Business Continuity

When the Network Goes Down, the Business Shouldn’t: The BCM Lesson from the Telstra Outage

The Telstra outage showed why BCM must map critical dependencies and test real workarounds before disruption exposes operational gaps.

Alex Roberts·July 2026·3 min read
When the Network Goes Down, the Business Shouldn’t: The BCM Lesson from the Telstra Outage

A major telecommunications outage is rarely viewed as a business continuity event until the phones stop working, payments fail, trains are delayed, customers cannot be contacted, and emergency channels become uncertain.

That is the real lesson from the recent Telstra outage in Australia. It was not only a technology failure. It was a live test of how dependent modern organisations have become on always-on connectivity, and how quickly operations can break down when that dependency is not properly understood, mapped and tested.

Telstra confirmed that the outage began after maintenance on a network server used to keep time synchronised across parts of its mobile network. The server restarted with the wrong date, causing intermittent impacts to voice and data services. At its peak, Telstra said approximately 45% of calls and data sessions on its mobile network were affected.

The wider impact was immediate. ABC reported that regional train services in NSW and Victoria were suspended, taxi passengers experienced payment problems, payment systems were affected, the ACT’s MyWay+ ticketing system was impacted, and hundreds of traffic lights in South Australia reverted to basic programming rather than responding dynamically to traffic conditions.

This is what a hidden operational dependency looks like.

For many businesses, mobile connectivity is not treated as critical infrastructure. It is simply assumed to be there. EFTPOS terminals connect through it. Staff communicate through it. Field teams rely on it. Customers are contacted through it. Ticketing, transport, logistics, monitoring and emergency escalation processes often depend on it. Yet when the network failed, many organisations were left trying to improvise continuity in real time.

That is not resilience. That is reaction.

The BCM Issue Is Not the Outage. It Is the Dependency.

Every organisation accepts that suppliers may fail, systems may go offline and external infrastructure may be disrupted. The purpose of business continuity management is not to prevent every external failure. It is to ensure the organisation can continue operating at an acceptable level when those failures occur.

The Telstra outage showed that many organisations may understand their technology stack, but not necessarily their operational dependencies. There is a difference.

Knowing that your business uses Telstra is one thing. Knowing which critical services fail when Telstra mobile voice, data, SIM-enabled devices, payment terminals, transport communications and staff escalation channels degrade at the same time is something else entirely.

That is where a mature BCM process adds value.

What Different Organisations Should Have Been Asking

For retailers, cafés, taxis and small businesses, the key question is simple: can we still trade if mobile EFTPOS fails? ABC reported that Tyro, which services almost 80,000 customers, was aware that some businesses could not connect payment machines operating on 4G networks.

A practical BCM response would include payment terminals with alternate connectivity, a clear cash or delayed-payment process, staff instructions for degraded trading conditions, and customer communication scripts.

For transport operators, the question is broader: can we safely operate if our communication network is degraded? If radio networks, ticketing systems, passenger updates or operational control channels rely on a single telecommunications pathway, then the continuity plan needs tested fallbacks, not just an escalation contact list.

For government and public-facing services, the issue becomes even more critical. Telstra stated that 58,835 Triple Zero calls connected successfully during the outage, but it also completed 604 welfare checks where calls were identified as unsuccessful.

That should prompt every emergency-facing organisation to ask whether it has tested alternate communication pathways, multi-carrier devices, public messaging protocols and escalation procedures for situations where primary mobile services are unavailable.

For professional services, legal practices and customer-facing organisations, the BCM lesson is equally practical: can staff still contact clients, receive instructions, confirm appointments, access systems and continue urgent work if the primary mobile network is down for half a day?

The Root Cause Also Matters

The Senate inquiry added another important dimension. Reuters reported that Telstra’s CEO told the inquiry the outage was likely caused by an undocumented design change and a missed software update on a network time-keeping device. The maintenance team was reportedly unaware of how the equipment would behave when restarted because the design change had not been properly documented.

That is not only a technical issue. It is a governance issue.

It speaks to change management, documentation, control ownership, maintenance procedures, risk prioritisation and assurance. The same principles apply inside any organisation. When critical dependencies are poorly documented, continuity plans become theoretical. When known risks are not tracked to closure, resilience becomes luck.

How a Proper BCM Process Would Have Helped

A strong BCM programme starts with a business impact analysis. This identifies which processes are truly critical, what they depend on, how long they can be unavailable, and what workarounds are required.

From there, organisations should map dependencies across telecommunications, payment systems, cloud services, third-party providers, field operations, customer contact channels and emergency escalation procedures.

The next step is scenario testing. Not a generic “system outage” exercise, but a specific and realistic scenario:

Our primary telecommunications provider is unavailable for six hours during peak operations. What breaks first?

That test should answer practical questions. Can we take payments? Can we contact staff? Can we update customers? Can we operate safely? Can we switch to another provider? Can key personnel access systems? Do people know what to do without waiting for executive approval?

Finally, the plan must be maintained. Contact lists, supplier arrangements, manual workarounds and escalation procedures become outdated quickly. BCM is not a document stored in a folder. It is an operational capability that must be reviewed, tested and improved.

The Bottom Line

The Telstra outage is a reminder that business continuity is not only about cyber attacks, floods, fires or pandemics. Sometimes the disruption is a mobile network. Sometimes it is a payment terminal. Sometimes it is a time synchronisation server most people in the business have never heard of.

The organisations that cope best are not the ones that assume critical services will always be available. They are the ones that know what they depend on, understand what happens when those dependencies fail, and have tested how they will continue operating when they do.

BCM is not about predicting the next outage.

It is about being ready when the outage exposes what your business was relying on all along.

About the author

Alex Roberts

Alex Roberts

Head of GTM

What excites me most is using tech and AI to solve real-world challenges - creating smarter, more efficient ways for organisations to grow and adapt. I love connecting with others who share a passion for what’s possible through innovation.

LinkedIn profile

See the platform behind the intelligence.

Unify Today turns these insights into operational reality, continuous risk sensing, automated compliance, and board-ready intelligence.