Defense

Disaster Recovery

The plans and capabilities that restore IT systems and data after a disruptive event.

Definition

Disaster recovery is the set of documented plans, procedures and technical capabilities that restore IT systems, applications and data after a disruptive event such as a hardware failure, ransomware attack, flood or power loss.

Disaster recovery is the technology component of a wider continuity picture. Two numbers define it. Recovery Time Objective (RTO) is how long a system may remain unavailable. Recovery Point Objective (RPO) is how much data you can afford to lose, expressed as a time window. Both are business decisions, not technical ones, and setting them honestly is most of the work.

In Indonesian banking the disaster recovery centre, commonly called the DRC, is a familiar concrete expression of this. A DRC is a secondary site holding the systems and data needed to keep operating if the primary site is lost, and supervisory expectations cover not just its existence but whether it has been proven to work.

The most common failure is not absence of a plan but absence of testing. A plan that has never been exercised tends to fail on details that only surface under pressure: expired credentials, undocumented dependencies, backups that restore but do not run, or a contact list where half the numbers have changed. Ransomware has made this sharper, because a recovery path that depends on backups reachable from the compromised network may itself be encrypted.

At a glance

Type
Resilience capability
Also known as
DR, DRP, disaster recovery plan, DRC, pemulihan bencana

How it works

  1. 1

    Classify systems by criticality, since not everything warrants the same recovery investment

  2. 2

    Set RTO and RPO per system with the business, not with IT alone

  3. 3

    Design the technical capability to meet those targets: backups, replication, a secondary site or region

  4. 4

    Document the runbook, including decision authority and the order of restoration

  5. 5

    Test, then fix what the test broke, then test again on a defined cycle

Key points

  • RTO is how long you can be down; RPO is how much data you can lose
  • Both are business decisions that IT implements, not the reverse
  • A disaster recovery centre is common practice in Indonesian banking and is subject to supervisory scrutiny
  • An untested plan should be assumed not to work
  • Backups reachable from the production network may be encrypted by the same ransomware event

Best practices

  • Keep at least one backup copy offline or otherwise immutable, so ransomware cannot reach it
  • Test restoration of actual data, not just the existence of backup jobs
  • Document dependency order, since systems rarely restore correctly in isolation
  • Rehearse the human side too: who declares a disaster, who communicates, and how staff verify identity when normal systems are down
  • Review RTO and RPO annually, because criticality shifts as the business changes

Real-world example

An Indonesian multifinance company holds nightly backups and a documented plan. During a ransomware incident the backups are found to be reachable from the same domain and encrypted alongside production. Recovery takes eleven days instead of the four-hour RTO on paper. The plan was real; the isolation of the backups was not.

How Claro helps

Recovery capability does not prevent the incident. In Indonesian organisations the most common trigger for a recovery event is ransomware, and ransomware most often enters through a person: an employee who opens an attachment or enters credentials on a convincing page. Claro measures and reduces that entry point, which is the cheapest place to intervene.

Frequently asked questions

What is disaster recovery?

Disaster recovery is the documented plans, procedures and technical capabilities that restore IT systems and data after a disruptive event. It is defined by two targets: how long a system may be down (RTO) and how much data may be lost (RPO).

What is the difference between RTO and RPO?

RTO, Recovery Time Objective, is the maximum acceptable time a system can be unavailable. RPO, Recovery Point Objective, is the maximum acceptable amount of data loss expressed as a time window. A four-hour RTO with a fifteen-minute RPO means back online within four hours having lost at most fifteen minutes of data.

What is a disaster recovery centre (DRC)?

A DRC is a secondary site holding the systems and data needed to keep operating if the primary site is lost. It is standard practice in Indonesian banking, and supervisory attention covers whether it has been tested, not only whether it exists.

What is the difference between disaster recovery and business continuity?

Disaster recovery is the IT restoration component. Business continuity is broader, covering how the whole organisation keeps functioning, including people, premises, suppliers and manual workarounds. Disaster recovery sits inside business continuity.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo