How to get disaster recovery right
This is cheap to get right at the start and expensive to retrofit. The short answer to disaster recovery is that it is mostly a sequence of small decisions, not one big one.
Security is a maintenance habit rather than a purchase, which is why it drifts. It rarely shows up as a line item, which is exactly why it slips.
Why this earns attention
Ask how long you could be down before it really hurts. That sounds obvious written down. It is still the thing most often skipped. Doing this properly once is usually cheaper than doing it approximately three times.
The steps
- Establish what you have today before changing anything
- That answer sets your budget
- Practise the recovery at least once a year
- Write down the decision so the next person does not re-litigate it
Practise the recovery at least once a year. Where this goes wrong is almost never a lack of knowledge. The version that survives contact with a real deadline is the simple one.
Making it stick
The short version
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about disaster recovery before you move on:
- Someone can say what the current setup is without going to look
- Practise the recovery at least once a year — and you know whether that is true here
- There is a way to tell whether the last change to this helped
The point is not perfection, it is knowing which of these you have consciously chosen to skip.