Many businesses believe they are protected because "everything is backed up". Then a server fails or ransomware strikes, and they discover that restoring takes days, or that the backups were incomplete. Backup and disaster recovery are related, but they are not the same thing.
What a backup is
A backup is a copy of your data that you can restore if the original is lost, deleted or corrupted. Good backups are automatic, frequent, stored in more than one place, and protected so that an attacker who reaches your systems cannot delete them.
What disaster recovery is
Disaster recovery is the plan and capability to get your business running again after a serious incident. It covers not just data, but servers, applications, network access, people and communication. A backup is one ingredient; disaster recovery is the whole recipe.
Two numbers that matter
- Recovery point objective (RPO): how much data you can afford to lose, measured in time. If you back up nightly, you could lose up to a day of work.
- Recovery time objective (RTO): how long you can afford to be down. Restoring a large server from a slow backup can take far longer than people expect.
Agree these numbers for each important system with the people who run the business, not just the IT team. They drive every other decision, including cost.
The 3-2-1 rule
A simple, proven guideline: keep at least three copies of important data, on two different types of storage, with one copy off site. Today, many businesses add a further rule: at least one copy should be immutable or offline, so ransomware cannot encrypt or delete it.
What a disaster recovery plan includes
- A list of critical systems, in the order they must be restored.
- Where backups are kept and how to access them if your main systems are down.
- Who does what, with contact details stored somewhere other than your email.
- How you will communicate with staff and clients during an outage.
- Alternative ways to work, such as cloud access or a temporary site.
Test, then test again
A backup that has never been restored is a hope, not a plan. Schedule regular test restores of individual files and whole systems, and time them. Run a short tabletop exercise once a year in which the team walks through a realistic scenario, such as a ransomware attack on a Monday morning. Each test will reveal gaps that are far cheaper to fix in advance.
Cloud services need backing up too
A common misunderstanding is that data stored in cloud applications, such as email, file sharing and customer systems, is automatically backed up by the provider. Providers protect their platforms against hardware failure, but they usually do not protect you from accidental deletion, a malicious insider or ransomware that encrypts synced files. Check the retention settings in each service, and consider a dedicated backup for the cloud applications your business cannot do without. Keep the backup with a different provider or account, so a single compromised login cannot remove both the data and its copies.
Common mistakes
- Backing up servers but forgetting cloud services, laptops or databases.
- Keeping backups on the same network, where ransomware can reach them.
- Not monitoring backup jobs, so failures go unnoticed for weeks.
- A recovery plan that only one person understands.
Our Infrastructure Services team designs backup and disaster recovery plans sized to your real business needs, and helps you test them.



