Disaster recovery is one of those phrases that makes business owners glaze over, right up until the morning a server dies, or ransomware locks every file, or a fire takes out an office. Then it becomes the only thing that matters. The good news is that the core ideas are simple, and you do not need to be technical to ask the right questions. This guide explains disaster recovery in plain language and shows you how to tell whether your business is actually protected or just assuming it is.
Two questions that define the whole thing
Strip away the jargon and disaster recovery answers two questions. First, if something destroys your systems, how much data can you afford to lose? An hour’s worth? A day’s? This is your recovery point. Second, how long can you afford to be down before you are working again? This is your recovery time. Every business has different answers. A busy SACCO cannot lose a day of transactions or be down for two days. A small office might tolerate more. The point is that you decide these numbers deliberately, in advance, rather than discovering them during the disaster itself.
A backup is not a recovery plan
Here is the mistake that catches people. They have backups, so they think they are covered. But a backup is just a copy of data. A recovery plan is knowing how to turn that copy back into a working business, and how long it takes. Plenty of organisations have backups that have never once been restored, sitting on a drive nobody has checked in a year. When the day comes, they find the backup was incomplete, or corrupted, or so slow to restore that the business loses a week anyway. A copy you have never tested is not protection. It is a guess.
The 3-2-1 rule, and why it still holds
The most useful rule in backup is also the oldest, and it survives because it works. It is called 3-2-1, and the United States cyber agency CISA still recommends it. Keep three copies of your data. Store them on two different types of media. Keep at least one copy off-site, away from your premises. The logic is plain. If a fire or a flood hits your office, the off-site copy survives. If one drive fails, the others remain. Ransomware adds a wrinkle, because modern attacks hunt for backups too, so at least one copy should be somewhere the attackers cannot reach and cannot change.
The two halves of recovery
When disaster strikes, recovery happens in two stages, and good planning covers both. The first is getting your people working again quickly, even if temporarily, so the business does not stop. This might mean switching to a cloud copy of your systems while the main ones are rebuilt. The second is the full restore, putting everything back properly, which takes longer. A plan that only thinks about the second stage leaves your business frozen for days while the rebuild happens. A plan that covers both keeps you running through the crisis and then quietly puts things back to normal.
The legal angle you cannot ignore
If a disaster involves a data breach, for example ransomware that steals data as well as locking it, Kenyan law may require you to act. The Office of the Data Protection Commissioner requires organisations to report certain personal data breaches, and there are time limits. This turns recovery from a purely technical exercise into one with legal consequences, and it is another reason to have thought it through before the day rather than during it.
How to check where you stand
You can test your own readiness without any technical skill. Ask whoever runs your IT three questions and watch how confidently they answer. When was our backup last test-restored, and can you show me it worked? If disaster hit today, exactly how long until we are working again? Is at least one copy of our data somewhere ransomware cannot reach? Clear, specific answers mean you are probably in good shape. Vague ones, or “it should be fine”, mean you have found a problem worth fixing before it finds you.
Every business should be able to keep operating, with its data, within hours of a disaster. If nobody can tell you how long yours would take, that is the answer.
If those questions made you less comfortable than you expected, a review is the cheapest way to fix that. Our free IT audit checks your backups, tests whether they actually restore, and tells you in writing how exposed you are and what to do about it. We build backup and recovery that is designed and tested in advance, with recovery times agreed to what your business can tolerate. Talk to a senior engineer about what yours should be.