From the team
Small-business backup and disaster recovery: a practical High Country checklist
If a server died this afternoon, how much work would your business lose — and how long would it take to get everyone working again?
Most owners cannot answer that with confidence. They know a backup runs somewhere, or that their files are “in the cloud,” but nobody has timed a restore or written down what happens after the first phone call.
That gap matters everywhere. In West Jefferson, Boone, and across the High Country, it also sits beside mountain weather, power interruptions, limited ISP options, and offices where one person holds most of the technical knowledge.
You do not need a hundred-page disaster plan. You need recoverable copies, realistic priorities, and a short procedure your team can follow while everyone is under pressure.
Backup and disaster recovery are not the same thing
A backup is a separate copy of data.
Disaster recovery is the process of using that copy to restore the systems, access, and information your business needs.
Business continuity is how you keep serving customers while recovery is underway.
Buying backup software handles only the first piece. A green “job successful” message does not tell you:
- Whether every important workload was included.
- Whether ransomware can reach and encrypt the backup.
- Whether anyone still has the credentials needed to restore it.
- How long a full recovery will take.
- What staff should do while systems are unavailable.
That is why our backup and disaster recovery work centers on monitored jobs and tested restores, not just storage capacity.
Start with two plain-English recovery targets
Before comparing products, answer two questions for each critical system.
How much work can we afford to lose?
This is your recovery point objective, usually shortened to RPO.
If the accounting system is backed up once each night, a failure at 4 p.m. could cost nearly a full day of entries. That may be acceptable for an archive. It is probably not acceptable for active scheduling, medical records, or orders.
Pick the acceptable amount of lost work first. That answer determines how frequently the system needs protection.
How long can we afford to be down?
This is your recovery time objective, or RTO.
“As soon as possible” is not a plan. Decide whether each system needs to return in one hour, four hours, one business day, or several days. Faster recovery usually costs more, so reserve it for work that actually stops revenue or client service.
For many small offices, the priority order looks something like this:
- Phones, internet, identity, and email.
- The line-of-business system used to serve customers.
- Current shared files and financial data.
- Historical files and archives.
Your order may be different. What matters is agreeing on it before an outage.
Know what actually needs backing up
“The server” is no longer a complete backup scope. A typical High Country business may have information spread across:
- A physical server or network-attached storage device.
- Microsoft 365 mailboxes, SharePoint, OneDrive, and Teams.
- QuickBooks or another line-of-business database.
- A cloud scheduling, CRM, or practice-management platform.
- Employee laptops that still contain files not saved anywhere else.
- Website assets, DNS records, firewall settings, and other configuration data.
List the systems that hold business data, who owns each one, and how it is protected. Ask cloud vendors what they back up, how long deleted data is retained, and how an export or full restore works.
Microsoft 365 provides useful retention and availability features, but being in Microsoft’s cloud is not the same as having a backup designed around your recovery needs. Accidental deletion, overwritten files, retention settings, compromised administrator accounts, and long-term recovery requirements still deserve a separate decision.
Use the 3-2-1 rule — then protect one copy from change
A durable baseline is the 3-2-1 backup rule:
- Keep three copies of important data, including the working copy.
- Store them on two different types of systems or media.
- Keep one copy off-site.
Modern ransomware adds another requirement: at least one backup copy should be offline or immutable, meaning an attacker using your normal administrator credentials cannot simply delete or encrypt it.
An external drive that stays connected to the server may be a second copy, but it is not much of a defense if the same ransomware can reach both. A cloud backup is better only when its retention, authentication, and deletion controls are configured correctly.
Separate backup administration from everyday accounts, require MFA, and make sure failure alerts reach someone who is expected to act. These controls should connect to the wider cybersecurity baseline, not live as an isolated appliance in a closet.
Plan for more than ransomware
Cyber incidents get the headlines, but recovery plans are used for ordinary failures too:
- A laptop is dropped, stolen, or damaged.
- A server disk or power supply fails.
- Someone deletes or overwrites the wrong folder.
- An update breaks a line-of-business application.
- A Microsoft 365 account is compromised.
- Power or internet service is unavailable for an extended period.
- Weather makes the office inaccessible even though the systems are intact.
For businesses in the mountains, continuity may mean forwarding phones, giving key staff a safe remote-work option, maintaining a secondary internet path, or documenting a manual way to serve customers for a day.
The right answer is not automatically a duplicate of every system. It is the smallest reliable setup that keeps the business functioning until normal operations return.
Run a restore test before you need one
A backup should be treated as unproven until data has been restored from it.
At least quarterly for critical systems, choose a realistic sample and document:
- What was restored.
- Which backup copy was used.
- Who performed the restore.
- How long it took.
- Whether the restored data opened and worked correctly.
- What slowed the process down.
A file-level test is useful, but it does not prove that a database or full server can recover. Rotate the test: restore a deleted file one quarter, a Microsoft 365 item the next, and a complete application or server when the business risk justifies it.
The goal is not to produce a ceremonial report. It is to catch missing credentials, expired subscriptions, incomplete jobs, slow downloads, and undocumented dependencies while the original system is still working.
Put the first hour on one page
When something fails, your team should not improvise around the affected system. Write a one-page recovery sheet and keep a printed copy somewhere accessible.
Include:
- The person authorized to declare an incident and set priorities.
- Your IT partner, internet provider, software vendors, insurer, and legal contact.
- The systems that must return first.
- Where recovery credentials and documentation are stored.
- A reminder not to erase, reboot, or reconnect affected equipment until the technical lead advises it.
- How staff and customers will receive updates.
- The approved temporary process for phones, scheduling, payments, and remote work.
Do not put passwords directly on the sheet. Point to a protected password vault and make sure more than one authorized person can reach it.
A 30-minute backup check for owners
You can find most dangerous gaps without buying anything. Ask whoever handles IT to show you:
- Today’s successful jobs and any unresolved failures.
- The complete list of protected systems and cloud services.
- Where the off-site or immutable copy lives.
- The date and result of the last restore test.
- The expected data loss and recovery time for the most important application.
- The written first-hour recovery procedure.
If any answer is “we think,” “the vendor handles it,” or “we have never tried,” put that item at the top of the list.
What good looks like
A practical recovery program for a small business is not flashy. Backups run on the schedule the business requires. Failures create action instead of sitting unnoticed. At least one copy survives compromised credentials or damaged equipment. Restores are tested. Staff know who makes decisions and how to keep basic service moving.
For many clients, we manage that as part of an ongoing managed IT relationship. We also take focused backup assessments and recovery projects when a full support plan is not the right next step.
Not sure what would happen if your main system went down today? Contact New River Technology. We will help you map the important workloads, set realistic recovery targets, and identify the first gap worth fixing — without turning a small-office plan into an enterprise binder.