Picture a morning when your website won’t load, your CRM is empty, and there’s an email demanding a ransom for your own data. At that moment the real question isn’t “do you have a backup” — it’s whether you have a disaster recovery plan: a step-by-step, tested procedure that a stressed person can actually follow at six in the morning to bring the business back to life. A backup without a plan is a spare part without assembly instructions. This article is about building that plan ahead of time, while everything still works.

Most owners of small and mid-sized businesses only think about recovery during the outage itself. That’s when the worst comes to light: there’s no backup, or it’s a week old, or it lives on the same server that just died, or nobody has ever tried to restore it. We’ve been working with clients’ systems since 2018, and we see this scenario regularly. The good news: preparation costs a fraction of a single day of downtime, and you can do it calmly, without a fire raging.

Why “we have a backup” isn’t protection yet

“We have a backup” is the most dangerous phrase in business, because it usually hides a few overlooked traps.

First: the copy sits right next to the original. If ransomware or a disk failure takes down the server, it takes the copy on that same server with it. A sound setup means at least three copies, on two different media, one of which is physically or logically separated — offline or off-site.

Second: nobody ever tested it. A backup that’s never been restored is an assumption, not a fact. Very often the archive turns out to be corrupted, missing the database, or requiring a password that only an administrator who left a year ago ever knew.

Third: stale depth. If the backup runs once a week, the worst case costs you a week of orders, documents, and correspondence. For an online store or a service business, that’s not an inconvenience — it’s direct financial loss and damaged customer relationships.

A disaster recovery plan starts exactly here — not with technology, but with an honest answer: how much data are we willing to lose, and how fast must we be back?

The two numbers everything starts with

Before configuring anything, define two targets for each critical system.

The first: how much downtime the business can survive. An hour? A day? For some, three hours offline is trivial; for others, it means missed shipments and penalties. This number dictates how fast and automated recovery needs to be.

The second: how much data you can afford to lose. If orders come in by the minute, a once-a-day backup means up to a day of lost sales. That calls for more frequent — sometimes continuous — backups.

These two numbers aren’t a technical whim; they’re a business decision the owner makes. They define the plan you actually need and guard against both extremes: paying for excessive “aerospace-grade” reliability where simple would do, or cutting corners where every hour of downtime costs real money.

What belongs in the plan besides data

Data is only half the job. A business isn’t just files — it’s access and knowledge that usually live in one person’s head. A complete disaster recovery plan records:

  • Access. Where and how passwords, keys, and access to the domain, email, and payment systems are stored. If one contractor knew all of it, you don’t have a business — you have a hostage situation. Access belongs in a secure vault, not someone’s notebook.
  • Domain and email. Often it’s not the website but control of the domain and corporate email that takes longest to recover. Record where they’re registered and who can reach them.
  • The sequence of steps. A plain document: what we do first, who we call, where we pull the copy from, how we confirm everything is back. Written in human language, not technical jargon.
  • Contacts. Who owns recovery, who backs them up, and how to reach them if the usual email is down.

This document has to live somewhere you can reach even when the main system is down — not inside that system itself.

A special case: recovering from a breach

A hardware failure and a hack are different scenarios, and the plan must cover both. After a breach, simply “restoring the latest copy” isn’t enough: if the attacker was inside your system for several days, a fresh copy may already contain their backdoor. So a recovery plan for an attack additionally calls for pinpointing when the intrusion actually began, choosing a known-clean copy from before that date, rotating every password and key, and only then bringing the system back. Skip that, and you risk restoring straight back into the hands of whoever broke in. That’s exactly why an offline copy the attacker couldn’t touch isn’t a luxury — it’s insurance.

How to confirm the plan actually works

A plan nobody rehearsed is hope, not a guarantee. On a regular cadence, run a recovery drill: take a copy and restore it into a separate environment without touching the live system. Such a rehearsal almost always surfaces something unexpected — a forgotten step, missing access, a copy that restores in half a day rather than five minutes.

One detail from experience: always drill on a separate copy, never on live data. The point of a rehearsal is to find the problem in calm conditions, not to create a second outage on top of the first. After each drill the plan gets sharper, and over time recovery turns from a frightening unknown into a routine that takes a few hours.

Where to start today

You don’t have to build everything at once. A smart first step is an inventory: list the systems your business depends on, and for each give an honest answer — where’s the copy, when was it last tested, who holds the access. That list alone usually exposes two or three gaps worth closing immediately.

Next: separate the copy from the original, align depth and frequency with those two numbers, and write the sequence of steps in plain words. That’s the foundation on which recovery stops depending on one person and their memory.

At LPF we’ve been building and maintaining systems like this on our own infrastructure since 2018 — from backups to tested recovery scenarios. If you’d like to calmly assess how ready your business is for a failure, start with a short conversation: together we’ll map out the risks and show you where to begin. Better one calm day of preparation now than one panicked morning later.