Cybersecurity and disaster recovery are often planned as separate projects — one focused on keeping threats out, the other on recovering if something goes wrong anyway. In practice, they're two halves of the same resilience strategy. This checklist brings them together as one practical list to work through.
Endpoint protection across every device
Every device that connects to your systems — laptops, desktops, mobile devices — is a potential entry point. A baseline worth checking:
- Is endpoint protection installed and kept up to date on every device, not just the obvious ones?
- Are personal or remote devices that access company systems covered by the same standard?
- Is protection actively monitored, not just installed and forgotten?
Access control and account security
Weak or poorly managed access can significantly increase the risk of compromise:
- Are user accounts and permissions reviewed periodically, especially after someone leaves the organisation?
- Is multi-factor authentication used for email, remote access and other sensitive systems?
- Is remote access secured appropriately, rather than left broadly open for convenience?
Network security
- Are firewalls configured and kept up to date, not just installed at setup?
- Is Wi-Fi segmented appropriately — guest access separated from internal systems?
- Is there visibility into what's actually happening on the network, so unusual activity can be noticed?
Backup: covering what actually matters
A backup strategy is only as good as what it actually protects:
- Does backup cover all the systems and data that would genuinely disrupt the organisation if lost — not just the obvious file shares?
- How frequently does backup run, and does that match how quickly the data changes?
- Where are backups stored — and are they protected from the same event (fire, ransomware, hardware failure) that could affect the primary system?
Disaster recovery: the plan that's actually been tested
This is where many organisations' resilience quietly falls short — having backups is not the same as having a tested recovery process:
- Is there a documented disaster recovery plan, not just an assumption that backups "will work"?
- Has recovery actually been tested — restoring real data, not just confirming a backup job completed?
- Are recovery time expectations realistic and agreed, rather than optimistic guesses?
Cloud and hosted systems
If systems are hosted in the cloud, resilience planning still applies — cloud hosting reduces some risks but doesn't remove the need for backup, access control and a tested recovery plan for what's hosted there. See Cloud Hosting & Data Centre Services.
Compliance considerations
Depending on sector, organisations may need to meet specific security and resilience requirements — for example, healthcare organisations working toward Data Security and Protection Toolkit (DSPT) requirements. Security and backup practices should be built with the relevant requirements in mind from the start, rather than retrofitted later. The NCSC's cybersecurity guidance is a useful starting point for baseline practices regardless of sector.
This checklist provides general guidance and does not replace an organisation-specific security or compliance assessment.
Bringing it together
Cybersecurity keeps threats out; backup and disaster recovery make sure the organisation can recover if something gets through anyway. Treating them as one resilience strategy — rather than two separate projects — gives a much clearer picture of actual risk. See Cybersecurity and Backup & Disaster Recovery for how HighTech IT approaches this.
Frequently asked questions
How often should disaster recovery plans be tested? This depends on how critical the systems involved are and how much they change over time — the right frequency is worth discussing rather than assuming a generic schedule fits every organisation.
Is cloud hosting automatically more secure than on-site systems? Not automatically — cloud hosting changes where responsibility for certain security controls sits, but backup, access control and recovery planning are still needed regardless of where systems are hosted.
What's the difference between backup and disaster recovery? Backup is a copy of data that can be restored; disaster recovery is the broader plan for getting systems and operations back up and running after a disruptive event — a complete resilience strategy needs both.
If you'd like a clearer picture of your organisation's cybersecurity and disaster recovery posture, book a free consultation with HighTech IT.