Typhoon Season IT Survival: A Business Continuity Plan for Philippine Weather
July 3 Flooded Metro Manila Before a Single Storm Was Named
Last Thursday, plain monsoon rain shut classes across roughly fifteen Metro Manila cities, PAGASA raised a yellow rainfall warning, and flood bulletins ran all day for the Pasig-Marikina, Laguna de Bay and Tullahan basins (Manila Bulletin). No typhoon was involved. If habagat alone can do that in the first week of July, the question is not whether your business gets disrupted this season but whether anyone wrote down what happens when it does — which is all a typhoon business continuity plan is.
PAGASA puts the rainy season from June to November (PAGASA), so early July is the front of a five-month window, not the aftermath of one bad week. This is preparation, not a post-mortem — and Laguna de Bay is the basin our Biñan office sits beside.
The gap nobody names: government suspends government work and classes; private employers decide for themselves. Most SMEs make that call in a 6 a.m. Viber message from the owner.
A BCP — business continuity plan — is that decision written down in advance. Five steps follow; by the end you hold one page with a name on every line and a restore test booked, about a week's work for a 10-40 person business. Scope is weather only: ransomware belongs to the article linked in Step 3.
Step 1: Write the Trigger — Who Calls It, and On What Public Signal
The most common failure is not technical: nobody is sure who may close the office, so the call waits for the owner, stuck in traffic. Name one decision-maker and one alternate in writing, with mobile numbers.
Tie the call to public signals, tracking where staff live, not where the office sits: someone in Marikina is cut off while Biñan is dry.
| Signal | Action | Who decides |
|---|---|---|
| Yellow warning over 2+ staff cities | Remote by default | Ops Manager |
| LGU suspends work in the office city | Office closed | Ops Manager |
| Flood bulletin on your basin | Remote, whatever the color | Ops Manager / CEO |
Signals worth watching (and who watches them)
- PAGASA warnings and the daily flood bulletin for your basin
- LGU announcements for every city your people commute from
- Both watched by one named person, with a backup
Sign the telecommuting terms before the water rises
Republic Act No. 11165, the Telecommuting Act of December 2018, makes private-sector telecommuting voluntary and "upon such terms and conditions as they may mutually agree upon" (RA 11165) — signed now, not assumed in a group chat at dawn. Cover hours, deliverables, equipment, connectivity allowance, pay treatment, and data handling at home.
Pick an announcement channel and a fallback that survives a dead office: group chat plus an SMS tree. Print the signed trigger table and tape it above the office manager's desk. RA 10121 also invites private-sector participation in disaster risk reduction (RA 10121), so trade numbers with your barangay disaster office too.
Step 2: Get the Hardware Off the Floor — Server Room and Power Checklist
Flood server protection starts with elevation, not software. When we walk a server room as part of our server infrastructure services, the first thing we measure is height off the floor: racks, UPS, switches and patch panels above the building's highest known water line. Server Room Basics: Racks, Cooling, and Power for Your First On-Prem Setup covers layout.
Water arrives from above as often as below: roof seals, the aircon drip tray over the rack, pipes crossing that ceiling. A P600 tray beats a P150,000 server.
A UPS buys minutes for a graceful shutdown, not hours of operation. Size it to bring down every device that matters, and test the battery — they die quietly at three to five years. Decide whether a generator is in scope, then plan for the surge when power returns, which kills as much hardware as the outage: Brownouts and Red Alerts: Protecting Your Servers with UPS and Power Planning.
Photograph the cabling, write a one-page ordered shutdown and startup sequence, and keep it printed. Pack a grab bag too: backup drive, bootable media, spare router, power bank, contact tree, plan.
Step 3: Prove You Can Restore — Backups, RTO, and the Copy Outside Your Basin
Most owners know the 3-2-1 rule: three copies, two kinds of media, one offsite. Typhoon season adds the correction people miss — offsite must mean outside your flood basin and outside your power grid. The drive in the branch across the street floods when you do; the NAS at the owner's house shares your brownout. That is why cloud backup and hosting is the honest answer for most SMEs.
Write two numbers per system in business language. RTO, recovery time objective, is how long you can be down before it hurts: if the POS is dead, we lose sales by the hour. RPO, recovery point objective, is how much recent work you can lose.
Then run one restore drill this month: restore a system to a spare machine or cloud instance, time it, and write that number beside your RTO. A backup nobody has restored is an assumption. We cover how to build a disaster recovery plan separately; this one stays on the weather side.
Credentials are the other silent failure point: registrar, hosting, email admin, backup console, bank portal. If they sit only in one person's head and that person is stranded in Marikina, the plan is dead. Use a password manager with emergency access for a second named person.
Rank your systems before the storm ranks them for you
- Same day: payroll, POS and orders, customer phone and email
- Within 48 hours: file server, reporting, integrations
- Within a week: archives, dev environments, seasonal work
Step 4: Keep the Line Up — Internet, Phones, and Where Work Actually Happens
A single internet line is the most common continuity gap in Philippine SMEs. The fix is a second path on a different medium — fiber plus fixed wireless or LTE — behind a dual-WAN router that fails over automatically, switching by itself when the first line dies. Test the swap on a calm day.
Your phone number is part of continuity: forward calls to a mobile, decide who answers, and pre-write the away message for your site, Facebook page and auto-reply.
Remote work fails at the employee's house, not at head office. Survey the team now: who has fiber, who is mobile-only, who is in a flood-prone barangay, who cannot work from home. That survey is your staffing plan. And anything that only runs on the office network is a single point of failure on a rainy Tuesday — the honest case for cloud or hybrid hosting, monthly cost and all.
Step 5: People, Payroll, and the Day-After Checklist
People first, servers second. When the trigger fires, run a head-count by SMS off a printed contact tree — name, mobile, alternate mobile, barangay — independent of the office network.
Payroll does not pause because the office closed. Confirm now that it can be run remotely, that the approver has access from home, and that staff know their pay treatment under the Step 1 terms. Pre-write the customer message too: operating remotely, deliveries may be delayed, here is how to reach us.
The day after:
- Never power on wet equipment; dry and check it first
- Photograph damage before moving anything — your insurer will ask
- Log the timeline: trigger fired, systems down, systems back
- Watch for silent damage from the restoration surge
Then hold a 30-minute debrief within the week, update your typhoon business continuity plan with what broke, and re-date it. A plan never revised fails the same way twice.
Your One-Page Typhoon BCP: The Printable Checklist
Put the whole typhoon business continuity plan on one page, print it, and add two columns beside every line — OWNER and DATE. An unassigned checklist is a wish list.
Before, this week: trigger table signed · telecommuting terms signed · racks and UPS off the floor · restore drill timed · offsite backup verified outside your basin · second internet path tested · contact tree printed · grab bag packed.
During: head-count by SMS · ordered shutdown · announcement sent · customer message posted · calls forwarded.
After: nothing powered on while wet · damage photographed · timeline logged · debrief held · plan re-dated.
Most of that costs nothing. The expensive items — generator, second server, cloud migration — can wait while the free ones get done first. Outside help earns its fee on three things: the flood-exposure assessment, monitored offsite backups with tested restores, and someone on call who is not the owner — usually why SMEs move to managed IT support.
Most of this you can finish yourself in a week. The two lines people never get to are the flood-exposure walkthrough and a restore that has actually been tested. If you want a second pair of eyes before the season deepens, book a 30-minute call with us — we are in Biñan, in the same Laguna de Bay basin as last week's bulletins, and there is no charge.