
What is disaster recovery, and what it is not
Disaster recovery is the set of arrangements and technology that brings your IT back after something has gone thoroughly wrong. The word gets used for three different things, and the difference decides what you need.
Four words that get used interchangeably
They overlap, but they solve different problems — and they cost very different things.
- BackupA copy of your data, so you can return to an earlier moment. A backup says nothing about how long restoring takes or whether the system is still there afterwards. It is a precondition for disaster recovery, not the same thing.
- Disaster recoveryBringing complete systems back after an outage, within an agreed time. Besides the copy that asks for somewhere to restore it to, an order of work, and someone to carry it out.
- High availabilityTechnology that absorbs failure without anyone noticing: duplicated components inside the same environment. That helps with a broken disk and not with ransomware or a bad change, because those propagate neatly along with it.
- Business continuityThe business carrying on, including without IT. Think of how customers still reach you and how the work runs differently for a while. Disaster recovery is the IT chapter of that.
What disaster recovery is meant for
Four situations that look alike and ask for different answers. We have seen all four in practice.
Encryption by ransomware
The scenario most plans come apart on, because the attacker looks for the backups before striking. What counts here is a copy that cannot be modified and cannot be reached from the environment itself.
Loss of a site or a platform
Fire, water, a long power cut or an outage at a cloud provider. Here it is about a second place: another location, another region, or an environment you can switch on at the provider.
A change that goes wrong
An update, a migration or a script that cleaned up more than intended. That is not an attack and the effect is the same. What counts here is how far back you can go and how fast — so the RPO.
Human error, and the time that passes
Something deleted weeks ago and only missed now. Only retention helps there: how far back your copies reach. That is a choice rather than a technical limit.
When does an organisation genuinely need this?
Not every organisation needs a failover environment. These four questions say enough to know where you stand.
- How long can the work stop?If the organisation can go a day without, a good backup with a rehearsed restore is enough. If you are talking in hours, that is a different design and a different budget.
- What happens to today’s data?If losing a night of work is unacceptable, that decides more than anything else: copying has to happen more often or continuously, and that touches the whole design.
- Is there an obligation on it?Regulated sectors, insurers and large customers now ask for demonstrable continuity. Under NIS2 it is named in the duty of care. Then the record matters as much as the technology.
- Who carries it out when it happens?A plan without people who can get to it is not a plan. This is often the reason to outsource it: not because the technology is hard, but because nobody is free at that moment.
Further reading
What this connects to.
Questions we get about this
The ones that come up most, answered briefly.
Is high availability the same as disaster recovery?
No. High availability absorbs the failure of a component inside the same environment and helps with a broken disk. With ransomware or a bad change the problem propagates neatly into the duplicated part; only a copy that cannot be modified helps there.
Does a small company need disaster recovery?
That depends not on size but on how long the work can stop. If the organisation can go a day without, a good backup with a rehearsed restore is enough. If you are talking in hours, that is a different design, whatever the headcount.
What is the difference between disaster recovery and business continuity?
Business continuity is about the organisation carrying on: people, buildings, communication, suppliers. Disaster recovery is the IT chapter of that, and takes its brief from it — how long a process may be down decides how fast the systems have to be back.
Not sure yet what you need?
That is a perfectly good starting point. Tell us what runs and how long it may be down; the rest follows from that. A conversation about it costs nothing and usually produces a list.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.