Do this in June, not when the cone appears
Almost everything worth doing takes days or weeks to arrange and can’t be done in the seventy-two hours before landfall, when every supplier in the region is dealing with every other business at once.
The single most important item is the one people assume is already handled: confirm that your backups exist, that they are stored somewhere outside the building, and that somebody has restored from them. An untested backup is a belief. The moment a storm surge reaches your server room is a bad time to discover the difference.
Verify your backups by restoring something
Not by looking at a green tick. Pick a real file and a real system, restore them, and confirm the contents. Do it now, and repeat it at least twice a year. This is the item that most often turns out to be wrong.
Confirm at least one copy is off site and out of the region
A backup drive in the same building as the server protects you from a failed disk, not from a flood or a fire. Cloud backup handles this by default, but check where it physically is. A copy in a data center one county over is a copy in the same storm.
Write down what has to come back first
If you could only restore three systems, which three? Phones, email, and whatever takes payments is a common answer, and it’s rarely the file server everyone assumes. Deciding this calmly in June is much better than deciding it in a parking lot in September.
Photograph your server room and network cabinet
Every cable, every label, both ends. It’s five minutes of work and it’s worth a great deal to whoever has to put it back together, which may not be the person who built it.
Check your UPS batteries
Uninterruptible power supply batteries last three to five years and fail silently. A UPS with a dead battery is a power strip that beeps. Test them under load, and replace anything over four years old before the season rather than during it.
Know how your phones fail over
If your phone system is on site, a power cut takes your phone number off the air. If it is hosted, UniFi Talk, or a carrier-hosted service, calls can be redirected to mobiles. Find out which you’ve and set up the redirect BEFORE you need it, because configuring it requires the internet connection you no longer have.
The seventy-two hours before
Take a fresh backup and verify it completed
On top of your normal schedule. If you can, take one copy off site physically as well, an encrypted drive that leaves with someone.
Redirect the phones
To mobiles, to an answering service, or to a recorded message with alternative contact details. Do it while you still have power and internet.
Put a notice on your website and Google listing
Your customers will look there first. Updating your Google Business Profile hours and posting a short update is the fastest way to answer fifty phone calls you won’t be able to take.
Shut equipment down cleanly and unplug it
A clean shutdown avoids filesystem damage. Unplugging from both power and the network protects against surge coming down either, and surge along the network cable from an outbuilding or a camera run is a genuinely common way equipment dies.
Lift equipment off the floor
Server, UPS, switches, recorder. Even a few inches matters, and it’s worth more than any other physical precaution available in the time you have.
Take the important small things with you
The backup drive, the documentation, the spare keys to the cabinet. Not the server.
Before you turn anything back on
The temptation after a storm is to get everything running immediately. Resist it for twenty minutes, because this is where equipment that survived the storm gets destroyed.
Check for water first, and do it with the power off
In the room, in the cabinet, in the ceiling above it. Water that has been in contact with equipment means the equipment does not get powered on until it has been assessed, regardless of how dry it looks.
Wait for the power to be stable
Restored power is frequently unstable for hours, with sags and spikes as the grid comes back. Bringing sensitive equipment up during that’s asking for damage. Wait, and bring things up on the UPS.
Power up in order
Internet connection, then firewall and switches, then servers, then everything else. Give each layer a minute. Powering on everything at once produces a set of symptoms that are hard to tell apart.
Verify backups ran before trusting the systems
If a machine came back with a corrupted disk, you want to know that before your backup rotation overwrites the good copy with the bad one. Check first.
Expect your internet to be last
Carriers prioritize infrastructure, and a business connection can be days behind the power. Know in advance whether you can work over a mobile hotspot, and which systems will and won’t tolerate that.
What this looks like if you get it right
A business with off-site backups, hosted phones, and cloud email is largely storm-proof from an IT point of view: staff can work from anywhere with power, customers can still reach you, and the building becomes a building instead of a single point of failure.
That isn’t an argument for moving everything to the cloud regardless of cost. Some systems belong on site. It’s an argument for knowing which of your systems tie you to a specific building, and making that a decision rather than an accident.