Skip to content
Security Updated Noah Stegman

IT Disaster Recovery Plan for Small Business: A Template

What a small business IT disaster recovery plan contains: RTO and RPO with a worked example, a one page outline to copy, SoCal risks, and test cadence.

An IT disaster recovery plan is a short written document that says which systems your business restores first after an outage, how fast each must be back, how much recent data you can afford to lose, who does what, and where the backups and passwords are. For a small office it fits on one or two pages. The two numbers that drive it are the recovery time objective (RTO) and the recovery point objective (RPO), explained below with a worked example and an outline you can copy.

This post is about the plan. The copies of your data that the plan depends on are covered in our small business backup guide.

What Counts as an IT Disaster for a Small Business?

Anything that stops staff from using the systems they need for longer than the business can comfortably absorb:

  • Ransomware or another cyberattack that encrypts or locks systems
  • Hardware failure: a dead server, storage device, firewall, or the one computer that runs a key program
  • Accidental deletion of a shared folder, mailbox, or database
  • Power or internet outage lasting hours or days
  • Cloud service outage at Microsoft 365, Google Workspace, or a software vendor
  • Physical loss: fire, water damage, earthquake damage, or theft

The federal Ready.gov guidance on IT disaster recovery recommends the same starting point for every business: inventory your hardware, software, and data, identify what is critical, make sure it is backed up, and document and test the plan.

What Are RTO and RPO?

Both terms come from contingency planning standards. The definitions below are from NIST Special Publication 800-34, the federal government’s contingency planning guide.

  • Recovery time objective (RTO): NIST defines it as the overall length of time a system can be in the recovery phase before it negatively impacts the organization’s mission. In plain terms: how long can this system be down before it really hurts?
  • Recovery point objective (RPO): NIST defines it as the point in time to which data must be recovered after an outage. In plain terms: how much recent work can we afford to redo?

RTO is about downtime. RPO is about data loss. They are business decisions, made by the owner, and the technology is then chosen to meet them. A shorter RTO or RPO costs more, so set them per system instead of demanding “instant” for everything.

A Worked Example

Picture a six person accounting office, used here purely as an illustration. It runs Microsoft 365 for email and files, QuickBooks Desktop on a small server, a cloud tax program, and internet-based phones. The owner works through each system and asks two questions: how long could we cope without it, and how much work could we redo?

SystemRTO (max downtime)RPO (max data loss)What that requires
Email and calendar4 hoursNear zeroCloud-hosted email, plus staff able to reach it from phones or home if the office is unusable
QuickBooks company file8 hours in tax season, 24 hours otherwise4 hoursBackups several times a day, and a documented way to restore the file onto another computer
Shared client files24 hours24 hoursNightly backup with version history, offsite copy
Cloud tax programVendor controlledVendor controlledKnow the vendor’s status page and support contact, and keep exported copies of finished returns
Phones2 hoursNot applicableForwarding to mobiles configured ahead of time in the phone system’s portal
Office internet4 hoursNot applicableA cellular hotspot or backup connection, tested

Now the numbers can be checked against reality. If QuickBooks is backed up only once a night, the actual RPO is up to 24 hours, which misses the 4 hour target. Either the backup schedule changes or the owner accepts a longer RPO. If a test restore of the shared files takes 30 hours over the office internet connection, the 24 hour RTO is not met, and a local backup copy is the likely fix. That comparison between target and tested reality is the whole point of writing the numbers down.

A One Page IT Disaster Recovery Plan Outline

Copy this outline, fill it in, and keep it to one or two pages. Short plans get read and updated.

IT DISASTER RECOVERY PLAN
Business name:                      Plan owner:
Last updated:                       Last tested:

1. WHO DECIDES AND WHO TO CONTACT
   - Person who declares an IT emergency, and a backup person
   - IT support contact
   - Internet provider, account number, support line
   - Electric utility account number
   - Key software vendors and support contacts
   - Cyber insurance carrier, policy number, claims line
   - How staff will be told what is happening (group message, personal email list)

2. SYSTEMS IN PRIORITY ORDER
   For each: what it is, where it runs, RTO, RPO, who restores it
   1)
   2)
   3)

3. BACKUPS
   - What is backed up, to where, how often
   - Where the immutable or offline copy is
   - How to sign in to the backup service if the office is unavailable
   - Date and result of the last restore test

4. ACCESS
   - Where administrator passwords and recovery codes are stored
   - Who can reach them, and how, from outside the office

5. RECOVERY STEPS BY SCENARIO
   - Ransomware or suspected breach
   - Server or key computer failure
   - Internet or power outage
   - Office unusable
   For each: first three actions, who does them, where staff work meanwhile

6. WORKING WITHOUT SYSTEMS
   - Manual fallbacks (paper intake forms, printed schedule, card reader on cellular)
   - Phone forwarding plan

7. TESTING AND REVIEW
   - Restore test schedule
   - Annual walkthrough date
   - What triggers an update (new system, new vendor, staff change)

Two storage rules matter as much as the content. Keep a printed copy offsite and a digital copy somewhere that does not depend on the systems in the plan. And keep the administrator passwords in a password manager that at least two trusted people can open from a phone.

Disaster Recovery, Backup, and Incident Response: How They Differ

  • Backup is the copy of your data.
  • Disaster recovery is the plan for restoring systems in the right order within target times.
  • Business continuity is how the business keeps serving customers while systems are down: paper forms, working from home, forwarding phones.
  • Incident response is what you do in the first hours of a security event, such as isolating machines and preserving evidence, before recovery starts.

For a small business, disaster recovery and business continuity comfortably share one document. Security incidents deserve their own checklist. See our incident response plan guide and what to do after a data breach. The FTC’s cybersecurity guidance for small businesses is a useful plain-language companion to both.

Which Risks Are Specific to Southern California?

Everyday causes such as failed drives and phishing apply everywhere. Three regional risks are worth a line each in an Orange County plan, and all three can be checked against official sources.

Earthquake

The California Geological Survey states that more than 70 percent of the state’s population lives within 30 miles of a fault where high ground shaking could occur in the next 50 years. Its EQ Zapp map lets you look up earthquake hazard zones by address. For IT planning, the practical effects are physical damage to equipment and an office you may not be allowed to enter. Secure server and network equipment in a rack or strap it down, keep it off the floor, and make sure at least one backup copy is outside the region. The state-sponsored MyShake app delivers earthquake early warning alerts in California.

Wildfire

The California Public Utilities Commission publishes a High Fire-Threat District map with an address search. Tier 2 marks elevated risk and Tier 3 marks extreme risk from utility-related wildfires. If your office or the homes of key staff sit in or near those tiers, plan for evacuation: staff need to be able to work from laptops with cloud access, and nothing critical should exist only on equipment inside the building.

Public Safety Power Shutoffs

A Public Safety Power Shutoff is when a utility turns off power to specific areas during dangerous fire weather to reduce the risk of its equipment starting a fire. Two investor-owned electric utilities publish shutoff procedures that matter locally, so check your bill to see which one serves your address.

  • San Diego Gas & Electric, which serves San Diego and southern Orange counties, says it aims to notify customers about 48 hours, 24 hours, 12 hours, and 1 to 4 hours before a shutoff. After the weather passes, crews must patrol the lines, which takes 4 to 8 daylight hours, and restoration can take days in difficult terrain.
  • Southern California Edison says notifications start about three days ahead, that events may last more than 24 hours, and that line inspections before restoration typically take up to eight hours.

For the plan, that means: keep utility account contact details current so alerts reach you, put a battery backup (UPS) on the server, firewall, and internet equipment so they shut down cleanly, decide ahead of time whether staff work from home during a shutoff, and confirm your phones can forward to mobiles. Our VoIP phone system guide covers forwarding options.

How Often Should You Test the Plan?

Ready.gov says to test the plan periodically. NIST 800-34 describes two useful kinds of test: a tabletop exercise, where people talk through a scenario, and a functional exercise, where you actually restore something. A cadence that works for a small office:

How oftenWhat to doTime needed
MonthlyRestore one file or folder from backup and open it15 minutes
QuarterlyRestore something large (a mailbox, the accounting file, a shared folder) and time it against the RTO1 to 2 hours
Twice a yearReview the plan: contacts, systems list, passwords location30 minutes
YearlyTabletop walkthrough of one scenario with the people named in the plan1 hour
After any changeUpdate the plan when you add a system, change a vendor, or a key person leaves15 minutes

Record every test on the plan itself: the date, what was restored, how long it took, and what you changed afterward.

Common Mistakes

  • RTO and RPO targets that were never compared with an actual timed restore.
  • The plan is stored only on the server it describes.
  • Administrator passwords known to one person, or stored only on a system that is down.
  • Cloud services left out because “the vendor handles it.” The vendor handles its uptime. You still need to know how to work during its outage and how to restore deleted data.
  • Contact lists and system lists that were accurate two vendors ago.
  • No named owner, so nobody schedules the tests.

When a Lighter Plan Is Enough

A business with a few people, everything in Microsoft 365 or Google Workspace, no server, and laptops that can work from anywhere already has much of its continuity built in. The plan can be a single page: the contact list, where the separate cloud backup lives, where passwords are kept, and what staff do during a power or internet outage. The more you depend on equipment in one building, the more detail the plan needs.

Common Questions

How long should a small business disaster recovery plan be?

One or two pages is enough for most offices under 25 people. It needs a contact list, systems in priority order with RTO and RPO, backup locations, where credentials are kept, and first steps for a handful of scenarios. Detailed restore instructions can live in a separate document that the plan points to.

What is a reasonable RTO for a small business?

There is no standard figure. An office might tolerate a day without shared files but only a few hours without email or phones. Set each target by asking what the outage costs per hour in lost work and missed customers, then check that your backup and restore speed can really meet it. Revisit targets if a test shows they are unrealistic.

Does cyber insurance require a disaster recovery plan?

Insurers commonly ask about backups, restore testing, and incident response planning on their applications, and requirements vary by carrier. Read your own application and policy, because answers on the application can affect a claim. Our cyber insurance guide explains what carriers typically look for.

Who should own the plan?

One named person inside the business, usually the owner or office manager, with a named backup. An outside IT provider can write and test the plan with you, but someone inside the business must be able to declare an emergency, reach the contact list, and make spending decisions quickly.

How Coastal Growth Co. Can Help

We help small businesses write a recovery plan that matches how they really work: listing systems, setting RTO and RPO with the owner, checking that backups can meet those numbers with timed restore tests, and documenting the steps. It can be a one-time project or part of ongoing managed IT for offices across South Orange County. Get in touch and we will agree on scope and price before any paid work begins.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.