Home · Business Continuity
Statement

Business Continuity Plan

Version 11, reviewed 12 July 2026

This plan sets out CyberLiver's approach to business continuity in scenarios where the CyberLiver platform and services cannot be used as normal. It ensures we can continue to operate, and can restore critical services, during and after a disruption, with particular regard to the continuity of clinical service and to patient safety.

It applies to all staff, contractors and sub-processors involved in delivering CyberLiver services, including services delivered to NHS organisations under the NHS SBS Healthcare AI framework, and is maintained as a controlled document within CyberLiver's ISO 13485:2016 quality management system.

Potential disruption scenarios

The plan addresses the scenarios that can affect the normal use of CyberLiver applications and services:

  • Cyber attacks, including ransomware, denial-of-service and data breaches
  • System failures, including hardware or software failure, network outage and cloud region outage
  • Natural disasters, including floods, fire and earthquakes
  • Human error, including accidental data deletion and misconfiguration
  • Supply chain and sub-processor issues, including third-party or cloud provider outages
  • Pandemics and other health crises affecting workforce availability

24/7 support and escalation

CyberLiver operates a support and incident-escalation capability available 24 hours a day, 7 days a week, 365 days a year for the services it provides to NHS organisations. Outside standard business hours, critical and high-priority incidents are handled by a designated on-call engineer reachable through a single 24/7 contact route, responsible for initial response, triage and escalation.

Incident priorities

  • P1 — Critical: complete loss of a live clinical or patient-facing service, a confirmed security or data breach, or any incident with potential patient-safety impact. Acknowledged within 30 minutes, 24/7, with immediate escalation to the Technical Authority and Clinical Safety Officer.
  • P2 — High: major degradation of a service or a key feature unavailable, with no immediate patient-safety impact. Acknowledged within 1 hour during support hours, within 2 hours out of hours.
  • P3 — Medium: minor or partial loss of function with a workaround available. Acknowledged within 1 business day.
  • P4 — Low: cosmetic issue, query or service request. Acknowledged within 2 business days.

Clinical safety

Where an incident is assessed as having potential patient-safety impact, it is referred to our Clinical Safety Officer, provided under DCB0129 by an independent clinical safety consultancy, for clinical safety assessment and hazard-log review. Immediate incident containment, service restoration and customer communication are handled by the internal team and are not dependent on the CSO's availability.

Recovery and review

The plan defines recovery objectives, backup and disaster-recovery arrangements, and post-incident review, governed by our Support and Incident Management Procedure. It is reviewed on a quarterly cycle within our ISO 13485:2016 quality management system.