
September 11, 2001, is remembered first and foremost for the nearly 3,000 people who lost their lives, the families whose lives were forever changed, and the extraordinary courage demonstrated by first responders and ordinary citizens.
The attacks also created an unprecedented challenge for American businesses and the technology systems on which they depended. In a matter of hours, organizations were forced to confront difficult questions about communication, business continuity, data protection, remote operations, security, and disaster recovery.
Twenty-five years later, many of the business and technology practices we consider routine reflect lessons reinforced by that day and its aftermath.
When Communication Became Critical
On September 11, communication systems were placed under extraordinary pressure. Telephone networks became congested as millions of people attempted to contact family members, friends, employees, and coworkers.
For businesses, the experience demonstrated a fundamental weakness in relying on a single method of communication.
Today, organizations routinely maintain multiple communication channels. Mobile phones, text messaging, email, collaboration platforms, cloud-based applications, emergency notification systems, and remote-access technologies give businesses alternatives when one system becomes unavailable.
The lesson remains relevant: business communication needs redundancy.
If employees, customers, vendors, or emergency personnel cannot reach an organization through the normal channel, there should be another way to communicate.
Business Continuity Became More Than an IT Issue
Before 9/11, many organizations treated disaster recovery primarily as a technology department responsibility. Backups were important, but comprehensive business continuity planning was not always given the attention it receives today.
The attacks reinforced the reality that protecting a business requires more than simply backing up files.
Organizations need to consider questions such as:
- What happens if employees cannot reach the office?
- Can critical systems operate from another location?
- How will employees communicate during an emergency?
- Where are backups stored?
- Who has access to critical accounts and systems?
- Can customers continue receiving essential services?
- How quickly can operations be restored after a major disruption?
Business continuity is ultimately about keeping an organization functioning when normal operations are no longer possible.
Data Needed to Exist Somewhere Else
September 11 also reinforced an important principle of information technology: critical information should never exist in only one physical location.
A backup stored beside the computer or server it protects may be useful for recovering from hardware failure, but it provides little protection when an entire facility becomes inaccessible or is destroyed.
Off-site backups, geographically separated data centers, redundant infrastructure, and, eventually, cloud computing provided increasingly practical ways for organizations to distribute and protect their technology resources.
Today, even a small business can use cloud-based email, online accounting systems, cloud storage, automated backups, hosted websites, and geographically distributed infrastructure.
Technology capabilities that once required substantial corporate resources are now available to businesses of almost every size.
The Growth of Remote Access
In 2001, working remotely was technically possible, but it was far from the everyday business practice it has become.
The aftermath of 9/11 reinforced the need for organizations to operate even when employees could not physically reach their normal workplaces. Over the following years, VPNs, laptops, broadband Internet connections, mobile devices, hosted applications, and eventually cloud services made remote operations increasingly practical.
That evolution continued through other disasters and disruptions and accelerated dramatically during the COVID-19 pandemic.
Today, remote access is not simply an employee convenience. For many organizations, it is an important component of business continuity and disaster preparedness.
Security Changed
The attacks fundamentally changed how government agencies and private organizations approached physical security, infrastructure protection, information sharing, risk management, and emergency preparedness.
Businesses increasingly had to consider security as an interconnected issue rather than a collection of isolated concerns.
Physical access affects technology security. Technology security affects business continuity. Employee training affects cybersecurity. Vendor security affects organizational risk.
Modern businesses consequently have to think beyond antivirus software and passwords. Security includes access controls, multifactor authentication, employee awareness, backups, software updates, network protection, physical security, vendor management, incident response, and recovery planning.
Technology Cannot Replace People
One of the most enduring lessons from September 11 has little to do with hardware or software.
Technology can provide redundancy. It can preserve information. It can connect people across enormous distances. It can help organizations recover from disasters and continue operating during emergencies.
But technology does not replace leadership, preparation, judgment, courage, or human compassion.
Businesses learned that continuity plans need to account for people as much as equipment. Employees need ways to check on one another. Managers need procedures for determining whether employees are safe. Organizations need reliable methods of communicating with families, customers, vendors, and communities.
A technically sound disaster recovery plan is incomplete if it fails to consider the people who must carry it out.
What Small Businesses Can Learn Today
A small business may never face an event remotely comparable to September 11, but disruption comes in many forms.
A fire can make an office inaccessible. A ransomware attack can lock employees out of their computers. A storm can interrupt electricity and Internet service. A server can fail. A key employee can suddenly become unavailable. A cloud provider can experience an outage.
The scale may be different, but the underlying question is the same:
Can your business continue operating when something you depend upon suddenly becomes unavailable?
That question should influence how businesses approach backups, websites, email, cybersecurity, cloud services, documentation, passwords, remote access, communications, and disaster recovery.
Preparation does not mean attempting to predict every possible disaster. It means building enough resilience into an organization so that one unexpected failure does not become a business-ending event.
Building a More Resilient Business Today
The lessons reinforced by September 11 remain relevant to businesses of every size. While technology has changed dramatically since 2001, the need to protect information, maintain communications, and prepare for unexpected disruptions has not.
At Horner Consulting & Publishing LLC, we believe technology should do more than help a business operate efficiently—it should also help that business remain resilient when something goes wrong.
For small businesses, that means taking a practical look at several critical areas:
Cybersecurity: Protect computers, networks, websites, email accounts, and business information from increasingly sophisticated threats. Strong passwords, multifactor authentication, software updates, employee awareness, and appropriate security measures all contribute to reducing risk.
Website and Email Continuity: Your website and business email are often essential connections between your company and its customers. Proper hosting, domain management, account security, backups, and recovery planning can help keep those communications available when problems occur.
Cloud and Off-Site Backups: Important business information should never depend on a single computer, server, or physical location. A reliable backup strategy should provide additional copies of critical data and a practical, tested method for restoring that information when needed.
Disaster Recovery: Having backups is only part of the solution. Businesses should know how they will recover their systems, data, websites, and communications after a hardware failure, cyberattack, natural disaster, or other unexpected event.
Technology Planning: Business technology should be evaluated before an emergency exposes its weaknesses. Understanding which systems are critical, where information is stored, who has access, and what alternatives are available can make the difference between a temporary disruption and a prolonged shutdown.
Is Your Business Prepared?
You cannot anticipate every emergency, but you can prepare your business to respond when one occurs.
Horner Consulting & Publishing LLC has provided custom business and technology solutions since 1999. We help small businesses evaluate their technology, identify potential weaknesses, and develop practical solutions designed around the way they actually operate.
From websites and business email to backups, cybersecurity, technology planning, and disaster preparedness, the objective is simple: protect the technology your business depends on and help ensure your organization is prepared when the unexpected happens.
Twenty-Five Years Later
On this September 11, twenty-five years after the attacks, we remember the people who went to work that morning and never returned home. We remember the first responders who ran toward danger, those who helped strangers, and the families and communities that endured unimaginable loss.
For the business and technology communities, there is another responsibility within that remembrance: to learn.
September 11 demonstrated how quickly assumptions about normal operations can disappear. It reinforced the importance of communication, redundancy, security, backups, disaster recovery, and business continuity.
Technology has advanced enormously since 2001. Cloud computing, smartphones, broadband Internet, cybersecurity platforms, remote collaboration, and distributed infrastructure have transformed how businesses operate.
Yet the fundamental principle remains unchanged:
Prepare for disruption before disruption happens.
The best technology strategy is not simply about making a business faster or more efficient when everything is working properly. It is also about making that business resilient enough to continue when everything is not.
