A better broadband failover plan starts by identifying the work that must continue during an outage, then choosing and testing a secondary connection and router configuration that fit the site. A second circuit or mobile service can reduce disruption for some scenarios, but local coverage, provider faults, power loss, capacity and application dependencies still set important limits.

Identify what has to work when the primary circuit fails

Begin with the business services rather than with a connection type. Ask which activities stop if the site loses internet access: card payments, cloud applications, telephony, customer communication, security systems, remote support, file access, ordering or a production process. Some teams may continue temporarily using a manual process or a mobile device, while others need a dependable route to a particular cloud service. Record the practical effect and the owner who can decide what should be restored first.

Map the dependencies behind those activities. A cloud phone system may depend on local power, a router, Wi-Fi, an identity service and a working secondary connection. A laptop may be able to use a mobile hotspot, but a fixed payment terminal or site-to-site connection may not. This prevents an attractive failover product from being mistaken for a complete continuity plan. It also reveals where a simpler workaround, documented contact route or local procedure may be more valuable than extra bandwidth.

  • List critical site activities and the cost of interruption.
  • Map power, router, Wi-Fi, cloud and supplier dependencies.
  • Identify services that can use a temporary manual workaround.
  • Name the business owner who sets recovery priorities.

Check realistic connection options for the specific location

Availability and expected performance are location-specific. Use provider information and independent resources such as Ofcom's coverage and speeds guidance to investigate fixed and mobile options for the address, but treat published figures as an input to assessment rather than an outcome. Building layout, local demand, installation constraints, service terms and conditions outside the site can all affect the connection that is actually available and usable.

A secondary path should, where practical, avoid sharing the same obvious point of failure as the primary service. That might mean a different technology, entry route, carrier or mobile network, but the right choice depends on the site and contracts. Confirm how installation, activation, support, data allowances, public addressing and handover to your router will work. If the only available secondary route has limited capacity, document which services it is intended to support and which are deliberately excluded.

  • Check fixed and mobile options against the actual site address.
  • Ask about installation dependencies, terms and support boundaries.
  • Compare likely failure modes, not only advertised headline speeds.
  • Record the capacity and services intended for the secondary path.

Design the router and traffic rules around business priorities

Failover depends on more than a spare connection. The router needs a clear health check, decision rule and route for traffic once the primary circuit is considered unavailable. Decide whether all traffic should move, whether only selected services should use the secondary path, and what happens to fixed public addresses, inbound calls, VPNs or remote access. Some applications do not recover cleanly when a public address changes, so involve the relevant supplier before relying on an automatic switch.

Keep the configuration understandable and protected. Record the circuit details, router ownership, administrator access, monitoring contacts and any changes made for failover. Use named administrator accounts where possible and store recovery information securely. If a configuration needs manual approval during an incident, say so in the plan. A partly manual design can still be appropriate when it matches the business risk and avoids a broader change that has not been tested.

  • Define the health checks and conditions that trigger a switch.
  • List inbound, VPN, telephony and public-address dependencies.
  • Choose which traffic is essential when capacity is constrained.
  • Document router ownership, access and configuration recovery details.

Test the response without creating an avoidable outage

A plan is not ready simply because a secondary connection is installed. Test the relevant route in a controlled window with people who can observe the services that matter. Confirm whether staff can authenticate, make a call, reach a cloud application, process a transaction or contact a supplier as intended. Record the conditions, start and end time, observed behaviour and any limits. A careful test may be staged or simulated where removing a primary circuit would create unacceptable risk.

NCSC response and recovery guidance is a helpful reminder to consider communication and decision-making alongside technical action. Staff should know who to contact, whether they need to change Wi-Fi or mobile settings, and what work can continue while a fault is investigated. Suppliers need the right account details and an agreed escalation route. Capture lessons from every outage or exercise, including the services that did not behave as expected, and decide whether to change the configuration, process or business workaround.

  • Test in an agreed window with business and technical observers.
  • Check the specific services, not just whether a router light changes.
  • Record results, limits, contacts and follow-up actions.
  • Repeat a relevant test after material circuit or router changes.

Keep the plan aligned with wider resilience arrangements

Connectivity is only one part of resilience. Link the failover plan to power arrangements, backup and recovery plans, telephony procedures, supplier contracts and communication templates. If a site loses power, a second internet circuit may not help unless the router, access points and essential devices have an appropriate power plan. If remote staff rely on home or mobile connections, their working arrangements and data-handling expectations also need to be considered.

Review the plan after a site move, office alteration, change of carrier, new cloud service, phone-system change or critical business process change. Keep a concise summary that can be reached when the normal network is down. It should state the circuit contacts, intended failover behaviour, business priorities and escalation steps. The aim is to make the next responsible action clearer during disruption, not to claim uninterrupted service in circumstances outside the organisation's control.

  • Connect internet plans with power, telephony and recovery arrangements.
  • Keep provider contacts and escalation information accessible offline.
  • Review the design after a material site, supplier or system change.
  • State known exclusions and workarounds plainly to decision-makers.

Failover does not remove every connectivity risk

This guide cannot confirm availability, coverage, speed, installation timing or uninterrupted service at a particular address. A secondary route may be affected by local conditions, shared infrastructure, power, configuration, capacity, supplier response and application behaviour. Validate the design against the site and the services that genuinely matter before depending on it in an outage.

Questions for a failover design review

Use a short workshop to agree the continuity objective before selecting a circuit or changing a router.

  • Which site services must continue, and which can use a temporary workaround?
  • What independent connection options are realistically available at the location?
  • Which traffic, addresses, phone services and suppliers must be included in a test?
  • Who will make decisions, contact providers and communicate during an outage?