
CONSULT CIRCLE | BUSINESS CONTINUITY
What a small or mid-sized business actually needs, how to prove it works, and the pricing structures that surprise people later.
Smaller organisations face the same threats as large ones with a fraction of the resource. The good news is that the requirements are well understood and achievable on a modest budget. The trap is buying on headline price and discovering the cost of actually using the service during an incident.
The requirements that matter
| Requirement | Why it matters | What good looks like |
|---|---|---|
| Offsite copy | A local-only backup dies with the site | At least one copy in a separate location or cloud |
| Immutable or air-gapped copy | Ransomware targets backups first, and often successfully | A copy that cannot be modified or deleted within its retention period |
| Tested restore | Backup success is not evidence of restore capability | A documented restore test at least quarterly |
| Coverage of everything | Cloud data and endpoints are routinely missed | Servers, endpoints, and software-as-a-service data including email and files |
| Defined retention | Too short fails compliance; too long costs unnecessarily | Retention set against a documented requirement, not a default |
| Documented recovery order | Restoring in the wrong order wastes hours | A written sequence with dependencies, reviewed annually |
| Monitoring and alerting | Silent failures are the norm | Alerts on failure that reach someone who acts |
| Named owner | Shared responsibility becomes no responsibility | One person accountable, with a deputy |
Table 1 — Core BDR requirements for smaller organisations.
The gap almost everyone has: Software-as-a-service data. Cloud providers protect their platform, not your data against your own mistakes. Deleted mailboxes, overwritten files and departed-user data are your responsibility, and default retention is shorter than most people assume.
The tests that prove it works
Four tests, in increasing order of confidence. Most organisations do the first and assume the rest.
| Test | What it proves | How often |
|---|---|---|
| Backup completion check | The job ran. Nothing more | Daily, automated |
| Single file restore | Data can be retrieved and is readable | Monthly |
| Full system restore | A whole system can be rebuilt, and how long it takes | Quarterly |
| Full recovery exercise | The business can operate again, in the right order, with people who know their roles | Annually |
Table 2 — Backup and recovery testing, by level of confidence.
Record the timings: Every test should record how long recovery actually took. That number, not the vendor’s figure, is your real RTO — and it is the one to put in front of the board when discussing whether it is acceptable.
Cost traps
- Egress and restore fees. Storing data is cheap; retrieving it can be expensive. Ask specifically what a full restore of your estate would cost, as a number.
- Per-device and per-workload pricing. Attractive at current size, less so after growth. Model it at twice your present estate before signing.
- Retention creep. Long retention on generous defaults quietly grows storage cost. Set retention deliberately against a requirement.
- Charges during an invocation. Some contracts bill separately for the resources consumed during an actual disaster. Establish what an invocation costs before you need one.
- SaaS backup as an add-on. Frequently priced separately per user and omitted from initial quotes.
- Exit costs. Getting years of retained data out of a provider can be slow and expensive. Agree exit terms at the start.
A realistic starting position
- Inventory what needs protecting, including endpoints and software-as-a-service data.
- Set RPO and RTO per system based on business impact, not uniformly.
- Ensure at least one copy is offsite and one is immutable or air-gapped.
- Automate monitoring so failures generate alerts that reach a named person.
- Schedule the four tests above and record the timings from each.
- Write down the recovery order, including dependencies such as identity and name resolution.
- Review annually, and after any significant change to the environment.
Related reading
- DRaaS vs traditional backup: choosing the right business continuity plan
- Disaster recovery terms to know in business
- Disaster Recovery Services and BC/DR Planning
Frequently asked questions
What is BDR?
Backup and disaster recovery: the combination of copying data so it can be restored, and the capability to resume operations after a disruptive event. The two are related but distinct, and both are needed.
Do we need to back up Microsoft 365 or Google Workspace?
Yes. Providers protect their platform against their own failures, not your data against deletion, overwriting or a departing employee. Default retention is usually shorter than organisations assume, and the responsibility is yours.
How often should a small business test backups?
Automated completion checks daily, a file-level restore monthly, a full system restore quarterly, and a full recovery exercise annually. Each level proves something the one below it does not.
What is an immutable backup?
A copy that cannot be altered or deleted for a defined retention period, even by an administrator. It is the most effective protection against ransomware, which routinely targets backups before encrypting production data.
How much should an SMB spend on backup and disaster recovery?
Set it against the cost of downtime rather than as a percentage of IT spend. Establish what a day of unavailability and a week of lost data would cost the business; that figure makes the investment decision straightforward.
Talk to Consult Circle
We design and run backup and disaster recovery for smaller organisations, including tested restores and documented recovery procedures.
Book a free 30-minute call - 0203 916 5593 - info@consultcircle.com