Here’s an uncomfortable exercise: imagine your main server — or your cloud account — is gone as of 8am tomorrow. Ransomware, hardware failure, theft, fire; the cause doesn’t matter. How long until your team can work again? How much recent data is lost forever? If the answers are “no idea” and “no idea”, you have backups but not disaster recovery — and the difference is measured in days of lost trading.
Backups ≠ disaster recovery
A backup is a copy of your data. Disaster recovery (DR) is the plan and capability to get your business operating again — systems rebuilt, applications running, staff connected, customers served. Restoring 2TB of data means little if there’s no server to restore it to, nobody knows the admin passwords, and the software licences were in the mailbox that’s also gone.
Two numbers define your plan
RTO — Recovery Time Objective: how quickly you need to be running again. For some businesses a day offline is an inconvenience; for others, every hour is lost revenue and reputational damage.
RPO — Recovery Point Objective: how much data you can afford to lose. Nightly backups mean up to 24 hours of work can vanish. If re-capturing a day’s invoices and orders is unthinkable, you need more frequent protection.
Tighter numbers cost more. The point of DR planning is choosing those numbers deliberately, based on what downtime actually costs your business, rather than inheriting whatever your current setup happens to deliver.
What a practical SME DR plan contains
- An inventory of what matters. Which systems, in what order? Email, accounting and the line-of-business app usually come before the archive server.
- Recovery methods per system. Restore to replacement hardware? Spin up backup images as virtual machines? Fail over to a cloud replica? Each has different cost and speed — match them to each system’s RTO.
- The information nobody thinks about. Admin credentials, licence keys, vendor contacts, DNS access, ISP account details — stored securely outside the environment they protect.
- People and communication. Who declares a disaster? Who calls the IT provider, the insurer, the customers? Where do staff work from if the office is inaccessible?
- Connectivity resilience. Recovery increasingly happens over the internet — cloud restores, remote work, hosted apps. A failover internet link (LTE/5G behind your fibre) is itself part of DR.
Then test it
An untested DR plan is a document, not a capability. You don’t need a full-scale fire drill — restore one critical system to alternate hardware, or run a tabletop walkthrough of the ransomware scenario, once or twice a year. Every test finds something: an expired password, an unbacked-up folder, a step that only lives in one person’s head. Better to find it on a Tuesday afternoon than during the real thing.
The bottom line
DR isn’t an enterprise luxury anymore. Modern backup platforms with instant virtualisation and cloud recovery have brought serious recovery capability into SME budgets. The businesses that survive major IT incidents aren’t the lucky ones — they’re the ones that decided, in advance, exactly how they’d come back.
We build and test disaster recovery for SMEs as part of our managed IT services — from defining your RTO/RPO to running the annual recovery test. Start with a conversation about what downtime really costs you.
