Almost every business has backups. Far fewer have ever restored from one. The gap between those two sentences is where companies discover, at the worst possible moment, that backup and disaster recovery are not the same product. Here is the difference, the two numbers that define what you need, and the test that tells you whether any of it works.
Backup is making copies of your data. Disaster recovery is the documented, rehearsed process for getting the business running again after something takes it down. They get sold together as backup and disaster recovery services, and they are not interchangeable.
A business with backups and no recovery plan still has all its data and no idea how long it will take to be operational. That gap is usually measured in days, and days is what closes companies. The published figures vary, but the pattern in them does not: extended downtime after data loss is survivable for large firms and frequently fatal for small ones.
The useful mental model is that backup answers "do we still have it" and recovery answers "when are we open again". You need an answer to both, and only one of them is a file.
Every serious conversation about this reduces to two numbers. Decide them before you look at a single product, because they determine the price and rule out most of the options.
How much data you can afford to lose, measured in time. Nightly backups mean an RPO of up to twenty-four hours: a failure at 4pm loses the whole working day. Continuous replication brings it to minutes. Ask what a lost day of work actually costs you and the right answer becomes obvious.
How long you can afford to be down. Restoring a server from cloud backup over a normal business connection can take a day or more. A local appliance that can spin the failed server up as a virtual machine brings it to under an hour, at a higher monthly cost.
Those two numbers, chosen honestly, produce a shortlist. Chosen aspirationally, they produce a quote nobody signs. Most small and mid-size businesses land on an RPO of an hour and an RTO of four, which is achievable without an enterprise budget.
The old rule still holds and is worth stating plainly, because most failures are a failure to follow it rather than a failure of technology.
The working copy plus two backups. One backup is a single point of failure wearing a reassuring name.
A local appliance and a cloud copy, not two folders on the same server. Ransomware does not respect folder structure.
Offsite covers fire and flood. Offline, or immutable, covers ransomware, which now routinely seeks out and encrypts the backups first. If your backup can be deleted using the credentials on your network, treat it as already gone.
An untested backup is a belief, not a control. Restores fail for dull reasons, silent job errors, a database that was never quiescent, a machine nobody added after it was built. Quarterly is a reasonable cadence, and the test should be a real restore rather than a green tick in a dashboard.
Cloud-only backup for a small business typically runs $8 to $25 per protected workstation per month and $60 to $200 per server, scaling with retained volume. It gives a good RPO and a poor RTO: your data is safe, and you will be waiting a while.
A hybrid appliance, local device plus cloud replication with the ability to run a failed server virtually, generally starts around $300 to $700 per month for a small environment. That is the real cost of a sub-hour RTO, and for any business where a day offline is not survivable it is the honest price of the requirement.
Compare it against the cost of the outage rather than against the cheaper product. A ten-person firm losing a full day of billable work, plus the recovery effort, plus the client conversations, is usually looking at more than a year of the appliance in one incident.
Backup and disaster recovery works best inside a managed agreement rather than bought alone, for the same reason smoke alarms work better when someone tests them. Somebody has to notice the failed job, add the new server, run the quarterly restore, and keep the recovery plan current as the business changes. Left as a product you bought, it quietly decays.
We include backup, monitoring of the backup, and tested restores in the base agreement for clients across British Columbia, with technicians in Vancouver and Victoria for the situations where recovery needs someone in the room. If you are working out what belongs in a base agreement at all, our guide to what a managed service provider does is the place to start.
If the answer is "we would have to check", that is the finding. Tell us what you are running and we will tell you honestly what your recovery time looks like today and what it would take to shorten it.
{ Book Your Consult