Many SMEs only discover that their backup isn’t working at the worst possible moment: when they actually need it. The difference between a few hours of downtime and permanent data loss almost always lies in how the backup and disaster recovery strategy was planned—not just executed.
Backup is not the same as disaster recovery
A backup is a copy of data. A disaster recovery (DR) plan is the set of processes that ensures that, in the event of a failure—such as hardware failure, a cyberattack, a fire, or human error—the company can resume operations within an acceptable timeframe. It’s entirely possible to have backups and still lack an effective recovery plan: the copy exists, but no one has tested how long it takes to restore it, or whether the process even works.
The 3-2-1 Rule
A robust backup strategy typically follows the 3-2-1 rule: three copies of the data, on at least two different types of media, with at least one copy stored offsite. This last component is often the most neglected—and the most critical in scenarios such as fire, flood, or theft, where backups stored in the same building are lost along with the original systems.
Two metrics every company should know
- RPO (Recovery Point Objective): What is the maximum amount of data the company can afford to lose, measured in time? If the last valid backup is 24 hours old, the company stands to lose up to one day of work in the event of a failure.
- RTO (Recovery Time Objective): How long can a company go without access to its systems before the impact becomes unacceptable for the business?
Determining these two values—even if only approximately—is the first step in properly sizing a backup strategy, because a daily backup performed at 2 a.m. may be perfectly adequate for one company and completely insufficient for another.
Why is testing the restore just as important as making a backup?
A backup that runs every night without generating any errors is no guarantee of anything—it may be copying corrupted files or inconsistent databases, or it may simply not include everything needed to restore operations. Periodically testing the restore process in a controlled environment is the only way to confirm that, when it’s really needed, the backup will work.
Scenarios that a disaster recovery plan should cover
- Hardware failure (hard drive, server, network equipment);
- Cyberattacks, including ransomware—a scenario in which having offline or immutable backups is crucial, because it prevents the attack itself from encrypting or deleting the backups;
- Human error — accidental deletion of files or folders;
- Physical incidents on site — fire, flooding, theft of equipment.
Where to Start
If your company can’t confidently answer these three questions—where the backups are, how long it’s been since they were tested, and how long it would take to restore the systems in the event of a failure—it’s a good sign that it’s worth reviewing your current strategy before you need it.




























































































