Wildfire and Earthquake Business Continuity Planning: A California-Specific Disaster Recovery Guide
The math is unforgiving: FEMA's data shows roughly 40% of businesses never reopen after a disaster, and another 25% of those that do close within a year. A separate, oft-cited SBA figure puts the number closer to 90% for small businesses hit hard enough. Either way, the pattern is consistent — companies unable to resume operations within five days of a disaster face a 90% failure rate within twelve months. For California businesses, that five-day window is no longer a worst-case scenario. It's an operating assumption. Between wildfire, Public Safety Power Shutoffs (PSPS), and a seismic hazard that USGS rates at over 99% probability for a magnitude 6.7+ event somewhere in the state over the next 30 years, the question isn't whether your business will face a multi-day disruption — it's whether you'll still be standing afterward.
The January 2025 Palisades and Eaton fires reset the baseline for what "worst case" means in California. Combined, they burned more than 57,000 acres, destroyed over 18,000 structures, killed 31 people, and forced 200,000+ evacuations. Munich Re calculated $53 billion in total damages, $40 billion of it insured, making it one of the costliest wildfire events on record — with business disruption inside the fire perimeters alone projected to cost the regional economy $4.6–8.9 billion in lost output through 2029. San Diego County is not exempt from this risk profile just because it hasn't had a Palisades-scale event. Cal Fire's live statistics dashboard (fire.ca.gov/our-impact/statistics) tracks thousands of ignitions statewide every year, and the driving conditions — Santa Ana winds, drought-stressed vegetation, low humidity — recur across every fire-prone corridor in the state, North County included.
Even businesses that never see flames can lose power for days through a Public Safety Power Shutoff. In January 2025 alone, SDG&E flagged 83,609 customers for a possible shutoff ahead of forecasted Santa Ana winds — a single notification cycle, in San Diego County specifically. PSPS notices typically begin 7–10 days before a potential de-energization, moving through staged alerts to critical facilities, medical-baseline customers, and government agencies before reaching general commercial accounts. The CPUC's public PSPS dashboard (cpuc.ca.gov/psps) and each utility's mandatory post-season reports are the best sources for circuit-level outage history, because duration varies enormously by tier and location rather than following one statewide average. The practical takeaway for a California business anywhere in a utility's PSPS territory: PSPS is a recurring, planned event, not a rare emergency — which means it's exactly the kind of risk a continuity plan can and should be built around in advance.
Wildfire dominates headlines, but California's seismic exposure is arguably the more certain long-term threat. USGS's UCERF3 model — maintained jointly with the California Geological Survey and the Southern California Earthquake Center — puts the probability of a magnitude 6.7+ earthquake somewhere in California at over 99% within 30 years, with a 75% chance of a magnitude 7.0+ event. For San Diego County specifically, the Rose Canyon Fault runs directly beneath downtown San Diego, Balboa Park, and Old Town, with an offshore extension carrying tsunami potential; USGS slip-rate studies put its activity at roughly 2.4 mm/year. Further inland, the Elsinore Fault Zone is capable of a magnitude 7.8 rupture and hasn't had a major event since the 1700s — a recurrence interval seismologists estimate at 250–600 years, meaning it may be overdue. A magnitude 5.2 quake near San Diego in April 2025, linked to the Elsinore system, was a reminder that this isn't abstract risk.

One meaningful defense is now built into the state's infrastructure: ShakeAlert, the USGS-operated earthquake early warning system covering California, Oregon, and Washington. As of October 2025, over 95% of the statewide sensor network is installed, with full build-out targeted for December 2026. Alerts reach the public through Wireless Emergency Alerts, the MyShake app, and California's Get Alerts portal — but the more interesting angle for businesses is automation. USGS licenses "Alert Delivery Partners" who can trigger protective actions the instant a ShakeAlert message fires: automatically starting backup generators, releasing fail-safe door locks, triggering PA announcements, or shutting down sensitive equipment before shaking arrives. That's not a consumer feature — it's a low-voltage integration opportunity. A facility with the right access control, generator start, and notification wiring in place can convert a few seconds of warning into a genuinely useful operational buffer instead of wasted lead time.
California's building and fire codes already assume power will fail, and they set minimums accordingly — minimums that often fall short of what a multi-day PSPS event actually demands. NFPA 72 requires fire alarm systems to maintain secondary power for at least 24 hours in standby, then power all notification appliances for a further 5 to 15 minutes; batteries must fully recharge within 48 hours of a full discharge. If a generator provides secondary power instead of batteries, the standby requirement drops to 4 hours, since a generator is assumed more reliable. Given that PSPS events can run well beyond 24 hours, that code minimum is a floor, not a target. Access control systems face a similar gap: typical UPS-backed runtime is 15–60 minutes unless specifically sized larger, and while UL 294 recognizes standby power requirements at higher certification levels, extended battery backup for access control is best practice, not a universal mandate — which is exactly why so many buildings get caught out.
Business continuity planning benchmarks in California should also account for a regulatory clock that starts ticking the moment a disaster compromises your systems. SB 446 amended the CCPA's breach notification rule so that covered businesses must notify affected California residents within 30 calendar days of discovering a breach, effective January 1, 2026, with Attorney General notification due within 15 days after that. If a wildfire or earthquake destroys on-premises servers or backup media holding unencrypted personal information, that event can trigger the same 30-day clock as a cyberattack — there's no disaster exception. Separately, new CPPA cybersecurity audit and risk-assessment rules phase in starting January 1, 2026, with audit deadlines running from 2028 through 2030 depending on company revenue. The compliance argument for encrypted, offsite backups isn't hypothetical anymore; it's now directly tied to a statutory notification deadline.
The insurance market is quietly signaling how serious California regulators consider this risk. The California FAIR Plan — the state's insurer of last resort — grew 44% year-over-year to roughly 668,600 policies by the end of 2025, up from just 124,000 in 2019, a more than fivefold increase in six years. FAIR Plan rates are set to rise 29.1% in late 2026. The state has responded by expanding FAIR Plan commercial coverage limits to as much as $20 million per location (with a new high-value option up to $100 million aggregate) specifically to serve businesses, HOAs, and developments that can no longer get standard-market coverage in high-fire-risk areas — relevant for multifamily and affordable housing developers navigating California's insurance crunch. Two caveats matter here: FAIR Plan commercial policies are named-peril only, not all-risk, and earthquake coverage is never included in a standard commercial property policy — it must be purchased separately, exactly like the residential CEA model.
Despite all of this, planning maturity lags badly behind the risk. Only 54% of organizations have an established, company-wide disaster recovery plan, and just 30% of small businesses have any documented resilience strategy at all. Worse, roughly 60% of businesses that do have a DR plan never test it annually, and only 24% qualify as having a genuinely "mature" plan — well-documented, tested, and kept current. The cost of that gap is steep: Gartner puts average downtime costs around $5,600 per minute across all organizations, while small businesses in retail and services face estimated downtime costs of $50,000–$100,000 per hour once systems go dark. IBM's 2024 Cost of a Data Breach Report puts the average total cost of a breach at $4.88 million. Cloud backup adoption has become close to universal — about 93% of small and mid-sized businesses use it in some form — but adoption alone isn't the same as a tested, disaster-specific recovery plan with defined recovery time and recovery point objectives (RTO/RPO) for each critical system.
A useful planning framework is NFPA 1660 (2024), the consolidated successor to the long-standing NFPA 1600 continuity and emergency management standard — still the name most people search for, and worth knowing even if the underlying document has been folded into the newer, broader standard. Rather than a single blanket RTO for the whole business, effective plans set RTO/RPO targets per system based on criticality: mission-critical systems might need an RTO around 15 minutes and RPO around 5 minutes, while non-critical supporting systems can tolerate an RTO of several hours. Many California employers are also now layering a written Workplace Violence Prevention Plan (required under SB 553 and Labor Code §6401.9 since July 2024, with Cal/OSHA penalties up to $162,851 for willful violations) into the same emergency planning cycle as their natural-disaster response — a sign that continuity planning in this state increasingly means one integrated plan covering multiple hazard types, not a wildfire binder sitting separately from an earthquake binder sitting separately from a workplace safety plan.
None of this is theoretical for Mytek Pros. As a licensed low-voltage contractor (License #1116987) with DIR public-works registration (PW-LR-1001158430, BICSI certified) and managed service provider based in Carlsbad, we design and install the physical infrastructure this article describes — structured cabling, fire alarm systems built to NFPA 72 standby requirements, access control with extended battery runtime, and CCTV/surveillance systems that stay operational through a PSPS event — alongside the managed IT side: cloud backup and disaster recovery, managed security, managed WiFi with cellular failover, and VoIP/UC systems designed to keep phones working when the grid doesn't. For clients in regulated industries, we also support HIPAA, SOC 2, CMMC, and NIST-aligned audits so that data protection and compliance obligations (including CCPA's 30-day breach notification clock) are addressed as part of the same continuity plan, not bolted on afterward. Managed IT services typically run $125–$250 per user per month depending on scope — a modest, predictable cost against the alternative of a five-day outage. If your business, multifamily property, or affordable housing development in California hasn't stress-tested its wildfire and earthquake continuity plan, contact Mytek Pros at (619) 353-5702 or inquire@mytekpros.com.
Questions about it services? Get in touch or explore our IT Services.
