What Is Backup & Disaster Recovery (BCDR) — and Why It's Not Optional
What is backup and disaster recovery (BCDR)?
Backup and disaster recovery (BCDR) is the combination of two things: copies of your data (backups) and a tested plan for restoring your systems and operations quickly after an outage, ransomware attack, hardware failure, or natural disaster. A backup answers "can we get the data back?" Disaster recovery answers "how fast can the whole business run again?"
Isn't a backup enough on its own?
No — and this is where most small businesses get caught. A backup is a copy of files. Disaster recovery is the plan and infrastructure that turns those files back into a working company: servers online, email flowing, staff logged in, phones ringing. Plenty of businesses discover the gap the hard way, when they have backups but no idea how to actually restore from them, how long it will take, or whether the backup even worked.
Think of it this way: a backup is a spare tire. Disaster recovery is knowing the tire is inflated, having the jack, and having practiced the change on the side of the road at night. One without the other leaves you stranded. If you're weighing a provider, this is a core piece of any serious backup and disaster recovery service.
What do RTO and RPO mean in plain English?
Two terms drive every BCDR conversation, and both are simpler than they sound:
- RTO — Recovery Time Objective: how long you can afford to be down before it seriously hurts. If your RTO is four hours, your systems need to be back within four hours of an incident. It's a target for time.
- RPO — Recovery Point Objective: how much data you can afford to lose, measured in time. If your RPO is one hour, your backups run often enough that you'd never lose more than an hour of work. It's a target for data freshness.
A dental office might tolerate a longer RTO but almost no data loss. An e-commerce shop might need both to be near zero. Setting these numbers honestly — per system, not one blanket answer — is the foundation of a real plan. A good provider or virtual CIO helps you set them against what downtime actually costs your business.
Why are immutable, tested backups the part that matters most?
Two words separate a backup that saves you from one that fails you: immutable and tested.
Immutable means the backup can't be altered or deleted once written — not by an admin, not by malware, not by an attacker who's been in your network for weeks. This matters because modern ransomware hunts for backups first. Encrypt or wipe the backups, and the victim has no choice but to pay. Immutable storage (often called object lock or WORM — write once, read many) makes that impossible. It's a central reason immutable backups now sit at the heart of any managed cybersecurity program.
Tested means someone actually restores from the backup on a schedule and confirms it works. An untested backup is a guess. The failure mode is brutally common: the backup job has been silently erroring for months, or it captured the files but not the database that makes them usable, and nobody notices until the day they desperately need it.
A widely used starting framework is the 3-2-1 rule: three copies of your data, on two different types of media, with one copy off-site. Many providers now extend it to 3-2-1-1-0 — adding one immutable/offline copy and zero errors on recovery verification.
What does ransomware have to do with disaster recovery?
Everything. Ransomware has quietly become the most likely "disaster" a small business will ever face — far more common than a flood or fire. A solid BCDR setup is the single best answer to a ransom demand, because it lets you restore clean data instead of paying criminals and hoping they hand back the keys. Recovery and prevention work together: strong backups on the recovery side, and layered defenses on the prevention side. If ransomware is your worry, pair this with our ransomware protection checklist to cover both halves.
What does good BCDR actually look like in practice?
- Written RTO and RPO targets for each critical system, tied to what downtime costs you.
- Automated backups running on a schedule that meets those RPO targets.
- At least one immutable and one off-site copy that ransomware can't reach.
- Regular, documented test restores — not just "the backup job says success."
- A written runbook: who does what, in what order, with which vendor contacts, when systems go down.
- Coverage for cloud apps too. Microsoft 365 and Google Workspace are not backed up for you by default — that's your responsibility.
Most small teams don't have the time or in-house expertise to build and maintain all of this, which is why BCDR is one of the most common reasons businesses bring on a managed provider in the first place.
Frequently asked questions
Is BCDR the same as just storing files in the cloud?
No. Cloud storage like Dropbox or OneDrive syncs your current files — if ransomware encrypts them, it syncs the encrypted versions too. BCDR keeps versioned, immutable, point-in-time copies you can roll back to, plus a plan to restore full systems, not just files.
How often should backups be tested?
At minimum quarterly, and after any major system change. Many managed providers run automated test restores far more frequently and verify them monthly, so a broken backup is caught in days, not discovered during an actual emergency.
Does Microsoft 365 back up my email and files for me?
Not in the way most people assume. Microsoft protects its own infrastructure, but recovering data you deleted or that was maliciously destroyed is on you. A third-party backup for Microsoft 365 is a standard part of a complete BCDR plan.
Want to compare providers who do this right? Compare vetted providers — free.
