Backup and business continuity are frequently discussed as one thing. They are not. A backup answers “can we get the data back”. Continuity answers “can we keep operating”. A business can have excellent backups and still be unable to trade for a fortnight.
Backup: the two numbers that define it
Before choosing any tool, decide two things for each system:
- Recovery point objective — how much data can you afford to lose? If backups run nightly, you can lose a day. For a transactional system, that may be unacceptable.
- Recovery time objective — how long can you be without the system? Restoring several terabytes over a domestic-grade connection can take days regardless of how good the backup is.
These two numbers drive every subsequent decision, and most businesses have never stated them.
The rule that still holds
Three copies of your data, on two different media, with one held offsite or offline. The offline element matters specifically because ransomware seeks out connected backups and encrypts them alongside production data.
Immutable backups — which cannot be altered or deleted for a set retention period — are the current best defence against that, and are increasingly available in mainstream products.
An untested backup is a hypothesis
This is the single most common failure. Businesses discover during an incident that backups had been silently failing for months, that the backup did not include the database they most needed, or that nobody knew the restore procedure.
Test a full restore at least annually, and document how long it actually took. That number is your real recovery time objective, as opposed to the one you assumed.
What cloud services do and do not cover
A widespread and dangerous assumption is that data in Microsoft 365, Google Workspace or a SaaS accounting system is backed up by the provider.
Providers protect against their infrastructure failing. They generally do not protect against you or an attacker deleting data, and retention periods for deleted items are limited. A malicious or accidental mass deletion discovered after the retention window is unrecoverable.
Third-party backup for cloud services is a separate product and worth having for any business whose records live there.
Continuity: the wider question
Data is one dependency. A continuity plan should identify what the business actually needs to keep operating:
- People. Who can do the critical tasks, and what happens if the person who knows the payroll system is unavailable? Single points of knowledge are as risky as single points of technical failure.
- Premises. Where do people work if the building is inaccessible — fire, flood, cordon, seismic assessment?
- Systems and their interdependencies. Which system must come back first, and what depends on it?
- Suppliers. Which single-source suppliers would stop you, and what is the alternative?
- Communications. How do you reach staff and customers if your email is down — and is the contact list stored somewhere that survives the outage?
- Cash. Can you invoice and get paid if systems are unavailable?
The scenarios worth planning for
Rather than a generic plan, work through a handful of realistic events and what each would actually require: ransomware encrypting production systems, extended power or internet loss, loss of building access, loss of a key person, and failure of a critical supplier or SaaS provider.
Each has a different answer, and working them through surfaces dependencies nobody had documented.
The insurance gap
Business interruption insurance generally requires physical damage to your own property. A cyber incident, a supplier failure or a road closure will not trigger it unless specific extensions are in place.
Cyber insurance covers response costs, business interruption from a cyber event and liability following a data breach. If you depend materially on systems, check which of your covers responds to which scenario — the answer is often less than assumed.
The regulatory dimension
Where an incident involves personal information and serious harm is likely, the Privacy Act 2020 requires notification to the Privacy Commissioner and affected individuals as soon as practicable. That obligation runs during the incident, when everyone is busy, which is why the decision path should be written down beforehand.
CERT NZ provides free incident guidance to New Zealand businesses and should be in the plan by name and number.
A proportionate starting point
For a small business: write down the RPO and RTO for your three most critical systems, confirm backups actually cover them including cloud data, test one restore, list the five people or suppliers you could not operate without, and put the whole thing on two pages that exist somewhere other than the system it describes.
That is a weekend of work and it is more than most businesses have.
The National Cyber Security Centre and CERT NZ both publish free guidance for New Zealand organisations, written for a general audience.








