Cycle count: counting stock continuously instead of once a year
Cycle counting replaces the annual shutdown with twenty minutes a day. It finds errors while their cause is still identifiable, which is the part that actually improves accuracy.
A disaster recovery plan is not a binder. It is a short document that says who decides, who calls whom, and in what order things come back — written while nobody is panicking.
A disaster recovery plan sets out how a business restores its systems and data after something breaks badly — ransomware, a failed server, a flooded office, a provider outage that lasts days rather than hours. It is the technical half of the broader question covered in business continuity plan, which is about keeping the business running by any means while recovery happens.
The version most small businesses need is two pages, not a binder. What kills recovery is rarely the absence of a procedure; it is that nobody knew who was allowed to decide, the credentials were in the system that went down, and the backup had not been tested.
Keep a copy offline. A plan stored only in the system that failed is a plan you cannot read during the event it was written for, and this is not a hypothetical failure — it is the most frequently reported problem in ransomware recovery. One printed copy at home, or a file on a phone, costs nothing.
A full failover rehearsal is out of reach for most small businesses, and a tabletop walkthrough is not. Take an hour, pick a scenario, and talk through who does what — you will find three missing things, and finding them costs nothing. Beyond that, the specific thing worth actually doing is restoring a real file from a real backup and timing it, because the gap between having backups and being able to restore is where most of the surprise lives.
It deserves separate mention because it breaks the usual assumption: your backups may be encrypted too, if they were reachable from the machine that was infected. That is the argument for at least one copy that is offline or otherwise not writable from your network. On paying, the position of most law enforcement is that it funds the next attack and does not reliably return the data, and in some jurisdictions payment carries legal exposure of its own. That is a decision for the business with proper advice, not one to improvise at 2am — which is precisely why the plan should say who makes it.
Ettex Records holds the plan, the contact list and the test log as entries with owners and review dates, so that the annual review is visible rather than remembered. The immediate-response side is covered in incident response plan and the wider continuity question in business continuity plan.
Being clear: we are not a backup or disaster recovery provider. There is no failover, no replication, no recovery service. What we hold is the document — and the document is the part that is usually missing.
Disaster recovery is restoring systems and data. Business continuity is keeping the business operating by any means while that happens, including manually.
Recovery time objective is how long you can be down; recovery point objective is how much data you can afford to lose, measured in time. Both should be stated per system.
A tabletop walkthrough annually, and a real restore of a real file at least twice a year. The restore test is where the unpleasant surprises are.
Keep one copy offline. A plan stored only in the system that failed cannot be read during the event it was written for, which is a routine failure in ransomware recovery.
Cycle counting replaces the annual shutdown with twenty minutes a day. It finds errors while their cause is still identifiable, which is the part that actually improves accuracy.
Appointing a data protection officer is a legal requirement for some organisations and a bad idea for others — because the role carries independence obligations that a part-time volunteer cannot meet.
Records management is not filing. It is deciding in advance what a business must be able to produce, for how long, and what happens to everything else — because keeping everything is a liability, not caution.