Power resilience is an engineering and dependency-assurance problem before it becomes an incident-response problem. This guide focuses on the infrastructure controls that make a site or technology service resilient to utility failure: UPS autonomy, generator loading, automatic transfer, fuel endurance, cooling, telecommunications, water and the evidence needed to trust those controls.
Map the complete utility dependency chain
Do not stop at the incoming electricity feed. Identify the components between utility loss and usable service: switchgear, ATS, UPS, batteries, generators, fuel, distribution boards, cooling, fire/life-safety systems, network rooms, lifts and building-management controls. A single unprotected component can defeat an otherwise expensive resilience design.
| Control | Question to prove | Evidence |
|---|---|---|
| UPS | How long can the real critical load run at current battery health? | Load test, battery condition and autonomy result |
| Generator | Can it carry the required load through transfer and sustained operation? | Load-bank/live transfer test and maintenance record |
| Fuel | How many hours are available and how quickly can replenishment arrive? | Consumption calculation, tank level, supplier SLA and alternate source |
| Cooling | Will critical rooms remain within safe limits on emergency power? | Emergency-power mapping and thermal test |
| Telecoms | Do carrier and network paths survive the same outage? | Path diversity and failover evidence |
| Site access | Can staff safely enter, work and exit? | Life-safety and facilities validation |
Calculate endurance, not just installed capacity
Generator nameplate capacity does not show how long a service can operate. Calculate expected critical load, start-up peaks, fuel consumption, usable tank volume, refuelling lead time and the effect of degraded equipment. Compare the resulting endurance with the business recovery strategy and the time needed to relocate or fail over.
Test transitions because transitions fail
Routine generator starts are insufficient. Evidence should cover utility loss, UPS ride-through, automatic transfer, generator acceptance of load, return to utility and failure scenarios such as one generator unavailable. Coordinate tests with technology and business owners so the organisation knows whether applications and services remained usable—not merely whether the generator ran.
Plan for correlated utility failures
Electricity loss can coincide with telecom congestion, cooling loss, water interruption, transport disruption or regional fuel demand. Challenge assumptions about “independent” suppliers and alternate sites that share the same substation, carrier route, fuel distributor or geographic hazard.
Supplier and fuel assurance
Record fuel delivery lead time, minimum order, emergency priority, access requirements, payment/authorization arrangements and alternate suppliers. Exercise a replenishment scenario rather than relying solely on a contract. Where fuel quality or long storage matters, include inspection and rotation controls.
Recovery acceptance
After utility restoration, verify stable supply, equipment alarms, cooling, network availability and any systems that shut down unexpectedly. Technical restoration should hand off to the business operating recovery process with clear evidence and exceptions.
Use the companion operational guide during an outage
For minimum service, manual workarounds, customer communications, staffing and transaction reconciliation during the disruption, use Power Outage Business Continuity: Keep Critical Services Operating. This page intentionally owns the infrastructure-resilience intent.
FAQ
How much generator fuel should a site hold?
There is no universal duration. Determine endurance from critical-service tolerance, realistic replenishment time, regional disruption scenarios, storage constraints and alternate-site/failover strategy, then test the assumption.
Is an annual generator test enough?
Not necessarily. The assurance program should reflect criticality and include the transitions and dependencies that matter, such as UPS ride-through, ATS operation, sustained load, cooling and technology/business validation.
Define a site energy operating envelope
For each critical site, document the minimum electrical load, cooling requirement, UPS autonomy, generator capacity, fuel burn rate, refuelling lead time and the equipment that cannot be supported indefinitely. Convert these values into operating thresholds: when nonessential loads are shed, when services move to an alternate site, when staff relocation begins and when controlled shutdown is safer than exhausting backup power. Revalidate the envelope when equipment, occupancy or critical-service demand changes.
Test transitions, not only components
Individual UPS and generator maintenance does not prove continuity. Exercise the sequence from utility loss through UPS ride-through, automatic transfer, generator stabilization, cooling response, network and application validation, fuel replenishment and return to utility. Include at least one failed transition such as a generator that does not start, an ATS fault or delayed fuel delivery. Record the time to detect, decide and restore the minimum service.
Coordinate facilities, technology and business decisions
Establish one outage decision picture covering remaining battery/fuel endurance, thermal conditions, technology health, staff safety, alternate-site readiness and business backlog. Facilities may see stable generator output while technology is degraded, or technology may be healthy while fuel endurance is falling below the time needed to relocate. Define who combines these facts and who has authority to reduce service, evacuate, fail over or shut down safely.
Protect recovery from hidden utility dependencies
Map dependencies beyond the building supply: telecom exchanges, mobile towers, water and cooling, access control, lifts, fire systems, fuel pumps, local transport and supplier facilities. Determine whether alternate sites and data centers share the same grid zone, substation, fuel route or regional hazard. Where concentration cannot be removed, make the residual exposure visible and define a practical workaround or risk acceptance.
Use evidence-based acceptance criteria
- Critical load transfers without exceeding the approved interruption tolerance.
- Backup power sustains the tested minimum load for the required endurance or until replenishment is demonstrated.
- Cooling and environmental conditions remain inside safe operating limits.
- Business representatives validate priority services after each power transition.
- Fuel replenishment, supplier escalation and site access are exercised rather than assumed.
- Return to utility includes stabilization, alarm review and controlled restoration of shed loads.
Related BCM.Center resources: Power Outage Business Continuity: Keep Critical Services Operating.