Disaster recovery planning for a small business is four decisions and one habit. The decisions are how long you can be down (your recovery time objective), how much data you can afford to lose (your recovery point objective), which systems have to come back first, and who is allowed to declare a disaster. The habit is testing a restore on a schedule, because an untested backup is a hope rather than a plan.
In Los Angeles the disaster is rarely exotic. It is a ransomware event, a failed server, a burst pipe on the floor above, a wildfire evacuation zone that includes your office, or a power event during a heat wave. The plan that handles a ransomware event handles most of the others too, which is why it is worth building one rather than one per scenario.
Start with the two numbers
Recovery time objective (RTO) is how long a system can be unavailable before the impact becomes unacceptable. Recovery point objective (RPO) is how much data you can afford to lose, measured backwards from the moment of failure. If your backup runs nightly at 11 p.m. and the server fails at 4 p.m., you have lost a day of work, so your RPO is 24 hours whether or not you chose it.
Set both per system rather than for the business as a whole. A practice management system and the marketing file share do not deserve the same investment, and pretending they do is how disaster recovery budgets get rejected. Write the numbers down, because they are what turns a technology conversation into a business decision: every improvement in RTO or RPO has a price, and the owner gets to choose.
Classify your systems
Three tiers is enough for most small businesses.
- Tier 1, revenue or safety critical. The systems where an hour of downtime is visible to customers or regulators. Typically the line-of-business application, email, and whatever holds client or patient records.
- Tier 2, operationally important. Painful within a day: file shares, accounting, phones, internal collaboration.
- Tier 3, everything else. Recoverable within a week without lasting damage.
The classification is what drives the restore order during a real event, and having it decided in advance is the difference between a recovery and an argument.
Backups: the 3-2-1 rule, plus immutability
The old rule still holds: three copies of your data, on two different media, with one copy offsite. Ransomware added a fourth requirement, which is that at least one copy must be immutable, meaning it cannot be altered or deleted within its retention window even by an administrator account.
That last property is the one that decides ransomware outcomes. Modern ransomware operators look for the backup console first and delete what they find, using credentials they have already stolen. A backup that a compromised administrator can delete is not protection against the threat you are most likely to face.
What to verify about your own backups today:
- What is included, and specifically whether Microsoft 365 or Google Workspace data is included. Both providers replicate your data for availability; neither is a backup against deletion, corruption, or a malicious insider.
- How often each system is backed up, compared against the RPO you wrote down.
- Where the offsite copy lives and who can delete it.
- Whether at least one copy is immutable, and for how long.
- Who holds the encryption key, and whether you could restore without your IT provider.
- The date of the last successful test restore.
Write the plan as a document someone can follow at 3 a.m.
A disaster recovery plan that only makes sense to the person who wrote it fails in exactly the circumstances it was written for. Keep it short and operational.
- Declaration. Who decides this is a disaster, who they call, and what authority that gives them.
- Contacts. Staff, IT provider, insurer, bank, landlord, key vendors, and legal counsel, with mobile numbers, stored somewhere reachable when the network is down.
- Restore order. The tier list, as a sequence.
- Step-by-step restore procedures for each Tier 1 system, written to be followed rather than interpreted.
- Alternate work arrangements. Where people work if the office is unreachable, and what they need to do it.
- Communication templates. What you tell staff, what you tell clients, and who signs it off.
- A printed copy, or one on a device that does not depend on the systems being recovered.
Test it, and be specific about what you tested
Testing is where plans stop being paperwork. Three levels, escalating in cost and value:
- Restore test, monthly. Pull one file and one full system from backup and confirm both open. This catches silent backup failures, which are the most common and the most damaging.
- Tabletop exercise, twice a year. Sit the leadership team down with a scenario and walk the plan. Ninety minutes. It finds the gaps in decision-making rather than the gaps in technology, and those are usually the bigger ones.
- Full failover test, annually. Bring a Tier 1 system up in the recovery environment and measure how long it actually took against the RTO you wrote down. The measured number is almost always longer than the estimate, which is the point of measuring it.
Record the date and the result of every test. When your insurer, your largest client, or a regulator asks whether you test your recovery capability, the answer they want is a date, not an assurance.
The small business disaster recovery checklist
- RTO and RPO written down for each Tier 1 and Tier 2 system, agreed by the owner.
- System tier list, with a restore sequence.
- Backups covering every Tier 1 and Tier 2 system, including cloud email and files.
- At least one immutable copy and at least one offsite copy.
- Encryption key custody documented, and held by the business.
- Monthly restore test, with dated results.
- Annual full failover test of at least one Tier 1 system.
- Written plan with declaration authority, contacts, restore order, and procedures.
- Offline copy of the plan and the contact list.
- Alternate work arrangements documented, and tried once.
- Cyber insurance policy read, with the notification window known in advance.
- Plan reviewed annually and after any material change.
Related reading
- IT disaster recovery plan for Southern California businesses, our detailed regional guide covering wildfire and earthquake scenarios.
- Disaster recovery versus business continuity, on how the two plans differ.
- Lessons from California wildfires and earthquakes.
- A guide to minimizing business disruptions.
- What your IT disaster recovery plan should cover.
- Why data disaster recovery matters at every size.
- Our disaster recovery and business continuity service.
Schedule a free consultation today to learn more about how Be Structured can safeguard your business from costly disruptions and security threats.
