
Disaster recovery cost for a small business is set by two numbers you choose before any product is chosen: how much data you can afford to lose (the recovery point objective, or RPO) and how long you can afford to be down (the recovery time objective, or RTO). Tighten either one and the price rises, because shorter windows need more frequent copies, faster storage, standby systems and more testing. Loosen them and the price falls, along with the amount of your business that survives a bad day. NetSys includes disaster recovery planning in every managed agreement, quotes DR infrastructure per environment, and keeps every agreement month to month. This guide explains how those two numbers turn into a bill.
Why do RPO and RTO set the price?
| Recovery target | What it takes to hit it | Cost effect |
|---|---|---|
| Lose a day, down for days | Nightly backup to cloud, restore to new hardware when it arrives | Lowest |
| Lose an hour, down for a day | Hourly snapshots, local backup appliance, cloud copy, documented rebuild | Moderate |
| Lose minutes, down for hours | Continuous replication, ability to boot servers from the appliance or in the cloud | Higher |
| Lose almost nothing, down for minutes | Warm standby systems in a second site or cloud region, automated failover, frequent full tests | Highest |
Most small businesses do not need the bottom row for everything, and paying for it everywhere is the most common way DR budgets get wasted. The useful exercise is to set RPO and RTO per system. The accounting database and the order system may need hours. The archive file share may be fine at a day. Email in Microsoft 365 is a different question, covered below.
What are the usual pricing units for backup and disaster recovery?
Providers bill DR in a handful of units, and a quote should say which one applies to each line. Per server or per workload covers the backup agent, the recovery plan and the testing for that system. Per terabyte covers cloud storage for the retained copies, and it grows with retention and with the amount of data that changes. Per appliance covers a local backup device that can also boot failed servers as virtual machines while the real hardware is replaced. Per workstation appears when laptops hold data that is not in OneDrive or on a server. A managed DR service adds the labor: monitoring backup jobs daily, restoring files on request, running tests and keeping the plan current.
Retention multiplies all of this. Keeping thirty days of restore points costs a certain amount of storage; keeping a year of monthly copies for a regulator or an insurer costs more. Decide retention per system alongside RPO and RTO, and write the decision down, because a retention policy nobody remembers setting is how storage bills creep.
What does immutable storage add, and why do insurers ask about it?
Ransomware crews learned years ago to find and destroy backups before encrypting production, which is why a backup copy that can be deleted with an administrator's password is no longer a backup. Immutable storage locks each copy for a set period so that nobody, including your own administrator and including the provider, can alter or delete it until the period ends. Air-gapped or offline copies achieve the same result by keeping the backup off the network entirely.
Immutability adds a modest amount to storage cost and a large amount to the chance you recover without paying anyone. Cyber insurance applications now commonly ask whether backups are immutable or offline, whether they are separated from the production network, and whether restores are tested. NetSys has handled more than thirty ransomware incidents in three years, every one fully recovered, and clients who had a disaster recovery plan in place were back within twenty-four hours. The plan and the immutable copy are what made the difference, and both are line items worth seeing on any quote.
What does DR testing cost, and what happens if you skip it?
A backup that has never been restored is a hope. Testing is where the DR budget proves itself and where cheap quotes cut corners, because testing is labor: booting servers from backup in an isolated network, confirming the database comes up consistent, checking that staff can log in, timing the whole thing, and fixing what failed. A quarterly restore test for the critical systems and an annual full failover exercise is a reasonable cadence for most small businesses, and the quote should say what is included.
The cost of skipping it shows up on the worst possible day: a backup job that had been silently failing for months, a restore that takes three days instead of three hours because nobody knew the order the servers had to come up in, or an application license tied to hardware that no longer exists. Every one of those is a known failure mode, and every one is found by a test before it is found by an outage.
What is usually left out of a DR quote?
- Microsoft 365 data. Microsoft keeps its service running; it does not keep an independent, restorable copy of your mailboxes, OneDrive, SharePoint and Teams data beyond its retention windows. That is a separate backup with its own cost, described on our Microsoft 365 backup page.
- Other cloud applications. Accounting, CRM and practice-management platforms need their own export or backup arrangement.
- Workstations. Data on laptops that never made it to OneDrive or the server is unprotected unless the quote says otherwise.
- Network and firewall configuration. A rebuilt server on a network nobody can reconstruct is still an outage.
- The plan itself. Contact lists, the order of restoration, who declares a disaster, and where the runbook lives when the file server is gone. Writing and maintaining it is work.
- The rebuild. Replacement hardware, or the cloud compute bill while failed-over systems run in Azure, is usually billed as incurred.
How do you compare disaster recovery quotes?
Put both quotes against the same RPO and RTO for the same list of systems, then check five things: whether the copies are immutable or offline, how much retention is included and what more costs, how often restores are tested and who does it, whether Microsoft 365 and other cloud data are covered, and what the provider commits to on the day you call. A quote that cannot state a recovery time for your most important system is a backup quote, and backup is only the first part of disaster recovery. Our backup and disaster recovery FAQ covers the other questions owners ask.
Frequently asked questions
How much does disaster recovery cost for a small business?
It depends on the recovery point and recovery time you set for each system, the amount of data and retention involved, the need for a local appliance or cloud failover, and how much testing is included. NetSys quotes DR per environment after looking at what runs and how quickly it needs to come back, and includes disaster recovery planning in every managed agreement. Loosening targets on systems that can wait is the honest way to bring the number down.
Is cloud backup the same as disaster recovery?
No. Cloud backup is a copy of your data somewhere else. Disaster recovery is the copy plus the systems to run it on plus a tested plan for the order in which everything comes back. A business with only cloud backup will get its files back eventually; a business with disaster recovery knows how long that takes because it has measured it. The gap between the two is where most of the cost, and most of the value, sits.
How often should we test our disaster recovery plan?
Test file restores monthly, because they are cheap and catch failing backup jobs. Test a full server recovery for critical systems at least quarterly, and run a complete failover exercise, including staff logging in and working, at least once a year and after any major change. The test schedule should be in the agreement, with a report after each one, so the plan is verified rather than assumed.
Does Microsoft back up our Microsoft 365 data?
Microsoft protects the service and keeps deleted items for its published retention periods, but it does not provide an independent backup you control, and a mailbox emptied by a compromised account or a departing employee can pass through those windows before anyone notices. Most businesses add a third-party Microsoft 365 backup with its own retention, priced per user, as a separate line from server DR. Our article on the Microsoft 365 shared responsibility model explains the boundary.
Setting recovery targets with NetSys
The right DR budget starts with a conversation about which systems can wait and which cannot, and NetSys begins every plan there. We set recovery objectives per system, build immutable and offline copies, and test failover on a schedule instead of assuming it works. See our disaster recovery services page, or our ransomware protection page for how DR fits with prevention.
Sources and further reading
- NIST SP 800-34, Contingency Planning Guide for Federal Information Systems, the source of the RPO and RTO framework.
- CISA StopRansomware, including its guidance on offline and immutable backups.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



