Website Disaster Recovery Plan: A Simple Guide for Small Businesses
A simple website disaster recovery plan: what can go wrong, backups and restore tests, who does what, a contact list, and how to keep customers informed.

On this page
- A one or two page plan written in advance turns a website emergency into a routine job.
- Test restores regularly and keep a contact and access list so the right people can act quickly.
- Prepare customer messages for Google Business Profile, WhatsApp and phone staff before you need them.
Most small businesses only think about website disasters after one has happened: the site is down, a customer is on the phone and nobody can find the hosting login. A disaster recovery plan is simply a short document, written in advance, that answers "what do we do now?" It doesn't need to be long or technical. One or two pages, kept up to date, can turn a stressful week into an afternoon's work.
What can go wrong
Start by listing the realistic problems for your site. For most business websites, they look like this:
| What happens | Typical cause | Usual recovery |
|---|---|---|
| Site shows an error after an update | Plugin, theme or PHP conflict | Roll back the update or restore a backup |
| Site hacked or redirecting to spam | Outdated plugin or weak password | Proper clean-up, then close the entry point |
| Website and email both stop working | Domain expired or DNS records changed | Renew the domain, correct the DNS |
| Hosting suspended or server down | Unpaid bill, resource limits or a host outage | Contact the host, or restore to new hosting |
| Pages, products or orders deleted | Human error or a bad import | Restore from a backup |
| Nobody can log in | Developer left, lost 2FA phone, forgotten passwords | Recover access through the account owner |
For what to check in the moment, see what to do when your website is down. This plan is about being ready before that moment arrives.
Decide how much downtime and data loss you can accept
Two questions shape the whole plan:
- How long can the site be offline before it really hurts? A consultant's brochure site might cope with a day. A WooCommerce store during a Diwali sale, or a clinic taking online appointments, probably can't.
- How much recent work can you afford to lose? If you restore yesterday's backup, anything added since (blog posts, orders, form entries) disappears from the website. For a store taking orders all day, that matters far more than for a site that changes once a month.
Your answers decide how often you back up, how quickly your developer or host needs to respond, and how much it's worth spending on hosting and support.
Backups and restore testing
- Automatic backups of files and database, at a frequency that matches your answers above
- At least one copy away from the server, such as cloud storage, so a hacked or failed server doesn't take your backups with it
- Several older copies kept, because hacks and mistakes are sometimes noticed days later
- An extra backup before every update, redesign or migration
Then test. Every few months, restore a backup to a staging copy of the site and check that pages, images, forms and checkout work. Note how long the restore took; that's your realistic recovery time, not a guess. The WordPress backup and restore guide covers the details.
Who does what
In a crisis, confusion wastes more time than the technical fix. Write down names, not just job titles, with a backup person for each role:
| Role | Responsible for |
|---|---|
| Decision maker (usually the owner) | Approving a restore, spending money, deciding what to tell customers |
| Technical lead (developer or maintenance provider) | Diagnosing the problem, restoring backups, cleaning up hacks |
| Accounts holder | Logging in to the domain registrar and hosting, raising support tickets |
| Customer communication | Updating Google Business Profile, social media, WhatsApp and phone staff |
In a small business, one person may wear several hats. That's fine, as long as everyone knows who makes the final call.
Keep a contact and access list
This is the part most businesses are missing. Keep an up-to-date list of:
- Domain registrar, hosting company and DNS provider, with account IDs and support contacts
- Your developer or maintenance provider, with an emergency number
- Business email provider, payment gateway and any booking or CRM tools connected to the site
- Where backups are stored and how to reach them
- Renewal dates for the domain, hosting, SSL and premium plugin licences
Keep passwords and two-factor recovery codes in a password manager rather than in the plan itself, and make sure at least two trusted people can reach them. If a former developer still controls key accounts, fix that now using the website ownership checklist.
The first hour: a simple response order
- Confirm the problem from another device and network, and note the time and the exact error
- Tell the technical lead and the decision maker
- Stop further changes to the site so data and evidence aren't overwritten
- Check the obvious: recent updates, domain and hosting renewals, emails from your host
- Decide whether to fix in place or restore a known-good backup to get back online while the cause is investigated
- Start customer updates if the outage will last more than a short while
- Keep a brief log of what was done and when
If the site was hacked, restoring a backup alone can bring back the same weakness. The way in has to be found and closed too.
Communicating with customers during downtime
Customers are usually forgiving if they know what's happening and can still reach you. Prepare these in advance:
- A short status message ready to post on your Google Business Profile, Instagram or Facebook, saying what's affected and how to reach you meanwhile
- A WhatsApp Business away or greeting message that points people to phone or WhatsApp orders
- A simple script for staff answering calls, so everyone gives the same answer
- For online stores: how to handle orders paid during the outage, and whom to contact if UPI or card payments look stuck
Keep your phone number and WhatsApp independent of the website so enquiries don't stop. If customer data may have been exposed in a hack, take advice promptly on what you may need to report under current rules such as India's DPDP Act, rather than guessing.
Review and practise the plan
Update the plan whenever you change host, developer or key staff, and after every incident. Once a year, run a short drill: can the right people log in to the registrar and host, find the latest backup and restore it to staging? Uptime monitoring helps too, so you hear about problems before your customers do.
Want someone else to handle this? My WordPress maintenance plans include regular off-site backups, security monitoring and uptime checks, and malware removal is there if a hack is the disaster.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


