Backup is not disaster recovery: the difference that saves businesses

Having backups and being able to recover are two different capabilities. Why untested backups fail when it counts, and what a real recovery posture looks like.

Ask a business if they have backups and nearly everyone says yes. Ask when they last restored something from those backups, and the room goes quiet.

That silence is the gap between backup and disaster recovery — and it’s where businesses actually get hurt.

Backups answer “is my data copied?” Recovery answers “is my business running?”

A backup is a copy of data. Disaster recovery is the proven ability to get your business operating again within a known amount of time. The difference sounds academic until 9 AM on the day your file server dies, and you discover:

  • The backup job has been silently failing since March.
  • The backups work, but restoring 4 TB over your internet connection takes six days.
  • The data restores fine, but the application it belongs to needs a server, licenses, and configuration nobody documented.
  • The ransomware that hit your systems also encrypted the backups, because they lived on the same network with the same credentials.

Every one of those is a real pattern, and none of them is discovered by looking at a dashboard that says “backup completed.”

Two numbers that matter more than “we have backups”

A real recovery posture starts with two numbers, decided by the business rather than the IT department:

RPO — how much data can we afford to lose? If the answer is “an hour,” nightly backups don’t meet it, no matter how reliable they are.

RTO — how long can we afford to be down? If the answer is “one business day,” then your recovery plan needs to produce working systems — not just restored files — in under a day. That has consequences for where backups live and what infrastructure is on standby.

Most businesses have never written these numbers down. Deciding them takes an afternoon and reshapes the entire conversation.

What we consider table stakes

For the environments we manage, backup looks like this — and we’d argue this is the minimum for any business that would be harmed by data loss:

  1. The 3-2-1 rule: three copies, two different media or platforms, one off-site.
  2. At least one immutable copy — a backup that can’t be altered or deleted, even with administrator credentials. This is your ransomware insurance.
  3. Automated verification — every backup job checked, every failure investigated same-day, not discovered during an emergency.
  4. Scheduled restore tests — actually recovering systems onto real infrastructure, on a calendar, with the results documented. A backup you haven’t restored is a hypothesis.

The uncomfortable question

If your current provider — or your internal team — can’t tell you your RPO, your RTO, and the date of the last successful restore test, you don’t have disaster recovery. You have hope, with a dashboard.


Cloud Square runs tested, ransomware-resilient backup and recovery as part of its managed infrastructure. Ask us for a recovery readiness check.