| A backup and recovery plan is a written record of how your business copies its important data and how it gets that data and its systems working again after something goes wrong. It names what is protected, where the copies live, how often they are made, who owns the plan, and what happens first when you need it. For a small business it can be a single page. |
Most owners think hard about this on the worst possible day. A file vanishes, a laptop is stolen, or an email arrives saying your systems are locked, and the only question that matters becomes: do we have a copy, and can we get it back?
Answering that before the emergency is the entire point of a backup and recovery plan. Most writing on the subject is aimed at IT professionals. This page is not. It is the plain-language starting point for an owner or manager who wants to know what they actually need, and which of the four documents people keep mentioning is the one for them.
What is a backup and recovery plan?
A backup and recovery plan is two ideas joined together and written down. Backup is making copies of your important data so you still have it if the original is lost. Recovery is getting that data and your systems working again afterwards. The plan is the record of how both happen and who is responsible for making sure they do.
That is the whole of it. It does not have to be a thick technical document, and length is not a measure of quality. What matters is that it exists, that one person owns it, and that somebody has restored something from it so you know it works before you need it.
The New Zealand government makes the ownership point plainly. The NCSC’s guidance for businesses states that as the owner you are responsible for managing your data, including making sure it is backed up, and that regardless of who actually runs the backups you need to understand what is being backed up, how often, how long copies are kept, and where the offline copies are stored. Those four questions are a fair test of whether you have a plan or just a service.
Do you need a backup and recovery plan or a disaster recovery plan?
Most businesses need a backup and recovery plan first, and a disaster recovery plan once they have one. The four documents people mention in this conversation answer different questions, and the reason they get confused is that nobody explains which is which.
| What it is | The question it answers | Start here if |
|---|---|---|
| A backup | Do we have a copy of the data? | You have nothing at all. This is the raw ingredient rather than a plan. |
| Backup and recovery plan | Do we have a copy, and can we actually get it back? | You are starting from scratch and want one page that covers both halves. |
| Disaster recovery plan | What order do systems come back in, and who does what? | Your backups are sorted and you need the response itself written down. |
| Business continuity plan | How does the business keep trading while IT is still down? | You need to keep serving customers through an outage, not just restore data. |
They are layers rather than competing options, and each one assumes the one above it. A disaster recovery plan is worth very little if the backups it depends on have never been restored, which is why the backup and recovery plan comes first for most small businesses.
What should a backup and recovery plan cover?
A backup and recovery plan needs five things, and you can write all of them in an afternoon.
- What you are protecting. A short list of the data and systems the business cannot operate without: email, accounting, customer records, the key files everyone works from.
- Where the copies live. At least one copy kept separately from your main systems, and at least one kept offline, so a single failure or a ransomware attack cannot reach both at once.
- How often it runs. Decided by how much work you could afford to redo. Daily is a floor, and anything taking in new customer data through the day needs more.
- Who owns it. One named person who checks it is working. Plans without an owner quietly stop being maintained, and nobody notices until the day it matters.
- What happens first. A short written description of the order things come back in and who to call. Anything longer than that belongs in a disaster recovery plan.
The copies question is where the standard applies. Our data backup strategy guide sets out the 3-2-1-1 rule in full: three copies, two media types, one offsite and one offline or air-gapped. The last one carries most of the weight, and it is the part the NCSC guidance singles out too.

Who should own the backup and recovery plan?
One named person in the business, not the IT provider. That distinction matters more than it sounds. Your provider runs the backups and can produce the evidence, but the accountability for the data sits with the business, and a backup and recovery plan owned by nobody inside the organisation drifts out of date within a year.
The owner does not need to be technical. Their job is to ask the four questions above at a set interval, confirm the answers have not changed, and get the plan updated when the business does. New system, new site, a staff member who leaves with something only they knew how to run: each of those quietly changes what the backup and recovery plan should say.
Review the backup and recovery plan at least once a year and after anything significant. That is the difference between a plan and a document, and it is the part most businesses get wrong, not the writing of the first version.
There is a compliance reason to name an owner as well. Under the Privacy Act 2020 you are required to take reasonable steps to protect the personal information you hold, and where a breach is likely to cause serious harm you must notify the Office of the Privacy Commissioner and the people affected. Being unable to recover information you were responsible for is not a good position to explain.
Where should a small business start if it has nothing in place?
Start by listing what you cannot lose, then find out what is already covered, then close the gap and write it down. None of the first three steps needs a budget or a technical person.
List what you cannot lose. Before any technology, write down the data and systems the business genuinely could not operate without. This list is the foundation of the whole backup and recovery plan and you can do it today.
Find out what you already have. Most businesses have something running and are unclear on what it covers. If you are on Microsoft 365, start with our Office 365 backup guide, because the retention windows are shorter than almost everyone assumes and that gap catches out more New Zealand businesses than any other.
Close the gap and write it down. Put protection in place for anything important that is not covered, name the owner, and write the five points in plain language. A simple document everyone understands beats a sophisticated one nobody opens.
Prove it. Restore something. Not check that the job ran, actually restore a file and open it. Until that has happened once, the backup and recovery plan is a hope rather than a capability.
Frequently Asked Questions
What is a backup and recovery plan?
A written record of how your business copies its important data and how it restores that data and its systems afterwards. Backup is the copies, recovery is getting back up and running, and the plan records how both happen and who is responsible. It does not need to be technical or long. For a small business a single page is enough, as long as it exists, has an owner, and has been tested.
What is the difference between a backup and recovery plan and a disaster recovery plan?
A backup and recovery plan covers the data: what is copied, where it goes, and how you get it back. A disaster recovery plan covers the response: what order systems come back in, who makes which decisions, and how long each step should take. Most small businesses need the first one before the second one is worth writing, because a response plan built on untested backups is not a plan.
Do small businesses really need a backup and recovery plan?
Yes, and usually more than larger ones, because a smaller business has less cushion to absorb weeks of disruption and is less likely to have someone watching the backups. Data loss through ransomware, accidental deletion, hardware failure or a stolen laptop affects businesses of every size. A short tested plan is one of the highest value protections a small New Zealand business can put in place.
Is my data already backed up by Microsoft 365 or Google?
Not in the way most people assume. Both keep their platforms running and secure, and neither guarantees to restore your individual emails and files after accidental deletion, a compromised account or ransomware. Retention windows are fixed and shorter than most people expect, and they start when something is deleted rather than when you notice. This is the single most common gap we find.
How often should backups run?
As often as your data changes, judged by how much work you could afford to redo. Daily is the practical floor for most businesses. The NCSC’s guidance suggests that anything taking in new customer information through the day should back up several times a day, and something that rarely changes can run weekly.
How do I know my backup actually works?
Restore something from it. Not confirm the job completed, actually recover a file and open it. A backup that has never been restored is an assumption, and the first attempt is where the problems show up. Do it once to prove the plan, then at a set interval after that.
Who should own the plan, us or our IT provider?
One named person inside the business. Your provider runs the backups and produces the evidence, and the accountability for the data stays with you. The owner does not need to be technical. They need to ask what is covered, how often, how long copies are kept and where the offline copy sits, and to get the plan updated when the business changes.
What is the 3-2-1-1 rule?
Three copies of your data, on two different media types, with one kept offsite and one kept offline or air-gapped. The offline copy is the part that matters most, because attackers commonly go after the backups they can reach over the network before encrypting anything. Our data backup strategy guide covers how to build it.
How long should a backup and recovery plan be?
Short enough that somebody can follow it under pressure. A backup and recovery plan is judged by whether it works on the day, not by its page count. For a small business one page covering the five essentials is genuinely enough. Length is not a measure of quality, and a long plan nobody has read is worth less than a short one everybody has.
Does the Privacy Act require a backup and recovery plan?
The Act does not name a specific technology. It requires you to take reasonable steps to protect the personal information you hold, and where a breach is likely to cause serious harm, to notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable. Being able to recover information you are responsible for is a practical part of meeting that duty rather than a stated requirement.
How often should the plan be reviewed?
At least once a year, and whenever something significant changes: a new system, a new site, a change in who does what. Businesses rarely fail at writing the first version. They fail at keeping it current, which is why naming an owner matters more than the format of the document.
NEXT STEP
When did anyone here last restore a file on purpose?
If the answer is nobody knows, that is the gap. An IT assessment tells you what is actually being backed up, how far back the copies go, whether one of them is offline, and whether a restore has ever been proved to work. We do this for businesses across Christchurch and Dunedin.
Or read more about our managed IT services.

