Most organisations we work with contact us for the first time during an active incident. In a minority of cases they contact us in advance, ask us to review their backup and recovery arrangements, and never need to call us again. The second outcome is always cheaper, faster, and less stressful for everyone involved.
A workable recovery plan does not require specialised software or major infrastructure investment. It requires three pieces of clear information: what data the business cannot operate without, where copies of that data are held, and how long it would take to return to normal operations if the primary copy were lost.
Each of those questions produces decisions. The first identifies which systems need protecting and which do not. The second exposes gaps — data held only on the laptop of one employee, backups stored on the same server they are meant to protect, cloud tenants without a second copy outside the provider. The third forces an honest assessment of recovery time, which is often much longer than the team assumed once the full restore process is considered end to end and under realistic network conditions.
We recommend that every organisation with more than a handful of employees produce a written recovery plan, test it at least annually with a real restore, and update it whenever significant infrastructure changes. The cost of producing the plan is trivial compared with the cost of discovering its absence during an incident.