Managed IT

Cloud Disaster Recovery Plan for UK Small Businesses: A Practical Guide

Owner and colleague reviewing a one page cloud disaster recovery plan at a window table in a small UK office
On this page

There is no server in the cupboard any more. Email, files, accounts and phones live in Microsoft 365 and a few cloud applications, and someone has probably told you that means you are covered. So what does disaster recovery mean now?

A cloud disaster recovery plan is a written, tested plan for getting the cloud services you depend on back to a working state, within a time you have chosen and with an amount of data loss you have accepted. The threat is unchanged: the Cyber Security Breaches Survey 2025/2026 (DSIT and Home Office) found that 46% of small businesses identified a breach or attack in the last 12 months.

Why "we are in the cloud" is not a disaster recovery plan

Cloud services run on a shared responsibility model. Microsoft keeps Microsoft 365 running. Your data is your responsibility. Microsoft's own Services Agreement says as much, recommending that customers regularly back up their content and data.

That leaves four gaps. Deleted items, accidental or malicious, are gone once the retention window passes. Ransomware on one laptop syncs encrypted files straight into OneDrive and SharePoint. A compromised admin account can empty mailboxes and remove users. And a provider outage leaves you with nothing to do but wait.

A cloud phone system fails with your internet connection too, so plan a mobile fallback you can switch on remotely.

The five decisions a cloud disaster recovery plan has to make

Traditional disaster recovery plans for IT assumed a server room to rebuild. Without one, a cloud disaster recovery strategy comes down to five decisions, written down. Make them and you have a disaster recovery plan for cloud services.

1. What you recover first, and what can wait

List every cloud service you use, who administers it and where the admin credentials are kept, then rank them.

  • Tier 1, recover first: identity (your Entra ID accounts and MFA), email, the line of business or accounts application, and the phone system.
  • Tier 2, recover next: shared files, the website, the CRM.
  • Tier 3, can wait: everything else.

Identity goes first because nothing else can be recovered until people can sign in; if the Entra ID tenant is locked or compromised, every other restore queues behind it.

2. How fast, and how much you can afford to lose: RTO and RPO

Recovery time objective (RTO) is how long a system can be down before the business suffers. Recovery point objective (RPO) is how much data, measured in time, you accept losing.

Take a 25 person accountancy practice in Dorset. For email, the practice might choose an RTO of four hours and an RPO of one hour. For its practice management system, an RTO of one working day and an RPO of four hours. For shared files, an RTO of one day and an RPO of 24 hours.

Those numbers drive the spend: an RPO of one hour for email means a backup every hour, not a nightly one. They are your numbers to choose, not ours to promise.

3. Where the recovery copy lives

Apply the 3-2-1 rule to a business with no servers. Copy one is the live data in the SaaS platform. Copy two is a cloud to cloud backup with a separate service, under separate credentials, so one stolen login cannot reach both. Copy three is immutable: nobody, not even your own admin, can alter or delete it for a set period, so ransomware cannot take the backup down with the data.

For most UK small businesses the cornerstone is cloud to cloud backup of Microsoft 365: mailboxes, OneDrive, SharePoint and Teams. We have written separately about what a good cloud backup solution looks like.

If you still run a server or virtual machines, cloud based disaster recovery is a different exercise: start with the six disaster recovery models.

4. Who does what, and how you talk when Teams is down

Name four roles: a decision maker who can authorise spend, a technical lead who runs the recovery, someone handling communications, and a supplier contact. For most small firms the technical lead is their managed IT support provider, so write down who you call there.

Print a contact sheet with your IT provider's number and your Microsoft tenant ID, and agree an out of band channel now, personal mobiles or a WhatsApp group, because the disaster may be the collaboration platform itself.

If personal data is involved, UK GDPR gives you 72 hours from becoming aware of a breach to report it to the ICO if it is likely to put people at risk, so name who makes that call.

5. How you know it works: testing

A plan that has never been tested is a hope. Three tests you can actually run:

  • Quarterly restore test. Restore one mailbox, one SharePoint library and one file, and time it against the RTO for that tier.
  • Annual tabletop. Walk the named roles through a ransomware scenario: who calls whom, and what is restored first.
  • After any change. New IT provider, new platform, new admin: test again.

Record the time achieved against the target. Most do not: the Cyber Security Breaches Survey 2025/2026 (DSIT and Home Office) found only 25% of businesses have a formal incident response plan, and the share of small businesses with a business continuity plan covering cyber security fell to 44% from 53% the year before.

A one page cloud disaster recovery plan template

Complete this in an afternoon and keep a printed copy somewhere that is not the cloud.

  • Services and tiers: every cloud service, its tier, its administrator and where the credentials are kept.
  • RTO and RPO per tier: the targets you have chosen.
  • Backup copies: where each copy lives, who holds those credentials, and which copy is immutable.
  • Roles and contacts: the four named roles, who makes the ICO call, and the printed contact sheet.
  • Test schedule and last result: date, what was restored, time achieved against target.
  • Review date: annually, and after any change of supplier, platform or key staff.

Disaster recovery as a service: does a small business need it?

Disaster recovery as a service means a provider keeps a ready to run copy of your servers or virtual machines and fails over to it. It makes sense if you still run servers, virtual machines or a line of business application that cannot be rebuilt from a SaaS backup, and your RTO is measured in hours.

If you are entirely Microsoft 365 and SaaS, DRaaS for small business in the UK is usually more than you need: cloud to cloud backup plus a written, tested plan is the proportionate answer. Our post on business continuity versus disaster recovery gives the wider picture.

What we do

We provide managed cloud backup for UK businesses from a base near Dorchester: cloud to cloud backup for Microsoft 365, immutable copies, regular restore testing and 24/7 monitoring by a UK team, on a predictable monthly cost with no long contracts. HGC holds Cyber Essentials and is a Microsoft Partner and Cloud Solution Provider.

If you are not sure whether your current backup would restore, get in touch. We will review your backup and disaster recovery position and tell you honestly where it stands.

Frequently asked questions

What is a cloud disaster recovery plan?

A written, tested plan for restoring the cloud services a business depends on after an outage, deletion, cyber attack or provider failure, within a chosen recovery time and with an accepted amount of data loss.

Is Microsoft 365 backed up automatically?

Microsoft keeps the service running and offers retention and recycle bins, but its own services agreement recommends customers back up their content. Deleted or encrypted data past the retention window is gone unless a separate backup holds it.

What is the difference between RTO and RPO?

RTO is how long you can be without a system before the business suffers; RPO is how much data, measured in time, you can afford to lose. Together they set how often you back up and how quickly you must restore.

How often should a disaster recovery plan be tested?

Test a restore at least quarterly, walk through a full scenario at least once a year, and test again after any change of supplier, platform or key staff. Record the time achieved against the target every time.

Related reading

6 Disaster recovery plan examples You Should Know

Managed IT

6 Disaster recovery plan examples You Should Know

In the face of unexpected disruptions, from localised flooding in Manchester to a critical server failure in a Glasgow office, having a robust disaster recovery plan is non-negotiable. It’s the strategic document that ensures your business can resume operations swiftly, minimise data loss, and prote

Business Continuity vs Disaster Recovery Explained

Managed IT

Business Continuity vs Disaster Recovery Explained

It's easy to get tangled up in jargon, but the difference between business continuity vs disaster recovery is actually quite straightforward. Think of Business Continuity (BC) as the big-picture strategy. It’s a proactive plan designed to keep the entire business afloat during a crisis. On the other

What Is Infrastructure as a Service A Guide to the Cloud

Managed IT

What Is Infrastructure as a Service A Guide to the Cloud

Think of Infrastructure as a Service (IaaS) as renting the foundational tools for your digital operations. Instead of buying and managing your own physical servers and data centre kit, you access these resources over the internet from a cloud provider, usually on a pay-as-you-go basis. What Is Infra

Talk to a real IT team

Plain-English advice from a UK team that picks up the phone. Call 01305 310006 or email [email protected].