Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
Disaster recovery for a Canadian SMB means bringing critical IT systems back online after ransomware, hardware failure, cloud-region loss, or human error, inside a documented time and data budget. This guide covers what an owner-operated business of 15 to 200+ users should have in place by the end of 2026.
KEY TAKEAWAYS
- The six practices: documented RTO and RPO, 3-2-1-1-0 backup architecture, quarterly restore tests, written runbooks, explicit Microsoft 365 protection, and a post-event review.
- Backups without successful restore tests are not backups; they are unproven assumptions.
- Sophos put the median ransom payment at US$769,000 in its State of Ransomware 2026 survey of 2,158 organizations.
- PIPEDA sets no 72-hour breach clock. The test is reporting as soon as feasible, and keeping breach records for two years.
What is disaster recovery for a Canadian SMB?
According to the Canadian Centre for Cyber Security (2025), ransomware is the most disruptive threat facing Canadian organizations. The deciding factor in recovery is whether backups are segregated and restore-tested. A documented recovery-time and recovery-point objective separates a real plan from a hope.
Disaster recovery (DR) is the set of policies and tested procedures that restore systems and data after a disruptive event. For a Canadian SMB that scope covers Microsoft 365 mailboxes and SharePoint, line-of-business servers, domain controllers plus the daily file shares.
Untested restores are one of the 10 issues we find most often on day one. Across our 41 Canadian SMB client onboardings, our engineers found unverified backup chains more often than any other infrastructure gap. The full list sits in our guide to the most common IT problems in business.
Most Canadian providers align to NIST SP 800-34 Rev. 1, paired with ISO 22301. Both define the same idea. A plan is only real once it has been tested, dated and signed off.
Fusion Computing is a Canadian-owned managed IT and cybersecurity provider serving businesses with 15 to 200+ users since 2012. The team operates a 93% first-contact resolution rate, holds CISSP-led security leadership, and aligns delivery to CIS Controls v8.1 across Toronto, Hamilton, and Metro Vancouver.
DR vs BCP: how they differ
According to ISO 22301, continuity management covers the whole organization. NIST SP 800-34 Rev. 1 sits one layer down and governs the IT contingency plan. Canadian SMBs that fold the two into one document usually end up testing neither properly.
Business continuity planning (BCP) is the wider problem: how the company keeps serving customers when the office, the network or the people are unavailable. Disaster recovery is the IT subset, and it is the layer a 15 to 200+ user firm can realistically staff.
The split SMB leaders find useful. BCP answers where staff work, how the phones reroute, and which suppliers are called first. DR answers how Microsoft 365 mail is restored and how long the rebuild takes.
Not sure which systems have an owner-approved RTO? Talk to our team.
The 6 disaster recovery best practices every SMB needs
According to the Sophos State of Ransomware 2026, 56% of attacks succeeded in encrypting data. Only 1 in 3 smaller organizations stopped the attack before encryption. Average recovery cost reached US$1.7 million across the 2,158 organizations surveyed, with a median ransom of US$769,000.
What the six practices cover
In our experience the same six practices separate Canadian SMBs that recover in hours from those that never recover. Each is documented, tested and reviewed annually.
RTO and RPO: what they actually mean
According to NIST SP 800-34 Rev. 1, recovery objectives are set during the business impact analysis. That ordering matters, because it puts the number before the product. A Canadian SMB that picks a tool first ends up defending whatever recovery window that tool delivers.
Setting targets per system class
Recovery Time Objective (RTO) is the maximum time a system can stay offline after a disaster begins. Recovery Point Objective (RPO) is the maximum acceptable data loss, measured as the interval between successful backups.
Both are set per system class, never as one site-wide number. The financial server and the marketing file share rarely deserve the same recovery budget. The table below reflects targets Fusion Computing sees signed off across Canadian SMBs.
Backup architecture: 3-2-1-1-0 explained
According to Microsoft, Microsoft 365 Backup writes restore points to append-only storage. The service cannot overwrite them. Coverage runs to 10-minute recovery points for the prior two weeks and one-year retention that Purview policies do not shorten.
The 3-2-1-1-0 model extends the long-standing 3-2-1 rule. It adds the two requirements that close the most common Canadian SMB recovery failures: immutable storage, and proven restores that finish with zero errors.
What that stack looks like in practice
That stack is an image-based backup platform for servers and endpoints, an immutable off-site copy in a Canadian cloud region, and a dedicated Microsoft 365 backup. Microsoft Defender for Endpoint guards the production estate so the backup chain is harder to reach.
A migration window is the most common moment for a recovery gap to open. Our guide to cloud migration challenges covers the rollback planning that keeps restores intact through a Microsoft 365 tenant move.
Want a second opinion on whether your off-site copy is truly immutable? Book a consultation.
Restore testing: why backups without tests are not backups
According to the Canadian Centre for Cyber Security ransomware playbook, offline and verified backups decide whether an organization can refuse a ransom demand. Verification is a scheduled activity in that playbook, and not a property any backup product supplies on its own.
The most common DR failure we see in Canadian SMBs is a backup job green for two years that has never been restored. Green means the job ran. It does not mean the data came back.
A restore-test cadence that works
A practical SMB cadence is a quarterly sandbox restore of a sample server and a SharePoint site, plus an annual failover of a tier-1 workload. Each test produces a written record of the real RTO and any deviations.
FIELD NOTE FROM MIKE
In one Hamilton manufacturing client we onboarded in 2024, a 50 to 75 seat operation, the prior provider had reported green backups for 26 straight months. On the first quarterly restore test, two of three tier-1 SQL databases failed to mount. The agent had silently corrupted the chain.
We rebuilt on an immutable platform and documented a 4-hour RTO. On the retest we measured the real restore at just under three hours. That is why I treat “we have backups” as a starting point rather than an answer.
“I got the call no business owner wants. Our systems were locked and there was a ransom demand on every screen. Fusion had someone working on it within the hour, and by Monday we were operating normally again with no ransom paid.”
DR plan documentation: what should be in it
According to the Office of the Privacy Commissioner of Canada, PIPEDA sets no 72-hour clock. Reporting is due as soon as feasible once a real risk of significant harm is identified, and breach records must be kept for two years.
A working DR plan is a living document, owned by a named person, dated and stored in 2 places. One should be a printed copy reachable when the network is down. The steps must suit an on-call technician who has never seen the environment.
Minimum contents of a DR plan
At minimum the document includes:
- Scope and system inventory, each workload mapped to a tier.
- Tiered RTO and RPO targets, signed and dated by an owner.
- Named recovery roles and a contact tree with mobile numbers.
- Vendor contacts: internet provider, Microsoft tenant admin, backup platform, insurer.
- Runbooks for every tier-1 and tier-2 system.
- A communication plan for staff, customers, and the Privacy Commissioner.
- A test log with dates, scenarios, results and owners.
FIELD NOTE FROM MIKE
The DR plans that fail across our Toronto and Hamilton engagements are rarely the thin ones. They are the 40-page binders nobody owns. When I ask a 30 to 60 seat client who signs off the RTO and get a job title rather than a person, the plan has never been rehearsed. One named owner and one alternate beats 20 more pages of procedure.
The 5-step DR plan rollout
According to the IBM Cost of a Data Breach Report 2026, global average breach costs rose 12% year over year to a record high. IBM attributes the rise to detection, escalation and lost business. Lost business is the component a tested recovery program compresses.
For an SMB starting from scratch or replacing an inherited plan, the rollout is a five-step program running 6 to 10 weeks. Each step closes with a written artefact rather than a verbal sign-off.
- Discovery and business impact analysis (week 1 to 2). Inventory systems, interview department leads, and rank workloads by financial impact.
- RTO and RPO sign-off (week 3). Owner-approved targets per system class, recorded in the plan template.
- Architecture build (week 4 to 6). Move the backup stack to 3-2-1-1-0, with immutable storage and Microsoft 365 Backup.
- Runbook authoring and tabletop (week 7 to 8). Write the runbooks, walk the team through a tabletop scenario, and capture gaps.
- Live restore test and sign-off (week 9 to 10). Restore a tier-1 workload, measure against RTO, sign and date the plan, book the next test.
SMBs that outsource the program run the same five steps through managed IT services. The prevention layer sits in cybersecurity services, and the companion playbook is our incident response plan for small business in Canada.
Ready to put a dated, signed DR plan behind your tier-1 systems? Get in touch.
FAQ
How often should a Canadian SMB test its disaster recovery plan?
Run a quarterly partial restore test on representative tier-1 and tier-2 systems, plus a full annual failover simulation. Add a test after any major infrastructure change, application migration, or office move. Record the actual restore time against the documented RTO.
What is the difference between RTO and RPO?
RTO (Recovery Time Objective) is the maximum time a system can be offline after a disaster. RPO (Recovery Point Objective) is the maximum acceptable data loss, measured as the interval between backups. RTO governs recovery speed, RPO governs data freshness, and the two are independent commitments.
What does 3-2-1-1-0 mean in backup architecture?
3-2-1-1-0 means three copies of data, on two storage media, with one off-site, one immutable, and zero unverified restores. It extends the older 3-2-1 rule with explicit immutability and verification. The final zero is the one most Canadian SMBs skip.
Is Microsoft 365 backed up by Microsoft?
Microsoft 365 retention and recycle-bin features are not a point-in-time backup. Microsoft sells Microsoft 365 Backup separately for Exchange, OneDrive, and SharePoint, with one-year retention and 10-minute recovery points for the prior two weeks. Protecting that data stays a customer responsibility.
What standards govern disaster recovery in Canada?
Canadian organizations most commonly align to ISO 22301 and NIST SP 800-34 Rev. 1, supported by CIS Controls v8.1. None of the three are law in Canada. They are the reference frameworks insurers and enterprise customers ask about.
How much does disaster recovery cost for a small business?
Price is driven by RTO. Daily file-level backup with an off-site copy is the entry tier. Image-based backup with cloud replication and a documented 4-hour RTO is the mid tier. Hot-standby replication with a sub-hour RTO is the high tier. Most 15 to 200+ user firms sit in the mid tier.
What is the difference between disaster recovery and cyber insurance?
Disaster recovery is the capability to restore systems and data. Cyber insurance is a financial transfer that pays incident-response, legal and recovery costs. Modern policies want evidence of tested DR and immutable backups, often 12 months of restore logs. Without it, coverage is denied or the premium rises.
Can ransomware encrypt backups too?
Yes. Operators routinely target connected backup repositories and shadow copies before encrypting production data. The defence is immutable storage that cannot be altered for a fixed retention window, plus an off-domain backup identity. Sophos found 56% of 2026 attacks still encrypted data.
Who should own the DR plan in a small business?
In a 15 to 200+ user firm, ownership sits with the senior leader accountable for IT, often the COO, operations director or owner. Delivery falls to an internal IT lead or the managed service provider. The plan must name a primary and a backup owner by person, not by job title.
Does PIPEDA require breach notification within 72 hours?
No. PIPEDA section 10.1 requires reporting a breach of security safeguards to the Privacy Commissioner of Canada as soon as feasible. The trigger is determining a real risk of significant harm. No 72-hour clock exists in the statute, and breach records must be kept two years.
How long should a Canadian SMB keep disaster recovery test records?
Keep restore test logs at least 24 months, matching the two-year breach-record retention PIPEDA requires. Underwriters and procurement reviewers commonly ask for 12 to 24 months of evidence at renewal. A dated log of measured restore times against the RTO satisfies both.
What should we do first if we have never tested a restore?
Pick one tier-1 system and restore it to an isolated sandbox this quarter. Measure the real time from request to usable data, then compare it against the RTO the business assumes. In our experience that one test surfaces more gaps than a plan rewrite.
Related Resources
- Server management best practices, the hygiene backups depend on.
- Windows 10 end of support, with business ESU Year 1 closing October 13, 2026.
- Cyber insurance coverage checklist, to match controls to underwriters.
- IT operations best practices, for keeping DR events rare.

