Answer
Network paths and remote access deserve the closest scrutiny because they are the piece most often assumed rather than verified. A secondary site with current data but no tested route for staff to reach 5250 sessions, no validated VPN profiles, and firewall or exit point rules that were never updated to match the recovery environment will strand a technically successful recovery. Buyers should confirm these paths are tested under realistic conditions, including staff connecting from home or an alternate office rather than from inside the primary data center.
Backup and replication currency should be checked against the documented RPO, not assumed from a green status light. Application dependencies, meaning every interface, batch job, and third-party connection the business application relies on, need to be inventoried and confirmed reachable from the secondary site specifically. And the human dependency is often the weakest link: a runbook that depends on one administrator who happens to know an undocumented workaround is not a ready site, it is a single point of failure with a data center attached. Buyers should ask how the DR platform tracks readiness across these dimensions together, rather than reporting replication health in isolation from everything else recovery actually requires.