Disaster Recovery Plan
A Disaster Recovery Plan sets out, in advance, exactly how the business gets systems and data back after a disruption, so the decisions get made calmly before the crisis, not during it.
Five steps run down the page in the order a plan gets built, from assessing risk to running the drill that proves it works.
Reach for this when…
- You realise nobody actually knows who calls whom if the server room floods tonight.
- A client or insurer asks for a written recovery plan and you don't have one.
- A near-miss outage showed you were improvising instead of following anything.
How to run it
- Assess the risks and rank them by likelihood and impact.
- Set recovery time and data-loss targets for each critical system.
- Build and test backup and recovery processes against those targets.
- Write the communication plan: who tells whom, in what order.
- Run a drill at least once a year and fix what the drill exposes.
A worked example
Situation. Nguyen Thi Mai ran Mai Health, a chain of three clinics in Da Nang, Vietnam, that lost two days of patient records to a single failed server with no working backup.
Applied. She built a plan with clear recovery targets for each system and, unusually, actually ran the drill six months later instead of filing the plan away.
Result. The drill found the backup for the billing system hadn't been running for weeks. She fixed it before it mattered, not after.
The catch
A plan nobody has tested is a document, not a capability, and most disaster recovery plans fail quietly at the drill stage, if they're tested at all. It also tends to focus on technology recovery while underestimating how much a crisis depends on people knowing their role without being told.
The plan you haven't drilled is a guess with a cover page.