Most operations can fail over. Far fewer can come back cleanly, inside the window they’ve promised someone. That difference usually shows up exactly once.
The question this answers. Not “is there a generator.” The real questions are what must not stop, what it quietly depends on, how long you can actually be down, and whether that’s inside what you’ve committed to a customer, a regulator, or an insurer. Most operations have never written down the first one. The list is usually shorter than people expect, and shortening it is free.
There are two ways to improve continuity, and only one is expensive. Reduce the consequence of failure: make less of the site critical, and shorten how long recovery takes. That’s cheap, fast, and almost always available.
Reduce the probability of failure: redundancy, N+1, duplicate everything. That’s expensive, slow to approve, and what most people reach for first.
We work the first list before the second. A client who can’t fund full redundancy can very often fund the cheaper work, and the cheaper work moves the number that actually matters, which is how long you’re down.
What that looks like in practice. Reduce what has to be protected: rank what is genuinely critical, and separate those circuits so you’re protecting a subset rather than a building. Everything downstream gets cheaper because there is less of it.
Collapse the restoration window: pre-terminated cabling and an interlocked manual changeover, so an alternative supply connects in minutes instead of being improvised over days. Physical access and standing space designed in, so a hired unit can actually be placed. A standby agreement with a stated response time is what turns the space and the plug into a capability rather than an intention.
Design for the substitute you can actually get. In an emergency you get what’s on the hire yard, not what the drawing specifies. Contingencies that only work with exactly the right unit fail at the moment they’re needed. Ours degrade: three-phase if it’s available, and the critical loads moved onto a single phase if it isn’t. Then, if it’s still warranted, redundancy.
Testing, and where we stop. A plan that has never been exercised is a document, not a capability. We verify engineered systems: component tests, transfer sequences, live transfer under load where you accept it, and a timed restoration test measured against the window you’ve committed. That last one is the one most often skipped, and the one most worth doing.
Every test beyond the trivial has a written plan, an abort condition, a rollback, an agreed window, and a named person on your side who can stop it. A test that causes the outage it was meant to prevent is a foreseeable failure, not bad luck.
Drills involving your people are yours, not ours. Evacuation, emergency response, tabletop exercises: those sit under your policy, your governance, and your local labour and safety law, and none of that is ours to direct. We will specify what should be drilled and how often, and attend as technical witness. We will not schedule your staff or advise you on employment law.
Being straight about where we are. Our electrical continuity work is well established: backup power, load priority, failover, and delivery into zero-tolerance environments under contractual deadline.
The formal documentation, testing and process side of this practice is newer. We will tell you which parts of any engagement rest on long experience and which rest on sound practice we are building a track record in. In this field in particular, you are buying judgement about failure, and overstating experience is not something anyone recovers from.
Worth 30 minutes?