 1)
- Notify IT team to monitor systems and prepare for potential remote transition
- Verify last backup completed successfully and off-site copy is current
- Start UPS on a manual runtime check if systems permit
Signal No. 2–3 Raised (TCWS 2–3)
- Transition non-essential staff to remote work
- Conduct orderly shutdown of non-critical servers if grid instability is observed
- Switch to generator if UPS runtime is less than 4 hours and grid is already unstable
- Notify ISP of potential circuit issues
Signal No. 4 or Super Typhoon Warning
- Shut down all non-essential systems in an orderly sequence (database servers last)
- Ensure backup jobs have completed; trigger a manual backup if timing allows
- Do not leave systems running unattended if flooding risk is present at the site
- Activate DR failover to cloud environment if your organisation has this configured
After the Typhoon: Recovery Sequence
Priority 1 — Safety first. Do not enter a flooded server room. Water and live electrical equipment is a fatal combination. Engage a qualified electrician before restoring power to any wet environment.
Priority 2 — Assess before restoring. Check physical hardware for water damage, check UPS battery integrity after discharge, check that storage arrays and NAS devices have not sustained shock damage.
Priority 3 — Restore in dependency order. Network infrastructure (switches, firewalls) → domain controllers and authentication services → email and communication → ERP and business applications → secondary systems. Restoring in the wrong order extends downtime and can corrupt data.
Priority 4 — Communicate. Notify clients and stakeholders of your recovery status. A brief, factual update is better than silence. Businesses that communicate transparently during outages retain client trust better than those that go dark.
Priority 5 — Post-incident review. Within two weeks of the event, document what failed, what worked, and what would have reduced downtime. Update your DR plan accordingly. This is the only way DR planning actually improves.
The Bigger Picture: BCP vs. DR
Business Continuity Planning (BCP) and Disaster Recovery (DR) are related but distinct:
DR is about restoring IT systems after an event. It answers: how do we get our systems back online?
BCP is about keeping the business operational during and after an event — which may include operating with degraded IT systems, manual processes, or from alternate locations. It answers: how do we keep serving clients even if systems are down?
Most Philippine SMEs have some version of DR thinking (backups, UPS, generators) but limited BCP thinking. The questions BCP forces you to answer: Can you process payroll manually if your HRIS is down for three days? Can you issue receipts if your POS is offline? Can you communicate with clients if your email is unreachable?
The answers to these questions determine your actual resilience — not the number of backup copies you have.
How Technica Can Help
Technica Solutions Inc. provides end-to-end business continuity infrastructure for Philippine organisations:
- Azure-based disaster recovery with defined RTO/RPO — workloads replicate continuously to Microsoft's Southeast Asia region
- Microsoft 365 and cloud backup configuration and monitoring
- UPS and generator integration through our Power Systems team — preventive maintenance contracts, emergency fuel top-up, and battery replacement programmes
- Managed IT services with typhoon-season SLAs and 24/7 monitoring


