A backup you haven't restored is a guess.
Disaster Recovery & Business Continuity
One day, Chaosstops knocking and just kicks the door in. Ransomware locks your files. A volunteer deletes the wrong database. A storm takes out the office. The one staffer who held every password gives notice. It isn't if— it's when.
And here's the cruel part: The Mundaneset you up for it months earlier, whispering “your backups are probably fine” every time you thought about checking. Continuity planning is simply how your mission survives a bad day. IP Bot tests the restore before the disaster; Masked Crewsader keeps the mission moving while you recover. Let's make sure the bad day is survivable.

Disaster doesn't ask permission. But a team that's ready? It bends, it doesn't break. Your mission is too important to lose to one bad afternoon.
Two numbers run this chapter: how long you can be down (RTO) and how much data you can afford to lose (RPO). Pick them, then build backups that meet them — and test the restore. A backup you haven't restored is a guess. #AutomateThis!

Know your two numbers: RTO & RPO
RTO — Recovery Time Objective
How long can you be down? If your donation page or case database vanished, how many hours (or days) until you must be back? That target shapes how much you invest in fast recovery.
RPO — Recovery Point Objective
How much data can you afford to lose?If you back up nightly, a crash at 4pm loses a day's work. If that's too much, you back up more often. Your RPO sets your backup frequency.
The Crew's playbook: the continuity checklist
- 1
Follow the 3-2-1 rule
Three copies of your data, on two different kinds of storage, with one copy off-site (and ideally offline). It's the backup standard for a reason.
- 2
Test your restores quarterly
Actually pull data back from a backup four times a year. An untested backup is a hope, not a plan.
- 3
Document critical systems and owners
List the systems your mission can't run without, and name a person responsible for each. No mystery systems.
- 4
Keep an emergency contact tree
Who calls whom when something breaks — staff, board, key vendors, your bank. Stored somewhere reachable when the main systems are down.
- 5
Keep offline copies of key documents
Insurance, bylaws, vendor contracts, account recovery info — printed or on a drive that isn't dependent on the system that just failed.
- 6
Write an "if X goes down" runbook
Short, plain steps for the likely disasters: email down, website down, database lost, ransomware. Future-you will be grateful.
- 7
Plan for people, not just servers
Cross-train so no single person is the only one who can run payroll, the donation page, or the database.
Your Recovery Plan at a glance
The plan becomes real when you write it down. One row per system your mission can't run without — how fast it has to come back, how much you can afford to lose, where the backup lives, and the date you last proved it restores:
| System | How fast back up (RTO) | How much loss OK (RPO) | Backup location | Last tested |
|---|---|---|---|---|
| Website | 4 hours | 1 day | Offsite cloud | YYYY-MM-DD |
| Donor/customer database | 8 hours | 1 hour | Offsite cloud + offline copy | YYYY-MM-DD |
| 2 hours | 1 day | Provider + offsite export | YYYY-MM-DD | |
| Financial records | 1 day | 1 day | Offsite cloud + printed copy | YYYY-MM-DD |
| File storage | 1 day | 1 day | Offsite cloud | YYYY-MM-DD |
The version of this table that protects you is the one with a recent date in every “Last tested” cell. A backup you haven't tested isn't a backup — so until that date is real, treat the row as a wish, not a plan.
Backups that actually work
The most expensive words in disaster recovery are “we thought we had a backup.” A backup isn't real until you've restored from it. Put a recurring reminder on the calendar, pull a file back from each backup, and confirm it opens. Do it quarterly. The day Chaos strikes is the wrong day to discover the backups were empty all along.
How Chaos & The Mundane win
- Backups that were set up once and never restored — and turn out to be empty when you need them.
- Single points of failure: one admin, one laptop, one person who knows the passwords.
- No plan for staff turnover, so knowledge walks out the door with the only person who had it.
- Assuming your SaaS vendor backs you up — many don't protect you from your own accidental deletions.
Common questions
▸ How often should we actually be backing up?
Let your RPO answer it, not a gut feeling. Ask: if everything since the last backup vanished, how much work could we stand to lose? If a day is fine, nightly backups are enough. If losing an afternoon of donations or case notes would be a disaster, you back up hourly — or continuously. The right frequency is the one that meets the loss you can live with, and not a minute more.
▸ Our files are in the cloud. Doesn't that mean they're already backed up?
Not the way you think. Cloud storage protects you from a dead hard drive — it does nothing about the volunteer who deletes the wrong folder, the ransomware that encrypts everything in sync, or the account that gets locked. Sync is not backup. You still need a separate copy, on different storage, that your live system can't reach in and ruin.
▸ What does "test the restore" actually mean — and how do we do it?
It means pulling real data back out of a backup and confirming it opens and looks right — not just checking that the backup job says "success." Put a recurring reminder on the calendar every quarter, restore a file or two from each backup, and open them. A backup you haven't tested isn't a backup; it's a guess wearing a backup's clothes.
▸ What's the difference between disaster recovery and business continuity?
Disaster recovery is getting the technology back — the servers, the database, the website. Business continuity is keeping the mission running while you do it: who answers the phones, how donors still give, where staff work if the office is gone. You need both. Recovering the database two days late doesn't help if the lights went out for the people you serve in the meantime.
The next leg of the journey
Prefer a story? See these ideas play out in our comic-book field guide, The Backup That Wasn't.
Ready to reach your Pitch?
You don't need a full-time CTO to do this right. Island Pitch works as your Fractional CTO — senior technology leadership at a nonprofit's budget, helping you choose well, lock the doors, and sleep at night.
Get the whole field manual
The full Right-Way Tech Guide — all seven chapters, plus an “if X goes down” runbook template.
The field manual is yours — grab it now.
Our signup form is being upgraded. In the meantime, here's the full PDF — no form to fill out.
Download the field manual (PDF)Want occasional tech tips by email too? Talk to a Fractional CTO above — we'll get you on the list.
