Direct answer
Continuity is advertiser-owned, not a promise Meta, Google, TikTok, bank, or agency will keep spend running. Map critical services/dependencies, assign decision rights, preserve evidence, set organization-defined targets for owned actions, and rehearse. Treat other accounts, cards, agencies, and platforms as common-mode dependencies until links are tested. Accept recovery after custody, finance, measurement, security, and monitored restart pass; provider timing remains dependent. Synthesis/inference. [RS-S08][RS-S09][RS-S17][RS-S18]
Who this is for
Fit: executives, finance/security owners, and operators responsible for material Meta, Google Ads, or TikTok spend across entities, regions, managers, payment profiles, domains, datasets, vendors, or automation.
Non-fit: routine low-risk setup with healthy owner access; campaign optimization; evasion, identity/payment rotation, rented accounts, forged records, credential sharing, or guaranteed reinstatement. Use official platform guidance or appropriate bank, security, legal, insurance, or privacy professionals. [PR-P07][PR-P10][DRS-A03]
Labels/routes are not universal. PR-P14 covers TikTok verification documents by country/region; PR-P15 covers transaction-appeal eligibility case by case and by account type. Recheck the current first-party route for the affected account and record its label, eligibility, requirements, and access date. [PR-P03][PR-P10][PR-P11][PR-P13][PR-P14][PR-P15]
Decision model
1. Define critical services and assets
Start with the business service, not account label. Record the minimum service needed to operate safely:
| Service | Critical assets and evidence | Business impact if unavailable | Restoration owner |
|---|---|---|---|
| Spend authorization and pacing | Budgets, caps, change ledger, approvals, platform billing profile | Unauthorized spend, missed demand, finance uncertainty | Finance owner plus asset owner |
| Platform access and custody | Owner identity, portfolio/manager, ad accounts, partner links, recovery contacts, sessions | Loss of control, inability to export or stop changes | Asset/security owner |
| Delivery and campaign control | Campaign/ad objects, creative, audiences, catalog/feed, policy state | Lost or constrained demand; state remains unclassified | Operations executor; provider decides platform state |
| Measurement and lead flow | Pixel/dataset, CAPI/Events API, tags, consent, analytics, CRM, backend settlement | Bad decisions from stale or mismatched signals | Measurement owner |
| Billing and reconciliation | Invoices, transaction IDs, bank/card records, agency invoices, legal entity | Dispute, suspension risk, cash-flow ambiguity | Finance owner |
| Communications and evidence | Incident register, UTC timeline, exports, notices, case IDs, contact tree | Poor handoff, weak escalation record, lost learning | Recorder/comms owner |
The table is an operating synthesis. Login, dashboard, script, or support response is an observation, not proof of ownership, persistence, billing, delivery, or settled outcome. Google documents best-effort scripts; provider/user views can differ. [BC-S06][RS-S07][RS-S19]
2. Tier business impact without universal thresholds
Use organization-defined tiers, not generic dollars or probabilities:
- Tier 1 — critical: unauthorized activity, lost full-control custody, payment exposure, cross-tenant/data-integrity concern, or interruption threatening a material obligation. Freeze risky changes within authority and convene named roles.
- Tier 2 — material: delivery, reporting, measurement, verification, or partner failure affecting a material program with a verified owner and safe containment path. Open an incident and set a next decision point.
- Tier 3 — contained: isolated reversible issue with healthy custody, no suspected compromise, and a current first-party route. Run the control and document the result.
Tier is a decision aid, not a loss estimate or provider severity; update as evidence changes. Synthesis/inference. [RS-S08][RS-S09][DRS-A03]
3. Use planning objectives only for what the organization controls
Populate fields from baseline and approved risk appetite:
Target acknowledgement: [organization-defined minutes]
Target decision to freeze risky owned changes: [organization-defined minutes]
Target evidence capture / export: [organization-defined minutes]
Target restore of advertiser-owned telemetry: [organization-defined hours]
Target finance reconciliation or named residuals: [organization-defined hours]
Target recovery-point objective for owned exports/logs: [organization-defined cadence]
These are organization-defined planning inputs, not universal targets, platform SLAs, review windows, delivery promises, reimbursement terms, or ROAS commitments. Use them only after they are measured, staffed, and tested; provider-dependent recovery remains “unknown/provider-dependent.” [RS-S08][RS-S11][RS-S12]
Diagnostic or control sequence
-
Declare service/tier. Input: symptom, platform/product, entity, region, IDs, first-seen UTC, last-good state. Owner: incident lead. Action: record one factual sentence without cause. Stop/branch: missing authority/scope means preserve visibility and assign verification; do not make destructive changes. [DRS-A01][DRS-A03]
-
Map custody/concentration. Input: owner/full-control flags, managers/Business Portfolios, partners, billing/payment, domain, dataset, catalog/feed, tokens, apps, scripts, vendors, approvers. Owner: asset owner with security/finance. Action: map parent-child/shared edges as controlled, observed, provider-dependent, or unknown. Stop/branch: if a change touches another campaign/entity/customer, stop for owner-approved rollback. IDs do not prove independence. Synthesis/inference. [RS-S17][RS-S18][RS-S23][BC-S09]
-
Capture before change. Input: raw label/error, exports, notices, request/status/case IDs, permissions, payment state, recent changes, event samples. Owner: recorder/evidence owner. Action: preserve UTC timeline, collector, location, access, and unavailable-data note; use read-only/immutable copy where feasible. Stop/branch: do not revoke, delete, relink, wipe, or rotate shared objects before preservation unless narrowly approved active-risk containment is required. [DRS-A01][DRS-A03]
-
Check independent signals. Input: product status/history, second admin, UI/API comparison, clean endpoint, delivery/event telemetry, CRM/backend, bank/card, customer symptom. Owner: operations and measurement owners. Action: compare signals and maintain an alternative hypothesis. Stop/branch: Meta Status is client-rendered; capture per-product (Ads Manager creation, delivery, reporting, APIs) status live for the target region and date rather than relying on a top-level green/red reading. Green status or dashboard silence does not prove account, regional, API, or downstream health. [PR-P01][PR-P09][RS-S07][RS-S19]
-
Contain reversible risk. Input: authorized change matrix, expected state, rollback condition, blast-radius map. Owner: operations executor; incident lead approves. Action: pause/cap unauthorized-risk spend, freeze nonessential automation, or revoke one identified suspect session/token from a clean endpoint; record read-back. Stop/branch: conflict, scope expansion, or unclear authority stops the change. [RS-S09][BC-S06][DRS-A01]
-
Communicate through alternatives. Input: contact tree, decision rights, official route, case ID, finance/issuer path, known-good channel. Owner: communications owner. Action: use the incident channel, then an approved out-of-band phone tree, secure collaboration channel, or alternate email if it fails; notify owners by tier. Stop/branch: inbound “recovery” contacts are unverified; navigate directly to platform domains and never send secrets. [DRS-A03][BC-S18]
-
Use the current official route. Input: account/region-specific policy, billing, verification, suspension, or compromise state. Owner: platform liaison with owner approval. Action: submit one factual record and preserve case ID. Stop/branch: Meta review eligibility/fields vary by asset/region; re-open the current route. PR-P14 covers TikTok verification documents by country/region; PR-P15 covers case-by-case/account-type transaction appeals. Use the current first-party route; do not use remembered labels or “un-ban” offers. [PR-P03][PR-P10][PR-P11][PR-P13][PR-P14][PR-P15]
-
Reconcile finance and measurement separately. Input: billed, served, attributed, analytics/events, backend settled, bank/card, and agency ledgers. Owner: finance and measurement owners. Action: align entity, account, transaction, currency, dates, time zone, event definition, and settlement cutoff; record residuals. Stop/branch: unauthorized activity goes to platform and issuer/bank fraud routes; legitimate-balance disputes require reconciliation; agency mismatches are separate contract/finance questions (Synthesis/inference). [BC-S07][BC-S08][PR-P09][PR-P18]
-
Restore in priority order. Input: tier, dependency map, evidence index, approvals, provider unknowns. Owner: incident lead and asset owner. Action: safety/spend containment, custody/security persistence removal, billing, measurement/event path, limited delivery test, then normal scale. Stop/branch: no broad restart with unknown admin/token/domain/payment mutation, automation diff, or material finance residual. Synthesis/inference. [DRS-A01][RS-S09][RS-S10]
-
Accept, monitor, and learn. Input: acceptance checklist, test event/conversion, campaign/automation diff, finance reconciliation, monitoring, signatures. Owner: asset, finance, measurement owners and incident lead. Action: run a limited restart with a stop condition; monitor spend, delivery, events, access, and incident signal. Stop/branch: failed predicate returns the incident to containment; close only with residual owners documented. Synthesis/inference. [BC-S06][RS-S08][RS-S10]
Roles and decision rights
Roles: incident lead (priority), operations executor, recorder/comms (UTC), finance (billing/issuer), measurement (events/settled cohort), security/asset (custody), and platform liaison (case). Roles may combine, but separate high-impact approval from execution. Asset owner approves restart/closure; provider, issuer, counsel, insurer, and security responders decide in their domains. [RS-S09][DRS-A03]
Off-hours readiness and tabletop cadence
Do not imply 24/7 coverage, privileged support, or an SLA without a tested roster. Document contacts, authority, pre-authorized actions, “no authority” handling, and official/issuer fallbacks; use an approved cadence for takeover, payment lock, delivery-zero, reporting quarantine, regional interruption, provider outage, and contact failure; test restore/export and communication failover. This does not promise 24/7 staffing or emergency response. [RS-S11][DRS-A03][BC-S17]
Evidence to preserve
- Incident ID, reporter, tier, platform surface, region, entity, business symptom, UTC first-seen and last-known-good times.
- Account/portfolio/manager/campaign/ad/dataset/catalog/domain/payment/transaction/request/case IDs; exact label/error, policy/verification/billing state, owner/partner map.
- Before/after exports for campaigns, budgets, permissions, automations, feeds, events, billing, and reconciliation cohorts.
- Activity/audit logs, API responses, email headers, notices, support chronology, bank/card and agency invoices, event samples, unavailable-data notes.
- Collector/time/location, access list, retention/deletion owner, redaction decision, and hash or immutable-copy reference where feasible.
Screenshots supplement exports. Minimize personal/payment data; keep passwords, MFA codes, cookies, government IDs, full card numbers, and remote-control artifacts out of the register. [DRS-A01][DRS-A03]
What not to do
Do not create replacement accounts, rotate identities/payments to evade enforcement, rent accounts, cloak, use anti-detect tools, forge records, spam appeals, or manipulate support. Do not blindly rotate shared dependencies or relaunch after login alone. A status page, community post, or script log is not causal proof. [PR-P07][PR-P10][BC-S06][BC-S07][VOC-F01][VOC-F05]
When to escalate
Self-service: healthy owner access, one platform, low complexity, no compromise, reversible action, and clear first-party instruction.
Qualified specialist: material spend/client exposure, high time/enforcement uncertainty, and a cross-system boundary (custody, billing, security, measurement, vendor, or regional policy). Value: evidence, dependency mapping, controlled changes, reconciliation, and a factual official case—not provider influence.
Immediate referral: unauthorized financial activity to issuer/bank and platform; endpoint compromise to security; contract/legal/privacy/insurance questions to professionals; policy/review decisions to the current first-party route. No route guarantees recovery, timing, reimbursement, or delivery. [BC-S07][DRS-A17][DRS-A18]
FAQ
Is a second platform or account a continuity plan?
Not by itself. Shared identity, payment, domain, data, token, vendor, policy exposure, or approver can create common-mode failure. Test independence; diversification is not a guarantee. Synthesis/inference. [RS-S17][RS-S18][RS-S23]
What RTO or RPO should a high-spend advertiser publish?
None universally. Set internal acknowledgement, freeze, evidence, telemetry, and export-cadence targets from baseline and staffing. Provider review, auction delivery, and reimbursement remain provider-dependent. [RS-S08][RS-S11]
Does restored login mean recovery is complete?
No. Confirm owner access, remove persistence, review partners/apps/tokens/automations, validate dependencies/payment, reconcile finance/measurement, test, monitor, and close. Synthesis/inference. [DRS-A01][BC-S06][BC-S09]
Should finance immediately charge back an unexpected ad charge?
Classify it first. Route unauthorized activity to platform and issuer/bank fraud channels. Reconcile legitimate balances before dispute; agency mismatches are separate contract/finance matters (Synthesis/inference). [BC-S07][BC-S08]
How do we prepare for nights or weekends?
Document actual coverage, authority, pre-approved containment, out-of-band contacts, and official fallbacks; test contact-tree readiness. If staffing is unverified, say so and do not market emergency response. [RS-S11][DRS-A03][BC-S17]
Source appendix
Recheck the first-party route for the affected account/region; this guide does not guarantee current labels, route availability, eligibility, timing, or outcomes. PR-P14 covers country/region documents; PR-P15 covers case-by-case/account-type appeal eligibility.
| Key | Source title; author/publisher; publication date | URL | Access date |
|---|---|---|---|
| RS-S07 | Monitoring Distributed Systems; Rob Ewaschuk, Google SRE; 2017 | https://sre.google/sre-book/monitoring-distributed-systems/ | 2026-07-19 |
| RS-S08 | Service Level Objectives; Chris Jones, John Wilkes, Niall Murphy, Cody Smith, Google SRE; 2017 | https://sre.google/sre-book/service-level-objectives/ | 2026-07-19 |
| RS-S09 | Managing Incidents; Andrew Stribblehill, Google SRE; 2017 | https://sre.google/sre-book/managing-incidents/ | 2026-07-19 |
| RS-S10 | Postmortem Culture: Learning from Failure; John Lunney and Sue Lueder, Google SRE; 2017 | https://sre.google/sre-book/postmortem-culture/ | 2026-07-19 |
| RS-S11 | Business Continuity Planning; FEMA/Ready.gov, U.S. Department of Homeland Security; accessed 2026-07-19; specific last-updated date not exposed on page | https://www.ready.gov/business/emergency-plans/continuity-planning | 2026-07-19 |
| RS-S12 | ISO 22301:2019 Security and resilience — Business continuity management systems — Requirements; ISO/TC 292, ISO; 2019-10 publication; stage: International Standard to be revised [90.92] as of 2026-07-19 | https://www.iso.org/standard/75106.html | 2026-07-19 |
| RS-S17 | Mapping Disruption Sources in the Power Grid and Implications for Resilience; Maureen S. Golan and Javad Mohammadi; arXiv; 2022-07-17 | https://arxiv.org/abs/2207.08146 | 2026-07-19 |
| RS-S18 | Comparative Resilience Notions and Vertex Attack Tolerance of Scale-Free Networks; John Matta, Jeffrey Borwey, Gunes Ercal; arXiv; 2014-04-01 | https://arxiv.org/abs/1404.0103 | 2026-07-19 |
| RS-S19 | Characterizing User and Provider Reported Cloud Failures; Mehmet Berk Cetin, Sacheendra Talluri, Alexandru Iosup; arXiv; 2021-10-23 | https://arxiv.org/abs/2110.12237 | 2026-07-19 |
| RS-S23 | Resilience Analysis for Competing Populations; Artur César Fassoni and Denis de Carvalho Braga; arXiv; 2019-03-14 | https://arxiv.org/abs/1903.06291 | 2026-07-19 |
| PR-P01 | Status and outages of Meta business products; Meta; live/undated | https://metastatus.com/ | 2026-07-19 |
| PR-P03 | Request a review if you are restricted from advertising on Meta platforms; Meta; undated | https://www.facebook.com/business/help/530209463124901/ | 2026-07-19 |
| PR-P07 | Meta Takes Legal Action Against Scam Advertisers; Meta Newsroom; 2026-02-26 | https://about.fb.com/news/2026/02/meta-takes-legal-action-against-scam-advertisers/ | 2026-07-19 |
| PR-P09 | *History | Google Ads Status Dashboard*; Google; live/undated | https://ads.google.com/status/publisher/summary |
| PR-P10 | Google Ads account suspensions overview; Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/9841640?hl=en | 2026-07-19 |
| PR-P11 | Billing and payment suspensions; Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/13704200?hl=en | 2026-07-19 |
| PR-P13 | About suspended ad accounts on TikTok; TikTok for Business; updated June 2026 | https://ads.tiktok.com/help/article/account-suspensions?redirected=1 | 2026-07-19 |
| PR-P14 | How to verify your business on TikTok; TikTok for Business; updated May 2026 | https://ads.tiktok.com/help/article/about-business-verification?aadvid=72391499277 | 2026-07-19 |
| PR-P15 | About transaction-related appeals; TikTok for Business; updated July 2026 | https://ads.tiktok.com/help/article/about-transaction-related-appeals | 2026-07-19 |
| PR-P18 | Google Ads Experiencing Outage Impacting Key Features; Matt G. Southern, Search Engine Journal; 2024-08-01, updated 2024-09-19 | https://www.searchenginejournal.com/google-ads-experiencing-outage-impacting-key-features/523624/ | 2026-07-19 |
| BC-S06 | Errors and Warnings; Google Ads Scripts team; updated 2026-06-24 | https://developers.google.com/google-ads/scripts/docs/troubleshooting/errors | 2026-07-19 |
| BC-S07 | Billing and payment suspensions; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/13704200 | 2026-07-19 |
| BC-S08 | How to dispute a Google Ads charge; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/10560092 | 2026-07-19 |
| BC-S09 | Manager Accounts (MCC): About Google Ads manager accounts; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/6139186 | 2026-07-19 |
| BC-S17 | PagerDuty Incident Response Documentation; PagerDuty; current/undated | https://response.pagerduty.com/ | 2026-07-19 |
| BC-S18 | Tech (non)support: Scammers pose as Meta in Facebook account grab ploy; Sharef Hlal and Karam Chatra, Group-IB; 2023-04-25 | https://www.group-ib.com/blog/meta-phishing-campaign/ | 2026-07-19 |
| VOC-F01 | Payment Failed, Amount Due. Account Blocked META account; u/abdk1996, Reddit; 2026-07-19 | https://old.reddit.com/r/FacebookAds/comments/1v0hild/payment_failed_amount_due_account_blocked_meta/ | 2026-07-19 |
| VOC-F05 | Sole Business Portfolio admin permanently disabled; u/Exact_Kiwi3437, Reddit; 2026-07-16 | https://old.reddit.com/r/FacebookAds/comments/1uxske3/sole_business_portfolio_admin_permanently/ | 2026-07-19 |
| DRS-A01 | Digital Evidence Preservation: Considerations for Evidence Handlers; Barbara Guttman, Douglas R. White, Tracy Walraven, NIST; 2022-09 | https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8387.pdf | 2026-07-19 |
| DRS-A03 | Incident Response Plan Basics; CISA; undated | https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf | 2026-07-19 |
| DRS-A17 | NetDiligence Publishes Fourteenth Annual Cyber Claims Study; NetDiligence; 2024-09-17 | https://netdiligence.com/press-releases/netdiligence-releases-2024-cyber-claims-study/ | 2026-07-19 |
| DRS-A18 | Social Engineering Fraud Insurance; Vouch; 2026-04-13 | https://www.vouch.us/blog/social-engineering-fraud-insurance | 2026-07-19 |
Related resources
- Facebook Business Account Hacked — Recovery GuideYour Facebook Business account has been hacked. Unauthorized campaigns are running, your budget is being drained, and your pages may have been transferred. Here's how to regain control immediately.
- Google Ads Account Suspended for Billing — Fix GuideYour Google Ads account has been suspended due to a billing issue — failed payment, suspected fraud, or expired card. Here's how to identify the exact issue and get your account back.
- TikTok Ads Not Delivering? Diagnose Zero ImpressionsTikTok ads approved but not delivering or spending? Check delivery status, billing, schedule, audience, bid, budget, and creative before making changes.
- Meta Pixel Not Firing — Troubleshooting GuideYour Meta Pixel is not firing or firing inconsistently. Here's how to diagnose the issue, fix broken tracking, and restore your conversion data and retargeting audiences.
- Google Ads Suspension Recovery — The Full RoadmapA step-by-step roadmap for recovering from a Google Ads suspension: how to triage the suspension type, which appeal channel to use, realistic timelines, and what to do if the appeal fails.
- Platform Outage vs Account-Specific Problem: A Cross-Platform Incident ClassifierSeparate provider outages from account, reporting, local, and shared-dependency failures using path-distinct evidence and reversible controls.
- Agency Offboarding Without Losing Ad InfrastructureStage agency offboarding across Meta, Google, and TikTok without losing access, evidence, billing clarity, domains, feeds, datasets, or measurement.
- Ad Account Recovery Acceptance Checklist: Prove Operations Before Resuming SpendProve access, ownership, billing, dependencies, measurement, test delivery, monitoring, reconciliation, and closure before resuming ad spend.
- Shared Dependencies: Why Multiple Ad Accounts Can Still Fail TogetherMap common-mode identity, payment, domain, data, access, vendor, policy, and reporting dependencies before calling accounts resilient.
Contact AdsInfra
Send a message about this resource before making a high-impact change.