Business Continuity & Disaster Recovery
Superstorm Sandy knocked out power to 2.7 million New Jersey homes and businesses for days — and most small businesses that closed during that week never reopened. If your disaster recovery plan for small business is a Word document no one has opened since the last administration, this guide is for you.
In This Article
- Why a Written Plan Isn't Enough (And What NJ Businesses Get Wrong)
- The Four Decisions Every NJ SMB Must Make Before Writing Anything
- Building the Plan: What Goes In, Section by Section
- Testing: The Step 90% of Small Businesses Skip
- Frequently Asked Questions
- Not Sure If Your Current Backup Plan Would Survive a Real Disaster?
Why a Written Plan Isn't Enough (And What NJ Businesses Get Wrong)
A documented disaster recovery plan that has never been tested is not a safety net — it's a false sense of security. FEMA data shows that nearly 40% of small businesses never reopen after a disaster. Having a plan on file does not change that number. Testing does.
NJ's Specific Risk Profile Changes the Calculus
Most national DR guides treat "disaster" as a generic concept. For your business in NJ, the threat list is concrete: hurricane season storm surge along Monmouth, Ocean, and Atlantic county coastlines; nor'easters that knock out power to densely built commercial corridors for days; and inland flooding from the Passaic and Raritan river basins, which regularly inundates office parks that look perfectly safe on a map.
The Route 1 and Route 9 corridors are lined with strip-mall office suites and small office parks where multiple tenants share a single data closet or utility feed. When one tenant's server room floods, the cascading failure can take down neighboring businesses on the same circuit or the same fiber run — a risk that no generic SBA or FEMA template acknowledges.
The fix isn't a better document. It's treating small business disaster recovery as an ongoing managed discipline — with a test cadence, a named owner, and a backup architecture built for NJ's real threat environment.
The Four Decisions Every NJ SMB Must Make Before Writing Anything
Before you write a single procedure, four decisions shape everything else in your business disaster recovery plan. Skip them and you'll produce a document that sounds complete but fails when you actually need it.
- Set your RTO and RPO in real operational terms. "We need to be back up fast" is not an RTO. "We cannot be down more than four hours on a Tuesday during month-end close, and we cannot lose more than two hours of transaction data" is. RTO and RPO for small business should be tied to specific business events — payroll runs, client billing cycles, POS peak hours — not IT jargon.
- Identify your two or three truly critical systems. Every business has a short list of systems where downtime immediately costs money or creates legal exposure — ERP, point-of-sale, VoIP, practice management software. Separate those from everything else. Your DR plan should recover the critical systems first; the rest can wait.
- Name a human owner who is not the person managing the incident. In a 10-to-50-person NJ business, the person who knows the backup system is often also the person fighting the live outage or ransomware attack. Your plan must name a backup decision-maker — by name, not job title — who can authorize recovery steps when the primary IT contact is unavailable.
- Choose your backup architecture with NJ's physical risks in mind. Local-only backup — a NAS or external drive in your office — fails completely when a nor'easter floods your server room or a fire takes out the building. Hybrid cloud backup, which maintains a local copy for fast restores and a geographically separate cloud copy for catastrophic events, is the architecture that survives NJ's real disaster scenarios.
Building the Plan: What Goes In, Section by Section
A business continuity and disaster recovery plan for an NJ small business needs six defined sections. Most businesses have a static document covering maybe two of them — last updated years ago and stored somewhere no one can find under pressure.
The Six Required Sections
- Asset inventory: Every server, workstation, cloud application, and network device — with owner, location, and criticality tier.
- Risk register: A prioritized list of threats weighted for your actual location. For most NJ businesses this means ransomware at the top, followed by utility outage, flooding, and hardware failure — listed by likelihood and impact for your specific address, not alphabetically.
- Communication tree: Who calls whom, in what order, using what channel, when primary communication methods are down. This includes staff, clients, and vendors — and it must be accessible offline.
- Recovery procedures by system: Step-by-step restore sequences for each critical system, written so that someone other than your primary IT contact can execute them. "Restore from backup" is not a procedure.
- Vendor contacts: Your ISP, cloud backup provider, and MSP — with account numbers, escalation contacts, and SLA terms.
- Test schedule: For NJ businesses in pharma, financial services, or healthcare, this section is legally material. The NJ Identity Theft Prevention Act, HIPAA, and SEC requirements for registered investment advisers all create documentation obligations that a dated, untested plan does not satisfy.
CNS Data Inc. provides managed IT services for New Jersey businesses that treat DR planning as a living managed service — not a one-time document hand-off.
Testing: The Step 90% of Small Businesses Skip
An untested disaster recovery plan gives you confidence without capability. Testing is the only step that converts a document into a verified recovery capability — and it catches failure modes that no amount of careful writing will reveal.
Three Test Types, One Specific Failure Mode to Watch For
There are three test types every NJ SMB should understand:
- Tabletop walkthrough: The team talks through the plan scenario by scenario, identifying gaps without touching production systems. Run this quarterly.
- Partial failover test: A single critical system is actually restored from backup in an isolated environment. Run this twice a year.
- Full simulation: A complete recovery drill treating a named scenario — nor'easter power loss, ransomware encryption — as if it were real. Run this annually for businesses with compliance obligations.
The failure mode competitors don't mention: backup jobs that complete successfully but produce corrupted restore files. A green checkmark in your backup dashboard confirms the job ran — it does not confirm the restore works. Only an actual restore test catches this. Businesses that discover corrupted backups during a real incident discover it too late.
CNS Data Inc. is serving businesses across Northern and Central New Jersey with on-site and remote DR support — including restore verification as a standard part of managed backup.
Frequently Asked Questions
What is a disaster recovery plan for a small business?
A disaster recovery plan for a small business is a documented, tested set of procedures for restoring critical systems and data after a disruption. It defines who acts, in what order, and within what time window — covering ransomware, power outages, flooding, and other events specific to your location and industry.
Does every small business need a disaster recovery plan?
Yes. Any business that relies on digital data, email, or software to operate needs a DR plan. Regulated industries — healthcare, financial services, pharma — face legal obligations on top of the operational risk. Even a one-page, tested plan is significantly better than none.
What are the 4 phases of disaster recovery?
The four phases are: (1) Mitigation — reducing the likelihood or impact of a disruption before it happens; (2) Preparedness — building and testing the plan; (3) Response — executing recovery procedures during an active incident; and (4) Recovery — restoring full normal operations and documenting lessons learned.
How long does it take to build a disaster recovery plan?
A working first version for a 10-to-50-person business typically takes two to four weeks when guided by an MSP — covering asset inventory, RTO/RPO setting, procedure documentation, and an initial tabletop test. Building it internally without outside help often stretches to several months or stalls entirely.
What is the difference between a disaster recovery plan and a business continuity plan?
A disaster recovery plan focuses on restoring IT systems and data after a disruption. A business continuity plan is broader — it covers how the entire business operates during a disruption, including staffing, client communication, and temporary workarounds. Most small businesses need both.
What happens if a small business has no disaster recovery plan during a ransomware attack?
Without a tested plan, a ransomware attack leaves a small business choosing between paying the ransom or losing data permanently. Recovery time without a plan is measured in days or weeks, not hours. Businesses in regulated industries also face compliance exposure on top of the operational loss.
What should a small business disaster recovery plan include?
A small business disaster recovery plan should include an asset inventory, a risk register weighted for local threats, an offline communication tree, step-by-step recovery procedures for each critical system, vendor contacts with account numbers, and a written test schedule. NJ businesses in healthcare, financial services, or pharma should treat the test schedule as a compliance document.
Not Sure If Your Current Backup Plan Would Survive a Real Disaster?
Book a free 30-minute IT risk conversation with a CNS Data advisor — we'll review your current backup setup and tell you exactly where the gaps are before they become a crisis.
Book Your Free IT Risk Conversation