Disaster Recovery Planning for Small Businesses

Image: fauxels via Pexels
Most conversations about disaster recovery start with the wrong question. “Do we have backups?” is easy to answer, and the answer is nearly always yes. The harder question — the one that decides whether a bad week turns into a bad year — is “how long until we’re trading again, and how much work will we have lost?”
That is what a disaster recovery (DR) plan is actually for. Not the backup software, not the storage — the plan is the part that turns “our data exists somewhere” into “we were back on our feet by Thursday lunchtime.”
Agree on Two Numbers Before You Buy Anything
Sit down with the people who run the business, not only the people who run the IT, and settle two figures:
- How long can we be down? (Your Recovery Time Objective.) For a law firm mid-settlement, or a clinic with a full waiting room, the honest answer is often hours rather than days.
- How much work can we afford to redo? (Your Recovery Point Objective.) If your backup runs nightly, you have already accepted losing up to a day’s work. That may be entirely reasonable — as long as it is a decision rather than an accident.
Nearly every other choice follows from those two numbers: where data lives, what you spend, how often it copies. Skip them and you tend to over-protect systems you could live without, while the one system that would actually stop you trading sits on a nightly job nobody has tested.
Three Copies Is No Longer the Standard
The familiar 3-2-1 rule — three copies, two media types, one offsite — has quietly gained a fourth digit. The NCSC now recommends a 3-2-1-1 model: three copies, on two different media types, with one held offsite and at least one held offline.
That last copy matters because modern ransomware goes looking for your backups first. If your backup target sits on the same network, reachable with the same credentials as everything else, treat it as part of the blast radius rather than as your way out of it. An offline or immutable copy is usually the difference between restoring and negotiating.
The Restore Is the Plan. Everything Else Is Preparation
A DR plan nobody has rehearsed is a hypothesis. The NCSC sets a sensible bar for smaller organisations: test restoring a single file at least quarterly, and run a full restoration test at least once a year. Time yourself while you do it. The number you get is your real recovery time, and in our experience it is nearly always longer than the one written in the plan.
Decide Now Who Decides
Half of a good DR plan has nothing to do with technology. Who declares an incident? Who talks to clients, and from which address if your own email is down? Who has the key phone numbers when the system holding them is encrypted? Put it on a single page, print it, and keep a copy somewhere that needs neither power nor a login.
The NCSC responded to 1,164 incidents in the first quarter of 2026, including three it graded “highly significant” — the first of that severity it has recorded since 2021/22 (NCSC Quarterly Cyber Security Insights). Most organisations will never appear in those figures. The ones that recover quickly are simply the ones who worked out the answers before they needed them.
If you would like a hand pressure-testing your current backup and recovery setup — or simply want someone to sit down and put those two numbers on paper with you — our team is always happy to help.
Simon Falconer
Director, Resolve Technology
When he’s not finding a reason to buy the latest gadget, Simon is probably setting it up, breaking it, and fixing it again — all before breakfast.
Need help with this?
Resolve Technology can help. Learn more about our SmartManage Managed IT and Cyber Security Services services, or get in touch to discuss your needs.
