Backup and Disaster Recovery (BDR) for SMBs: Requirements, Tests and Cost Traps

    Consult Circle5 min readDisaster Recovery
    Backup and Disaster Recovery (BDR) for SMBs: Requirements, Tests and Cost Traps

    CONSULT CIRCLE | BUSINESS CONTINUITY

    What a small or mid-sized business actually needs, how to prove it works, and the pricing structures that surprise people later.

    Smaller organisations face the same threats as large ones with a fraction of the resource. The good news is that the requirements are well understood and achievable on a modest budget. The trap is buying on headline price and discovering the cost of actually using the service during an incident.

    The requirements that matter

    RequirementWhy it mattersWhat good looks like
    Offsite copyA local-only backup dies with the siteAt least one copy in a separate location or cloud
    Immutable or air-gapped copyRansomware targets backups first, and often successfullyA copy that cannot be modified or deleted within its retention period
    Tested restoreBackup success is not evidence of restore capabilityA documented restore test at least quarterly
    Coverage of everythingCloud data and endpoints are routinely missedServers, endpoints, and software-as-a-service data including email and files
    Defined retentionToo short fails compliance; too long costs unnecessarilyRetention set against a documented requirement, not a default
    Documented recovery orderRestoring in the wrong order wastes hoursA written sequence with dependencies, reviewed annually
    Monitoring and alertingSilent failures are the normAlerts on failure that reach someone who acts
    Named ownerShared responsibility becomes no responsibilityOne person accountable, with a deputy

    Table 1 — Core BDR requirements for smaller organisations.

    The gap almost everyone has: Software-as-a-service data. Cloud providers protect their platform, not your data against your own mistakes. Deleted mailboxes, overwritten files and departed-user data are your responsibility, and default retention is shorter than most people assume.

    The tests that prove it works

    Four tests, in increasing order of confidence. Most organisations do the first and assume the rest.

    TestWhat it provesHow often
    Backup completion checkThe job ran. Nothing moreDaily, automated
    Single file restoreData can be retrieved and is readableMonthly
    Full system restoreA whole system can be rebuilt, and how long it takesQuarterly
    Full recovery exerciseThe business can operate again, in the right order, with people who know their rolesAnnually

    Table 2 — Backup and recovery testing, by level of confidence.

    Record the timings: Every test should record how long recovery actually took. That number, not the vendor’s figure, is your real RTO — and it is the one to put in front of the board when discussing whether it is acceptable.

    Cost traps

    • Egress and restore fees. Storing data is cheap; retrieving it can be expensive. Ask specifically what a full restore of your estate would cost, as a number.
    • Per-device and per-workload pricing. Attractive at current size, less so after growth. Model it at twice your present estate before signing.
    • Retention creep. Long retention on generous defaults quietly grows storage cost. Set retention deliberately against a requirement.
    • Charges during an invocation. Some contracts bill separately for the resources consumed during an actual disaster. Establish what an invocation costs before you need one.
    • SaaS backup as an add-on. Frequently priced separately per user and omitted from initial quotes.
    • Exit costs. Getting years of retained data out of a provider can be slow and expensive. Agree exit terms at the start.

    A realistic starting position

    1. Inventory what needs protecting, including endpoints and software-as-a-service data.
    2. Set RPO and RTO per system based on business impact, not uniformly.
    3. Ensure at least one copy is offsite and one is immutable or air-gapped.
    4. Automate monitoring so failures generate alerts that reach a named person.
    5. Schedule the four tests above and record the timings from each.
    6. Write down the recovery order, including dependencies such as identity and name resolution.
    7. Review annually, and after any significant change to the environment.

    Frequently asked questions

    What is BDR?

    Backup and disaster recovery: the combination of copying data so it can be restored, and the capability to resume operations after a disruptive event. The two are related but distinct, and both are needed.

    Do we need to back up Microsoft 365 or Google Workspace?

    Yes. Providers protect their platform against their own failures, not your data against deletion, overwriting or a departing employee. Default retention is usually shorter than organisations assume, and the responsibility is yours.

    How often should a small business test backups?

    Automated completion checks daily, a file-level restore monthly, a full system restore quarterly, and a full recovery exercise annually. Each level proves something the one below it does not.

    What is an immutable backup?

    A copy that cannot be altered or deleted for a defined retention period, even by an administrator. It is the most effective protection against ransomware, which routinely targets backups before encrypting production data.

    How much should an SMB spend on backup and disaster recovery?

    Set it against the cost of downtime rather than as a percentage of IT spend. Establish what a day of unavailability and a week of lost data would cost the business; that figure makes the investment decision straightforward.

    Talk to Consult Circle

    We design and run backup and disaster recovery for smaller organisations, including tested restores and documented recovery procedures.

    Book a free 30-minute call - 0203 916 5593 - info@consultcircle.com

    Share this article: