How do you create a disaster recovery plan for a small business?
Build it in seven steps: list what the business genuinely cannot run without, decide how long you can be without each and how much data you can lose, write down who does what, record where the backups are and how to restore them, keep contact details reachable when systems are down, test it, and review it twice a year.
Most guidance on this subject is written for organisations with a business continuity manager, which is why it produces documents small businesses never finish. What follows is scaled for a ten to fifty person business where the person writing the plan also has a day job, and where the plan's real test is whether someone can follow it at seven in the morning with the phones ringing.
Step one, list what you cannot run without, and be ruthless. Most businesses have three to five genuinely critical systems and a long tail that can wait a week. For a practice it is the clinical system and the phones; for a builder it is job management and the plans; for an accountant it is the ledger and the document store. Rank them, because the ranking is the plan: in a real incident you cannot restore everything at once, and deciding the order under pressure is how the wrong thing gets restored first.
Step two, put numbers against each one. How long can you be without it before the damage is serious, and how much recent work can you afford to lose? Those two questions are your recovery time and recovery point objectives, and they matter because they size everything downstream. A four-hour tolerance and a twenty-four hour tolerance are different products at different prices, and choosing without deciding this means paying for the wrong one in one direction or the other.
Step three, write down who does what, with names and mobile numbers, and a deputy for each name. Who declares that this is an incident, which sounds trivial and is the step businesses most often stall on. Who calls the IT provider. Who tells staff, and by what route if email is down. Who talks to customers, and who is authorised to speak if they are unreachable. Who contacts the insurer, because most cyber policies require prompt notification and some require it before remediation begins.
Step four, record the recovery detail itself: where each system's backups live, who can access them, roughly how long a restore takes, and what has to come back first for the rest to work. That last dependency point is where untested plans fall over, because the file server is useless until the domain controller is up and the line-of-business app is useless until the database is back. Include the boring credentials question too: if your password manager is inside the systems that are down, the plan needs an answer for that today, not on the day.
Step five, keep the plan reachable when everything is off. A disaster recovery plan stored only on the file server is a joke with a long setup. Printed copy, phone copy, a copy with your provider. Step six, test it, and a tabletop test counts: an hour in a room walking through a scenario out loud will find more holes than another month of drafting, and the holes it finds are usually contact details, dependencies and assumptions about who knows what. Then test a real restore at least annually, because the plan and the backups have to be true at the same time.
Step seven, review twice a year and after any significant change, because plans rot quietly. Staff leave, systems move to the cloud, phone numbers change, and the version that was accurate in March is fiction by November. Date it, name an owner, and diarise the review, since an out-of-date plan is worse than none: it produces confident wrong actions.
Two honest caveats. A plan is not resilience; it is coordination. If the underlying backups are untested and the systems have a single point of failure, the plan will document your way to a bad outcome faster. And the goal is not the document, it is the thinking, which is why a rough plan written by the people who would actually run it beats a polished one written by someone who would not. Energy Logistix runs 24/7 across five sites on infrastructure built for this, and the plan and the architecture were designed together rather than one bolted onto the other. If you want yours written and tested properly, call 1800 456 567.
Write the plan before you need it
We build disaster recovery plans that name the systems, the order, the people and the numbers, then test them so they work on the day.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business