When disaster recovery is worth the effort
The version of this that works is simpler than the version most people imagine. Disaster recovery is not free, and pretending otherwise leads to bad decisions.
Security is a maintenance habit rather than a purchase, which is why it drifts. If it only works because one person remembers to do something, it does not work yet.
When it is worth it
Ask how long you could be down before it really hurts. Getting it slightly wrong is survivable. Ignoring it entirely is not. It is the sort of thing that looks like polish right up until it costs you an enquiry.
When it is not
If nothing downstream depends on it and nobody is complaining, it can wait. In practice this is a scheduling problem more than a technical one.
How to decide
Practise the recovery at least once a year. The teams that handle this well are rarely the ones with the biggest budgets. Write the reasoning down alongside the decision, because the reasoning is what changes first.
In practice
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about disaster recovery before you move on:
- Someone can say what the current setup is without going to look
- Practise the recovery at least once a year — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Worth checking on your own setup before it becomes someone else's problem to fix.