Disaster Recovery Planning for Australian Businesses
Synopsis
A strong disaster recovery plan helps Australian businesses respond quickly to natural disasters, cyberattacks, system failures, and other disruptions. Discover the key steps to prepare, recover, and keep your business running.
Some industry estimates put average ransomware recovery downtime for Australian SMBs at around 22 days, although the figure varies. Not a weekend, not a rough week. Twenty-two days with systems locked, staff sitting idle and someone overseas waiting to see if you'll pay.
That's not a technology failure. It's a planning failure. Businesses with tested backups and documented recovery procedures are generally better positioned to restore operations faster. The ones that don't are the ones counting to 22.
DR vs Business Continuity - They're Not the Same Thing
People mix these up constantly and it matters.
| Disaster Recovery Plan (DR) | Business Continuity Plan (BCP) | |
| What it covers | IT systems - servers, data, applications | Business operations - people, communication, customer service |
| Focus | Getting technology back online | Keeping the business functioning during disruption |
| Who leads it | IT manager or MSP | Business owner or operations manager |
| When it activates | System failure, ransomware, data loss | Any disruption including non-IT events |
You need both. A BCP without a DR plan means you've got a communication strategy but nothing to run it on. A DR plan without a BCP means IT might come back online but nobody knows what to do in the meantime.
Two Numbers That Drive Everything
Before anything else, answer two questions for each system that matters to your business.
RTO - Recovery Time Objective. How long can this system be down before real damage happens? Two hours? A full day? That number drives the technology choices and the budget. A two-hour RTO costs very differently to build for than a 48-hour one.
RPO - Recovery Point Objective. If this system fails right now, how much data can we lose? If it's four hours, your backups need to run at least every four hours. If it's 24 hours, daily might be enough.
| System Type | Typical RTO Target | Typical RPO Target |
| Core business applications (ERP, CRM) | 2–4 hours | 1–4 hours |
| Email and communication | 4–8 hours | 4 hours |
| File storage and documents | 8–24 hours | 24 hours |
| Website / e-commerce | 1–2 hours | 1 hour |
| Non-critical internal systems | 24–72 hours | 24–48 hours |
Don't set these numbers from gut feel. Ask the people who actually use each system, they know faster than anyone how quickly a failure turns into a real problem.
What the Plan Needs to Actually Say
A plan that lives in someone's head is not a plan. It needs to be written down, accessible when your normal systems are offline, and known by more than one person.
| DR Plan Component | What It Covers |
| Asset inventory | Every system, device and application that matters - with owner and priority |
| Backup schedule | What's backed up, how often, where it lives |
| Recovery procedures | Step-by-step instructions clear enough for someone unfamiliar to follow |
| Roles and responsibilities | Who does what, who has authority to make decisions |
| Contact list | IT support, cloud provider, insurer, legal, key customers |
| Communication templates | Pre-drafted messages for staff and customers |
On backups specifically - the standard starting point is the 3-2-1 rule. Three copies of your data, on two different types of storage, with one copy offsite. In practice that usually means local backup, cloud backup, and immutable storage that attackers can't encrypt even with your credentials.Backup systems are increasingly targeted during ransomware attacks. In one Australian survey, 78% of affected organisations said attackers had at least partially compromised their backup and recovery options, while 35% said the attackers had completely compromised them. If your backups live on the same network with the same credentials as everything else, they're not really backups.
Testing- The Part Nobody Does Until It's Too Late
A backup that's never been tested is just an assumption. You don't know it works until you try to restore from it, and finding out it doesn't during an actual incident is the worst possible timing.
| Test Type | What's Involved | How Often |
| Tabletop exercise | Walk key people through a scenario - no systems involved, just people and the plan | Annually |
| Partial restore test | Actually restore a system or dataset from backup to confirm it works | Quarterly |
| Full failover test | Simulate complete failure and recover from backup end-to-end | Annually |
The tabletop is the easiest starting point. Get your key people in a room and walk through a scenario, it's 7am Monday, ransomware has locked your systems, what happens next? Half a day reveals gaps immediately.
The Insurance Angle
Cyber insurers are increasingly asking for evidence of tested DR procedures before issuing or renewing policies. Documented RTO and RPO targets, backup logs, records of restore tests these are showing up as standard underwriting requirements. If you can't show the plan exists and has been tested, coverage gets more expensive or harder to obtain.
There's also a legal angle worth knowing. Under the Cyber Security Act 2024, businesses with annual turnover above $3 million must report ransomware payments to the ASD within 72 hours of making one. That obligation exists whether you have a DR plan or not, but having one tends to mean you're less likely to end up in the position of having to make that payment in the first place.
What It Actually Costs
There's no standard number here. A small business with basic cloud infrastructure and a 24-hour RTO can build something workable for a few thousand dollars in setup and a few hundred a month in ongoing costs.
| Business Size | Estimated DR Setup Cost | Monthly Ongoing Cost |
| Small (1–20 staff) | $2,000–$8,000 | $200–$500 |
| Medium (20–100 staff) | $8,000–$30,000 | $500–$2,000 |
| Large (100+ staff) | $30,000–$100,000+ | $2,000–$10,000+ |
For context, ASD-linked reporting puts the average self-reported cybercrime cost at approximately $56,600 for small Australian businesses and around $97,000 for medium businesses. These figures cover cybercrime more broadly and should not be treated as universal ransomware-recovery costs. Against those numbers, the cost of building and testing a plan before something happens looks like the cheaper option by a significant margin.
FAQs
What's the difference between a DR plan and a business continuity plan?
A DR plan is specifically about recovering IT systems servers, data, applications. A BCP is about keeping the business running during a disruption more broadly communication, staffing, customer service. Both are needed and they work together.
How often should a DR plan be tested?
Quarterly partial restore tests at minimum, a tabletop exercise annually, and a full failover test at least once a year. The more critical your systems, the more frequently you should test.
Do Australian businesses have to report ransomware?
Covered entities, including businesses carrying on business in Australia with annual turnover above $3 million and certain critical-infrastructure entities, must report ransomware or cyber-extortion payments within 72 hours under the Cyber Security Act 2024. The obligation concerns payments, not every ransomware incident. Reporting incidents more broadly is encouraged through the ASD's ReportCyber portal regardless of size.
At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.