Dabish Digital
Security

Five mistakes teams make with disaster recovery

We end up explaining this on discovery calls often enough that it deserved writing down. These are the ones we run into repeatedly when we audit disaster recovery.

The realistic threat for most small businesses is automated and opportunistic, not targeted. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.

Common failure modes

  • Treating it as a launch task rather than an ongoing one
  • Assuming someone else already owns it
  • Ask how long you could be down before it really hurts
  • That answer sets your budget
  • Never checking whether the fix actually worked

Practise the recovery at least once a year. The reasoning matters more than the rule, because the rule has exceptions. Write the reasoning down alongside the decision, because the reasoning is what changes first.

A reasonable first step

In practice

The cheapest security work is the boring kind done on a schedule. Three things worth confirming about disaster recovery before you move on:

  • Someone can say what the current setup is without going to look
  • That answer sets your budget — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

Pick the one that would hurt most if it failed, and start there.