Imagine opening the laptop tomorrow and finding that your customer records, invoices and saved passwords are unavailable. Now imagine the same thing happened to the shared drive or the inbox where customers contact you. Which service do you restore first, who has the administrator access, and how would customers know what is happening?
For a solo operator, the answer cannot be ‘ask the IT department’. A small team might have a provider, but that provider cannot recover data it was never asked to protect. Recovery starts with a short inventory and an actual restore test, not a reassuring green badge in a hosting dashboard.
Write down the minimum viable business
List what you need to operate for the next working day: customer contact information, invoicing, the website, online bookings, supplier orders, payroll, shared documents and any specialist application. Put an owner and a provider beside each one. Record what would happen if it was unavailable for a few hours, a day and a week. You do not need to put a dollar figure on everything to see which dependency comes first.
For each service, ask two questions: how much recent work can we afford to lose, and how quickly must we get back online? Those are recovery-point and recovery-time objectives, but plain answers are more useful than acronyms: ‘we can re-enter one day’s bookings’ or ‘customers need a working contact method by tomorrow morning’. Treat them as planning targets, not promises a provider has already made.
Back up the thing you actually need
A laptop backup may miss the booking system. A web host backup may omit the domain, DNS records, mailbox and third-party integrations. A cloud sync folder is convenient, but synchronisation can propagate deletions and unwanted changes. Take an inventory across devices, mail, file storage, business applications, website files and database, domain/DNS settings and the credentials needed to restore them. Ask each supplier exactly what they back up, how far back their copies go, who can request a restore and what it costs.
The Australian Government’s cyber security checklist recommends regular backups and testing them, as well as MFA and software updates. Keep at least one recoverable copy independent of the account whose loss you are planning for. Protect backup administrator access too; an attacker with the same credentials as your everyday account should not be able to erase every usable copy.
The restore test is the evidence
Pick a file and restore an older version to a safe location. Check that it opens, the permissions are sensible and a colleague can find it. For a website, test a restore in a staging environment rather than overwriting the live site. Check that the database, uploads, form notifications and essential plugins work together. Record the steps, the time taken and the gap between the backup and the failure you simulated.
Repeat on a schedule that reflects how much data the business changes. Also test after changing your host, email provider, booking system or backup configuration. A backup that has never been restored is an untested assumption.
Secure the accounts needed to recover
Start with the mailbox used for password resets, the domain registrar, password manager, cloud workspace and hosting account. Set up MFA, remove stale administrator access and store recovery codes securely. Decide who is authorised to contact each provider if the owner is unavailable. Do not place the only recovery instructions inside the inbox you might lose.
Domain and email recovery overlap but are not identical. Our domain and email continuity checklist explains the registrant, registrar, DNS and billing roles. Losing a .au domain during the expiry grace period can interrupt the website and mail together, so keep a separate renewal reminder.
If something fails tomorrow morning
- First, establish scope. Is one device affected, a whole account, the domain or the provider? Use a known-good device and an independent contact channel.
- Preserve what you can. If you suspect an intrusion, do not casually wipe devices or delete logs before recording the facts and seeking appropriate incident help.
- Contain account access. Revoke compromised sessions, change credentials from a safe device and check administrator roles, MFA methods and forwarding rules.
- Restore in business order. Bring back the minimum viable customer contact path first, then the remaining applications and records according to your inventory.
- Communicate plainly. Tell affected customers what is known and when you will update them; do not speculate about a breach before establishing the facts.
If personal information may have been accessed, work out whether the OAIC’s Notifiable Data Breaches scheme applies to your organisation and the particular incident. Not every small business is covered and not every incident meets the notification threshold. If you are unsure, get advice promptly rather than assuming either outcome.
A realistic 60-minute exercise
Choose a scenario: ‘our principal laptop is gone’ or ‘the shared mailbox is locked’. Give yourself an hour to identify the account owner, locate an independent recovery method, find the latest backup and restore one non-sensitive item. Write down each place you got stuck. This is not a race to earn a badge; it tells you exactly what to improve before the event is real.
Run the WordPress security checklist for your site’s day-to-day controls, then revisit the restore procedure with the same seriousness. SenseICT can help assess ICT dependencies, practical backups and recovery processes for a small business; DomainCastle provides managed WordPress hosting where that is the right fit, but no host replaces a plan for your domain, inbox and business records. Talk to Matt if you want a second pair of eyes on the recovery path.