Home / Blog / Backup & Continuity
Backup & Continuity

Disaster Recovery Planning: A Step-by-Step Guide

When a server dies, ransomware strikes, or a flood reaches the comms cupboard, the question is not whether you have backups — it is whether you can actually get your business running again, and how fast. That is the job of a disaster recovery plan. This step-by-step guide covers DR strategy, the RTO and RPO targets that shape it, the 3-2-1 backup rule, testing, and how cloud DR changes the picture.

Quick answer

A disaster recovery plan is a documented, tested process for restoring your IT systems, applications and data after a disruptive event. It sets recovery priorities and RTO/RPO targets, defines who does what, and specifies the exact steps to bring technology back online quickly and with minimal data loss.

What is disaster recovery planning?

Disaster recovery (DR) is the IT-focused discipline of getting systems and data back after an incident. It is the technical engine inside a broader business continuity plan: continuity keeps the business operating, DR restores the technology it depends on. A DR plan turns "we have backups somewhere" into a rehearsed, reliable procedure.

RTO and RPO: the two numbers that drive DR

Every DR decision comes back to two targets, set per system according to how critical it is.

RTO — Recovery Time Objective
The maximum acceptable time to restore a system after an incident. A shorter RTO means faster recovery, which usually costs more. Your order-entry system might need a one-hour RTO; an archive might tolerate a day.
RPO — Recovery Point Objective
The maximum acceptable data loss, measured in time. A 15-minute RPO means you can lose at most 15 minutes of data, so replication or backups must run at least that often.

Setting realistic RTO and RPO targets for each system is the single most important step, because they dictate the technology and budget your DR plan requires.

The 3-2-1 backup rule

Reliable recovery starts with reliable backups. The widely used 3-2-1 rule is a sound baseline:

  • 3 copies of your data (the original plus two backups).
  • 2 different types of media or storage.
  • 1 copy kept off-site.

Because of ransomware, many businesses now extend this to 3-2-1-1-0: add one copy that is offline or immutable (so attackers cannot encrypt it), and confirm zero errors by test-restoring. An immutable, isolated copy is what stops a single incident from taking your backups down with everything else. See our detailed guide to ransomware-ready backups for more.

Disaster recovery tiers

Not every system needs the same speed of recovery. Matching each system to a DR tier keeps costs sensible while protecting what matters most.

Common disaster recovery tiers by recovery speed and cost
TierTypical RTOTypical RPOApproachRelative cost
Backup & restoreHours to daysHoursRestore from off-site or cloud backups.Lowest
Pilot lightTens of minutes to hoursMinutes to hoursCore systems pre-provisioned in the cloud, scaled up on failover.Low–medium
Warm standbyMinutesMinutesA scaled-down running copy ready to take over quickly.Medium–high
Hot site / active-activeNear zeroNear zeroFully redundant, always-on environment.Highest

How to build a disaster recovery plan: step by step

  1. Inventory and prioritise systems. List every critical system and application, and rank them by business impact.
  2. Set RTO and RPO for each. Agree recovery-time and data-loss targets with the business, not just IT.
  3. Choose a DR strategy per tier. Map each system to a tier above, balancing recovery speed against cost.
  4. Design your backups. Implement the 3-2-1 (or 3-2-1-1-0) rule with at least one immutable, off-site copy.
  5. Document the runbook. Write clear, ordered recovery steps, roles, credentials access, and emergency contacts.
  6. Test with real restores. Regularly restore data and fail over systems to prove the plan works and to measure actual recovery times against your targets.
  7. Review and improve. Update the plan after every test and every significant change to your environment.

Cloud disaster recovery

Cloud DR replicates your systems and data to a cloud provider, so you can fail over and keep operating if your primary environment goes down. For most small and medium businesses it is more practical and affordable than maintaining a second physical site: you pay for standby capacity rather than duplicate hardware, and recovery times can be dramatically shorter. It pairs naturally with our cloud services. The ACSC provides broader guidance on preparing for and recovering from incidents at cyber.gov.au.

The honest takeaway

A disaster recovery plan is worthless until it has been tested with a real restore. The most damaging surprises happen when a business discovers, mid-crisis, that its backups were incomplete, out of date, or encrypted along with everything else. Regular, verified testing is the difference between a DR plan and a false sense of security — and it is exactly what our backup and business continuity services deliver.

Related services

Explore our backup and continuity services and cloud services, read our companion guide to business continuity planning, or book a free IT assessment. Ready to talk? Contact our Sydney team.

Frequently asked questions

A disaster recovery plan is a documented, tested process for restoring IT systems, applications and data after a disruptive event such as a cyber attack, hardware failure or natural disaster. It defines recovery priorities, roles, RTO and RPO targets, and the exact steps to bring technology back online.

The 3-2-1 rule states you should keep at least three copies of your data, on two different types of media, with one copy stored off-site. Many businesses now extend it to 3-2-1-1-0: adding one offline or immutable copy and zero errors after verifying restores. This protects against ransomware and single points of failure.

A backup is a copy of your data. Disaster recovery is the whole process of restoring systems and operations from those backups within agreed time and data-loss targets. You can have backups without a disaster recovery plan, but you cannot recover reliably without one.

At least annually, and after any major change to your systems. Testing should include an actual restore, not just a review of the document, because untested backups frequently fail when they are finally needed.

Cloud disaster recovery replicates your systems and data to a cloud provider so you can fail over and keep operating if your primary environment is unavailable. It removes the need for a costly secondary site and can offer faster recovery times than traditional tape or on-premises approaches.

← Back to all articles

Recover fast when it matters most

Talk to a Sydney-based IT specialist today. No jargon, no pressure — just clear advice on backups and disaster recovery that actually work.