Back to Blog
Security 6 min read 22 September 2026

Backup vs Disaster Recovery: What Does Your Small Business Need?

Backup vs Disaster Recovery: What Does Your Small Business Need?

Backups protect copies of your data; disaster recovery gets the business working again. Learn how to set practical RPO and RTO targets, protect backup copies and test recovery.

A backup tells you that a copy exists. Recovery means the business can use its essential systems again. Small businesses need both: buying storage without planning how work will resume can leave a long gap between retrieving files and serving customers.

Backup protects data; recovery restores operations

A backup is a separate copy of data that can be restored after deletion, corruption, equipment failure or a cyber incident. It may cover files, databases, email and application data.

Disaster recovery is the wider process for rebuilding usable operations. It covers the people, priorities, instructions and technology needed to restore systems in the right order, from clean devices and applications to access permissions and integrations.

Operational recovery also has dependencies that a file copy cannot solve. The business must know who can access the backup console, where licences and encryption keys are held, who makes recovery decisions, how employees work temporarily and in what order systems are restored.

Set RPO and RTO before choosing a product

Two targets turn “recover quickly” into something that can be planned and tested:

  • Recovery point objective (RPO): the maximum amount of recent data the business can accept losing, measured in time. A four-hour RPO requires a recovery point no more than four hours before the incident.
  • Recovery time objective (RTO): the target time for restoring a usable service. Diagnosis, access, replacement equipment, configuration and checks all count.

Targets should reflect business impact. A near-zero RPO or very short RTO usually requires more resilient systems and cost.

Labelled hypothetical example

Scenario: A fictional five-person accountancy practice stores active client documents in a cloud service and uses a separate line-of-business application.

Chosen RPO: Four hours for active documents and 24 hours for archived material. The practice decides that recreating up to four hours of document changes is difficult but manageable.

Chosen RTO: Eight business hours for active documents and two working days for the application. The team can use an agreed temporary process for one day, but not indefinitely.

Recovery plan: The owner reports the incident, a named technical contact checks whether accounts or devices are compromised, and clean access is established before data is restored. Staff then verify a sample of current files and application records before normal work resumes.

These are planning targets, not promises. A test may show that eight hours is not achievable with the current internet connection, supplier response arrangements or hardware. The business must then improve the design or agree a more realistic target.

SaaS sync is useful, but it is not automatically a backup

Cloud sync keeps files available across devices, but it is designed to copy changes. Microsoft explains that when a file in a OneDrive folder is added, changed or deleted, that action is reflected online and vice versa. This is convenient for collaboration, but it means a mistaken or malicious change can propagate.

Recycle bins, file versions and service-wide restore features can help, but they have retention rules, permissions and service-specific limits. They should not be treated as an independent backup without checking exactly what is retained, for how long, who can delete it and how it is restored.

Review important SaaS platforms, including email, CRM and finance systems. Confirm what customers can restore and whether an independent export or backup is needed.

Keep separate, protected copies

CISA describes the 3-2-1 rule: keep three copies of important files, use two types of storage and keep one copy off-site. It is a useful starting point, but separation also needs to cover credentials and destructive access.

At least one copy should be offline or immutable: disconnected when not in use or protected from change and deletion during its retention period. Otherwise, ransomware or a compromised administrator account may reach both live data and backups.

Also consider:

  • separate backup administrator accounts with multi-factor authentication;
  • encryption, with recoverable key arrangements;
  • enough retention to recover from damage discovered late;
  • alerts for failed jobs, unusual deletions and configuration changes;
  • a copy in a different location or failure domain from the live system.

A green tick is not a restore test

A completed job proves that backup software wrote something. It does not prove that the right data was captured or that staff can rebuild a working service.

Run regular, recorded restore tests. Restore a selection of files and, periodically, an entire critical system into a safe location. Check that the data opens, permissions are appropriate, applications start, integrations work and the measured recovery point and time meet the stated targets. The NCSC advises system owners to test restoration regularly and to detect corrupted backups.

Tests should be non-destructive and must not overwrite live data. Record the date, scope, result, time taken, problems and follow-up owner.

Give the plan an owner

For each critical service, write down:

  1. The business owner and technical recovery contact.
  2. The data and systems included—and anything excluded.
  3. The agreed RPO, RTO, backup frequency and retention.
  4. Where protected copies, credentials, keys and instructions are held.
  5. The recovery order and a safe temporary working method.
  6. The last test result and date of the next test.

Keep an accessible copy of the plan outside the systems it is meant to recover. Review it after major software, supplier, staffing or infrastructure changes.

The achievable plan is better than the ambitious plan nobody has tested. Start with the services that would stop trading, set honest targets, protect independent copies and prove the recovery steps.

HCMA Softtech's Managed IT & Security Services do not imply automatic backup or guaranteed recovery. We can discuss backup and recovery requirements within an agreed written scope. Contact HCMA Softtech to review what your business needs.

Sources and further guidance

BackupDisaster recoveryBusiness continuityRPORTOCybersecuritySmall business
HG

HCMA Softtech

Chesterfield-based support for customers UK-wide · hcmagroup.co.uk

Need help with software for your business?

We supply and install Microsoft, Adobe, QuickBooks, and security software across the UK. Get in touch for a free quote.