Most business owners believe they're prepared for disaster. They have backups. They have insurance. They have a plan documented somewhere. But when disaster actually strikes, survival often comes down to one question: did you practice?
Three incidents across two decades illustrate what preparedness really means. One involved Europe's largest peacetime explosion. Another was a ransomware attack that crippled essential services for months. The third was the rarest example: an organisation that actually prepared properly.
When the Explosion Hit
In December 2005, a catastrophic explosion at an oil storage facility in Hertfordshire rocked the region. The blast measured 2.4 on the Richter scale and overwhelmed 20 large storage tanks. It remains one of the biggest incidents of its kind in peacetime Europe.
A housing system provider serving a major London council had infrastructure in the blast zone. For the council relying on that system to manage thousands of housing records and serve vulnerable residents, this should have been catastrophic.
It wasn't.
The system went offline, but mirrored backup systems at a separate location took over. Downtime was brief. The housing system was back up and running. Residents continued receiving services. There were no reputational issues for the council—the recovery happened smoothly enough that the disruption barely registered. This wasn't luck. It was disaster recovery planning that assumed the worst and prepared for it.
Good DR planning works even when disaster exceeds imagination.
The Organisation That Practised
Years later, participation in a disaster recovery exercise with the City of London Corporation revealed a critical difference. The task involved sitting with key disaster planning team members, working through simulated crisis scenarios, identifying core applications, and determining recovery priorities.
It was the only organisation encountered in an entire career that actually practised disaster recovery.
Not just documented it. Not just discussed it in meetings. Actually ran scenarios, tested assumptions, identified gaps, and refined the plan based on learning.
The difference was clear. Everyone knew their role. Systems were prioritised. Communication channels were established. There was confidence born from repetition, not just theoretical knowledge.
Having a plan isn't enough. Practicing the plan makes it work.
When Ransomware Struck
In October 2020, a London council fell victim to a major ransomware attack. The attack crippled systems, locked staff out of essential applications, and left residents unable to access critical services. Recovery took months. The financial cost ran into millions. Reputational damage lasted longer.
This wasn't a small organization lacking IT resources. This was a large council with experienced leadership who understood technology and risk. The senior stakeholder managing the crisis had years of experience. The head of IT had led teams through complex technical challenges.
None of that mattered when the attack hit.
Cyber disasters don't discriminate. Experience and good intentions don't provide protection. Only preparation does.
What Small and Mid-Sized Businesses Miss
These scenarios span different disaster types—physical destruction, proactive preparation, and cyber attack—but share a common thread. Organisations that survive aren't lucky. They're ready.
For small and mid-sized businesses, disaster recovery typically falls into three categories:
No plan at all. Many SMBs assume disaster recovery is for large enterprises only. They rely on cloud services and hope for the best, unaware that cloud hosting doesn't automatically include disaster recovery.
Plans that exist on paper. Some businesses have documented critical systems and backup procedures. If that plan has never been tested, it's theoretical at best and dangerously misleading at worst.
Fragmented preparation. Others have pieces in place—data backups here, vendor agreements there—but no cohesive strategy for how everything works together when crisis hits.
The gap isn't always technical. It's operational. Knowing which systems matter most. Having communication plans when email goes down. Understanding dependencies that only become obvious when something breaks.
The Real Cost of Unreadiness
When the explosion happened in 2005, organisations without mirrored systems lost critical data and faced extended downtime. When the ransomware attack hit in 2020, recovery costs included not just technical remediation but lost productivity, emergency staffing, and damaged public trust.
For small and mid-sized businesses, stakes are higher. There's less financial cushion to absorb extended downtime. Customer relationships are more fragile. Reputation takes longer to rebuild.
The question isn't whether disaster will strike. The question is whether the business will still be standing when it does.
Related reading: Explore IT support for small businesses or learn how disconnected tools increase your business risk.
