Back to notes

Your disaster recovery plan is fiction until someone actually runs it

Most DR plans fail for a boring reason: nobody has tested whether the document can survive contact with reality.

The problem with most disaster recovery plans is not that they are badly formatted. It is that they are treated like proof of seriousness instead of proof of readiness.

If the first full reading of the plan happens during an outage, what you have is not a recovery plan. It is a confidence ritual with page numbers.

What usually goes wrong

Teams often assume:

  • the backups are complete
  • the access still works
  • the vendor contact list is current
  • someone remembers the order of operations

That is already too much optimism for a stressful day.

In practice, recovery breaks on the small things. Credentials are stale. DNS details live in one person’s head. The “temporary” server from nine months ago is now in the critical path. Everyone is urgent, but nobody is sequenced.

What I prefer

I like a DR plan that can be spoken aloud by a team under pressure and still make sense. That means:

  1. clear ownership
  2. explicit recovery order
  3. tested access paths
  4. real RTO and RPO expectations
  5. a rehearsal that creates evidence, not optimism

The rehearsal matters most. Once you run it, the fiction drops away very quickly. The plan gets shorter. The assumptions get fewer. The confidence becomes quieter and much more believable.

The uncomfortable truth

A tested four-hour recovery target is more impressive than a beautifully designed two-page promise nobody has attempted to execute.

I have more respect for an imperfect plan that has been drilled than for a polished one that has only been admired in meetings.