Skip to content

Preparing for the Unpredictable: A Comprehensive Guide on Disaster Recovery Plan for Small Business

Disasters, from cyber attacks to floods to a spilled coffee, are rarely preventable, but their impact is. This guide walks through how to build a disaster recovery plan that keeps a small business running when something goes wrong.

Sereno IT
Talk to us
· Updated ·15 min read
3D illustration of a person managing cloud backups and secure data recovery on a computer, with cloud storage icons and green checkmarks.

Before you get down to disaster recovery planning, it’s crucial to understand the threats you should be prepared for. They can range from pandemics to office break-ins, and small businesses aren’t immune. Here’s a breakdown of some of the most common threats to business continuity today.

Understanding the potential threats to your business continuity

  • Cyber attack, since the early 2010s, cyber attack has consistently topped the charts for posing the most serious threat to businesses globally. As technology advances, attackers are evolving and finding more loopholes to access your critical systems. A proper cyber security strategy is fundamental to protecting against cyber criminals, no matter the size of your business.
  • Core IT infrastructure failure, servers, firewalls, and network switches failing can all cause downtime and disruption to varying extents. While these failures can be planned for and redundancies put in place, they still pose a significant risk to business continuity. Ensuring the reliability and resilience of your core IT infrastructure is crucial to minimising the impact of such failures.
  • Natural disasters, in London, you may not think of natural disasters as a real threat to business. However, whilst we don’t often experience tsunamis or earthquakes, we’re certainly accustomed to adverse weather. Anything from storms to floods and fires could damage your IT equipment, servers and systems, causing data loss and disruption.
  • Physical disasters, fires, explosions, and other physical disasters present severe threats to business operations. In addition to an emergency response plan to ensure the safety of your staff, it’s critical to have a disaster recovery plan to address the potential consequences for your IT systems.
  • Human error, humans are prone to making mistakes, and even with the best intentions, your employees could put your business at risk. It’s not uncommon for people to accidentally delete important data, drop a laptop, or spill a drink over a server. Whatever the error, having a disaster recovery plan in place will help to maintain business continuity.
  • Theft or loss, hybrid working means our devices are on the go more than ever. If these mobile devices end up in the wrong hands, it could pose a serious threat to your security. And what if your office is broken into? Thieves could access an abundance of sensitive data, putting your reputation and finances at risk.
  • Health concerns, this hardly requires explanation given recent events, but the spread of infectious diseases can put office spaces in lockdown, force remote working, and cause large portions of your team to be off sick.

Disaster recovery vs business continuity planning: understanding the difference

Both disaster recovery and business continuity plans aim to minimise damage from a disaster, and they are often combined into a single document. Still, they refer to different things.

The major difference is that recovery strategies focus on bringing systems back to normal performance as quickly as possible after an outage or incident. A business continuity plan, on the other hand, aims to maintain service delivery even while the disruption is still happening.

Put simply, disaster recovery outlines how to restore full functionality once a disaster occurs, while business continuity ensures the organisation can continue working at some level throughout the disruption. For that reason, businesses should develop both, or at least include disaster recovery measures within their broader continuity planning.

What could disaster mean for my business?

The impact of disaster can be split into three key areas, all of which put your business at serious risk.

  • Financial loss, if sensitive data ends up in the wrong hands (e.g. on the dark web), you will breach data confidentiality regulations, leading to hefty fines from authorities. Likewise, if your physical assets are destroyed in a crisis and your data isn’t secured elsewhere, you will not only be unable to work but also face the financial burden of replacing your devices and services.
  • Reputational damage, news of data losses and security breaches spreads rapidly, and soon clients and potential clients won’t want to work with you. A reputation for having bad cyber security and unreliable business continuity is a fail-safe way to see your business suffer.
  • Operational disruptions, disasters will usually disrupt your business to some extent; they’re often unpredictable and unpreventable. However, you can control to what extent. If your business is unable to function for weeks or even months, you will lose clients, money and reputation. A robust disaster recovery plan minimises this disruption and gets your team back up and running as soon as possible.

Advantages of a disaster recovery plan for small businesses

While a lack of a comprehensive disaster recovery plan can lead to severe consequences for any organisation, having a robust plan up your sleeve offers several decisive advantages.

Business continuity

The main benefit is that it helps small businesses stay resilient when an unforeseen disruptive event occurs, from physical disasters and hardware failures to digital threats such as cyberattacks or data breaches.

Cost-effectiveness

Disaster recovery plans allow small businesses to quickly resume critical operations, minimising downtime and avoiding the high costs associated with data loss.

Improved data security

Disaster recovery plans include data backup strategies. These help small businesses ensure they can quickly restore data, even when loss occurs due to hardware failure or malicious attacks.

Customer retention

Customers value reliability. Small businesses that quickly restore operations after a disaster are more likely to build customer trust and loyalty.

Reduced compliance risks

A well-designed disaster recovery plan helps small businesses avoid compliance violations by ensuring that data handling, storage, and the recovery process meet regulatory expectations. This reduces the risk of penalties and safeguards the business’s reputation.

Building your disaster recovery plan

Now that you know the risks of not preparing, you might be wondering: so how exactly do I create a small business disaster recovery plan?

We’ve included our guidelines for creating a successful disaster recovery plan below. However, we recommend discussing this with your IT partner so that your plan is aligned with the unique needs of your business.

Backing up data and systems

Your data and systems are the backbone of your business, and losing access to them could be catastrophic. As such, it’s vital that you effectively back up data and systems as part of your disaster recovery plan. Here are a few things to consider before creating your backup plan.

Backup types

There are two key ways to back up your data: physical backup and cloud-based backup.

  • Physical backup stores an extra copy of your data offline. These solutions are kept locally, often in an on-premises server room or data centre, and don’t require an internet connection. Generally, physical backups aren’t recommended in favour of cloud-based backups, because they’re physical, they’re more prone to loss, damage and theft. However, some owners prefer to have physical backups of very important files. In such a case, they need the right security measures in place to protect data should it get lost or stolen.
  • Cloud-based backup backs up all of your data and applications using cloud services, rather than relying solely on on-premises servers. Backups occur automatically in the background, continually making a copy of all your files, folders and images. Cloud backup makes it easy to access data from different locations while remaining cyber secure, which made cloud disaster recovery and backup extremely important, and for some businesses vital, when the coronavirus pandemic broke out.

But choosing the type of backup, be it cloud or physical, only means you have a copy of the data. In the event of disaster, the important question remains: how can you actually recover your data quickly and minimise downtime? A comprehensive backup and recovery solution goes beyond simply making copies, you must also ensure the recovery process is quick and you can resume operations seamlessly.

Choosing data recovery solutions

It’s all well and good to have a backup and disaster recovery plan, but getting a backup solution in place that’s fit for purpose is usually the first step, and can be the most difficult. There are many different solutions and practices available, and it can get confusing as to what you need for what types of IT systems and data.

A backup service and a full disaster recovery solution are very different things. Having a backup service may simply mean your files are stored in a different location, on a physical drive or in the cloud, and should you delete or lose them, you can recover them. A full disaster recovery solution, however, will allow you to completely “fail over” and work entirely from a recent version of your IT system if your primary system goes down.

For example, if you have an in-house server, it’s no good just backing up the data on it. If your server went down and your employee needed to work, having a copy of the files without a way to access the applications and systems your business relies upon won’t help. In this scenario, you would need a DR solution that takes a full copy of your entire server, replicating everything, essentially data centre disaster recovery on a small-business scale.

If your business runs on servers, or you have storage devices in-house such as a network-attached storage device (NAS), the traditional best practice is an “onsite and offsite” backup solution. This is where you have a failover server in your office that does frequent backups throughout the day and also backs up to a secure data centre or backup cloud environment offsite. The onsite server can do more frequent backups without the worry of uploading over the internet, and it’s quicker to recover data from it, or fail over completely onto the copy of your server if your main server goes down. Think of it like a spare tyre in an emergency.

The offsite or cloud backup should offer the same replication of your entire server (image-based backup) to protect against a real disaster, think fire, flood, electrical surge, or outage, when both your main server and onsite backup are unavailable. In these scenarios, you can connect to your cloud environment and work from there through a VPN or remote desktop. Technology is changing, though, and many solutions now remove the need for an onsite backup server because they can offer such quick, full recovery in the cloud. It is often cheaper to have just this, as cloud storage is coming down in price, assuming it meets your Recovery Time Objective (more on this below).

Cloud apps still need a backup

A common misconception is that cloud productivity suites like Microsoft 365 and Google Workspace don’t need to be backed up. Because these Software-as-a-Service apps are cloud-based, they have redundancy and security built in to protect against cyberattacks and outages, but they are still at risk. Microsoft, in its own T&Cs, recommends you have a third-party data backup. Redundancy is not the same as backup: Microsoft does not keep old versions of your environment forever, so you can lose data easily, and your data can still be encrypted in a cyberattack without a backup held outside their environment.

The good news is that there are many low-cost SaaS backup solutions available. These take full image-based backups of your entire Microsoft or Google environment frequently, so if anything happens, you have a full backup to recover from.

Things to consider

Not all data is created equal. Many companies have two types of data: “live” data that employees access frequently and depend on every day, and “archived” data that is rarely accessed and kept for reference or compliance. Consider this when looking at backups, you could use a cheaper data-only backup for archived data and a more comprehensive DR solution for live data.

  • Recovery Time Objective (RTO) and Recovery Point Objective (RPO): when choosing a backup and DR solution, you’ll need to set and agree on RTOs and RPOs, the speed at which your solution will get you operational again, and the longest period from the last backup point you’re comfortable with. These should dictate the solution you put in place, be documented in your DR plan, and be tested. More information can be found here.
  • Desktop backup: a cloud backup of what is saved on an individual’s desktop. Although available and cost-effective, this encourages bad practice and isn’t recommended. All data should be saved in centralised file storage and backed up as part of the company’s DR policy. Tools like OneDrive and Google Workspace can automatically back up the desktop, but try to store everything centrally to avoid silos and duplication.
  • Reporting and testing: the most important thing when choosing a backup solution is reliability, and that means reporting and alerting. Backup success reports, failure alerts, and automatic testing of full environment restoration should be in place. Your IT support provider should manage these on your behalf and be able to prove success and report on it frequently.
  • Insurance policies and risk assessment: before finalising your DR setup, review your insurance policies to understand what they actually cover. Many help with physical damage or equipment replacement but do not cover extended downtime or data loss. A thorough risk assessment will also show where the weak points are and which problems could cause the biggest disruption.

It’s not just data, servers, and systems that need to be reviewed for disaster recovery, a DR plan should include the whole IT environment and consider all dependencies within it. For example, firewalls, network switches, UPS systems, and internet failovers should all feature in your DR planning and testing.

Developing a disaster recovery team

Backing up your data is just one piece of the puzzle. Without the right team in place to prepare for and respond to a disaster, your business could suffer. Here are the roles that make for a successful disaster recovery team:

  • A disaster response expert, helps you formulate a recovery plan unique to your business, covering recovery objectives, dependencies and diagrams. You may have someone qualified in-house, or you may need to consult your IT partner.
  • Business continuity experts, all businesses should have a business continuity plan detailing how to keep operating should disaster occur. This doesn’t just cover technical needs; it should involve everything needed to keep the business running, e.g. staffing and supply chains.
  • Executive team, decision-makers are vital when faced with disaster. Your executive team should be involved in planning, including determining what’s possible given budget, staffing and other resources.
  • Catastrophe manager, if a catastrophic event occurs, you need someone to take responsibility for managing it. They should understand how your business operates so they can coordinate the things your plan cannot fully anticipate: people, resources, and timelines.
  • Recovery technicians, need to be immediately available in a crisis and able to solve technical issues remotely or onsite, prioritising fixes alongside the catastrophe manager.
  • Utilities providers, although not technically part of your team, it’s a good idea to establish relationships with utilities providers in case of a power outage or damage to the office.

Performing a business impact analysis

Next, conduct a business impact analysis. It will help you understand the potential effect of a disaster on your business by identifying critical assets, assessing the impact of disruptions on them, and prioritising recovery objectives. Based on this analysis, review your business interruption insurance to determine whether your coverage is sufficient.

Creating a communication plan

Let’s say a disaster strikes and your team is working to get the business back up and running. Beyond that, you need clear notification procedures to communicate what has happened, what the impact is, and when it will be resolved. Communication is twofold, internal (e.g. to employees) and external (e.g. to clients, vendors, or suppliers), and we recommend using multiple channels:

  • Email, a great way to send mass communications quickly and reassure everyone before news spreads elsewhere.
  • SMS, if you already use it to communicate with employees and clients, another fast way to send information out.
  • Phone/video call, offer calls to employees or key clients to explain the situation and potential impact. This could be crucial to retaining important customers.
  • Social media, explain what’s happened to mitigate rumours and protect your brand, then follow up once the situation is rectified.
  • Traditional media, if you’re a big brand, you may wish to communicate via traditional media too, offering reassurance about your DR plan.

We recommend creating templates for these channels and including them in your disaster recovery plan, so once a disaster strikes you can edit them to the situation and distribute quickly.

Testing and updating the plan regularly

Creating a disaster recovery plan is not a one-time event. Although many companies create one, tick the box, and forget about it, plans need to be reviewed constantly to reflect organisational changes, technology changes, and ever-changing cyber threats.

Testing is a very important part of effective recovery and should validate that the plan in place is effective and still relevant. Expect that after tests, the plan will need updating. DR planning is an ongoing process. Your first step should be to create a testing plan that considers scenarios that could play out in your environment: cyber security attacks, hardware failures, and even quarantine contingencies. Identify the biggest risks, test those scenarios first, and allocate the personnel involved.

A low-impact but good approach is a “tabletop” exercise: gather the relevant people and simulate what would happen if a specific scenario occurred, walking through the steps to ensure everything is covered. The most effective approach is a “functional exercise” that simulates the actual scenario, testing the impact and recovery process without causing a loss of operations. For example, simulating the failure of a core network switch lets you observe the impact, understand replacement turnaround times from hardware SLAs, and factor in installation time and the communication needed throughout.

How Sereno can help

Creating a disaster recovery plan for small business comes as part of our small business IT support services, helping companies like yours resume business functions quickly in the event of a natural disaster, cyberattack, or hardware failure.

At Sereno, we provide data backups and multiple DR solutions to fit our partners’ needs. We take the time to understand what our partners’ recovery point and recovery time objectives are, then find the right solutions for them, tailoring disaster recovery processes to meet their recovery goals.

We understand that it’s often backups and DR solutions that keep people awake at night, so it’s our job to remove that worry. We do this by providing proof and reporting for your backups, automated and sent to you directly, or reviewed in a quarterly review meeting with your dedicated technology advisor. As a trusted managed service provider, we take the success of backups seriously and only provide solutions that give us real-time alerting and reporting.

The benefit of having your IT support provider manage your backups is that your DR plan just became much simpler. With us, you have one point of contact for response, recovery, and communications with your team. Our aim is to take ownership of your entire IT environment, cyber security, data protection, infrastructure, and disaster recovery, so you can rely on us to keep you secure and recoverable at all times.

We’re also best placed to help create and test DR plans. We understand your entire environment, can identify potential risks, and then suggest testing scenarios that are less impactful during operating hours, removing the burden from your employees. Whether it’s virtual environments, physical servers, or cloud applications, we can find the right solution for your small business and manage it all on your behalf.

If you haven’t yet established a disaster recovery plan, or aren’t sure whether your existing plan is up to scratch, we can help. Simply contact us today to discuss your needs and goals, and we’ll help you devise a reliable IT disaster recovery plan, from risk assessment and selecting the most suitable backup solution to restoring your systems when something goes wrong.

Share this article

From Sereno IT

The Sereno IT team

Sereno IT is a London-based managed IT support provider helping businesses across the UK stay secure and productive. Read more in the Cyber Security section.

Improving Cyber Security

Ready to take the next step?

Friendly, no-jargon guidance from the Sereno team. Tell us what's going on with your IT, we'll tell you what to do about it.

Get a free security audit