Cloud & Infrastructure

Disaster Recovery Plan for SMEs: A Practical Guide

Affix Center · · 6 min read

Disaster Recovery Plan for SMEs: A Practical Guide - Affix Center

Almost every business says it takes backups. Far fewer can answer a simple question: if your main server stopped working this morning, how long would it take to get your business running again, and how much data would you lose? For many small and mid-sized businesses, the honest answer is "we are not sure".

A disaster recovery (DR) plan answers that question in advance. It is not only for large enterprises with data centres. A trading firm in Bhiwandi, a clinic chain in Thane or a CA practice in Andheri all depend on data and systems that can fail. This guide explains how to set recovery targets, design a backup setup that fits your size, and test that it works.

Backup and Disaster Recovery Are Not the Same

A backup is a copy of your data. Disaster recovery is the full process of getting your systems and people working again after a serious failure. You need backups for DR, but backups alone are not enough.

Consider a ransomware attack that encrypts your accounting server. You may have a backup, but you also need a clean machine to restore it to, the software installed and licensed, the right people who know the steps, and a way to confirm the backup itself was not infected. A DR plan covers all of this.

Start With Two Numbers: RTO and RPO

Before choosing any technology, agree on two targets for each important system.

  • Recovery Time Objective (RTO): the maximum time the system can be down before the business is seriously affected. For example, four hours for billing, two days for an internal wiki.
  • Recovery Point Objective (RPO): the maximum amount of data, measured in time, you can afford to lose. An RPO of 24 hours means a daily backup is enough. An RPO of 15 minutes needs something much more frequent.

These targets should come from business owners, not only from IT. Ask each department what happens if their system is down for an hour, a day and a week. The answers will show you where to spend and where a simpler setup is fine.

Follow the 3-2-1 Backup Rule

The 3-2-1 rule is a widely used starting point for backup design:

  • 3 copies of your data: the live data and two backups.
  • 2 different types of storage, for example a local backup appliance and cloud storage.
  • 1 copy kept offsite, away from your main office.

Many organisations now add one more layer: at least one copy that cannot be changed or deleted for a set period, often called an immutable or offline backup. This protects you if ransomware or a compromised admin account tries to delete your backups along with your live data.

Choosing a Setup That Fits Your Size

On-Site Backup Only

A local backup device or NAS gives fast restores and is simple to manage. But it shares the same risks as your main systems: fire, flooding, theft and ransomware on the same network. On its own, it does not meet the 3-2-1 rule.

Cloud Backup

Backing up to a cloud service gives you an offsite copy without managing a second location. Restores of large volumes can be slower, depending on your internet connection. Check where the data is stored, how it is encrypted, and how long it takes to download a full restore.

Hybrid Backup

For most SMEs, a hybrid approach works best: a local copy for fast day-to-day restores, plus a cloud copy for serious incidents. This covers both the accidentally deleted file and the full office outage.

Disaster Recovery as a Service (DRaaS)

For systems with short RTOs, DRaaS keeps a copy of your servers ready to start in the cloud. If your main server fails, the cloud copy can take over within a short time. It costs more, so it is usually kept for your most critical systems only.

What Your DR Plan Document Should Include

A DR plan does not need to be long. It needs to be clear enough that someone can follow it under pressure. Include:

  1. A list of critical systems, with their RTO and RPO.
  2. Where each system's backups are stored and how often they run.
  3. Step-by-step restore instructions for each critical system.
  4. Names and phone numbers of the people responsible, with a backup person for each role.
  5. Vendor and support contacts, including your internet provider and software vendors.
  6. How staff will be informed and how they can keep working in the meantime.
  7. Where license keys, passwords and configuration details are kept securely.

Store a copy of the plan outside your main systems. A DR plan saved only on the server that has failed is not much help.

Test Restores, Not Just Backups

The most common gap in small business DR is that backups are never tested. The backup software shows a green tick every night, and nobody notices that a key database was excluded or that the files cannot be opened. A simple testing routine closes this gap:

  • Monthly: restore a few random files and confirm they open correctly.
  • Quarterly: restore one full system, such as your accounting database, to a test machine and check that it works.
  • Yearly: run a tabletop exercise. Walk through a scenario like ransomware or a flood with the team and follow the DR plan step by step.

Record how long each restore took. If it is longer than your RTO, you know where to improve.

Common Gaps in SME Backup Setups

  • Email and cloud apps assumed to be "backed up by the provider" when retention is limited.
  • Laptops of senior staff holding important files that are never backed up.
  • Backups running with the same admin password as the main network.
  • No alert when a backup job fails, so failures go unnoticed for weeks.
  • Only one person in the company who knows how to restore.

Frequently Asked Questions

How often should a small business back up its data?

It depends on your RPO. For most business systems, at least daily backups are a sensible minimum. Systems where losing a few hours of work would be costly, such as billing or order entry, may need backups every hour or more often.

Is cloud backup safe for business data?

It can be, if the service encrypts data in transit and at rest, supports strong access controls, and stores data in a location that meets your contractual and legal requirements. Check these points before choosing a provider.

What is the difference between high availability and disaster recovery?

High availability keeps a system running through small failures, for example by using two servers instead of one. Disaster recovery brings systems back after a major event that high availability cannot handle, such as losing the whole site.

How much does a DR setup cost?

Costs vary widely with data volume, RTO and RPO targets, and the number of systems. Setting clear targets first stops you from overspending on systems that do not need fast recovery.

How Affix Center Can Help

Affix Center designs and manages backup, business continuity and disaster recovery setups across private, public and hybrid cloud. We help you set realistic RTO and RPO targets, choose the right mix of local and cloud backup, and run regular restore tests. Learn more about our cloud and infrastructure services, or see how our managed IT operations team monitors backups day to day.

If you are not sure your current backups would hold up in a real incident, speak with our team for a review of your setup.