Q4 Is Coming: 5 DR Checks Every NY Business Should Make Before the Holidays

Q4 is almost here. The holiday season, year-end deadlines, severe weather, reduced staffing, and increased customer demand will put pressure on your systems at exactly the wrong time.

If your primary server fails in October, can your team recover before customers notice? If ransomware encrypts your production environment in November, can you restore clean data without relying on the people who are already away for Thanksgiving?

You cannot afford to discover the answer during an outage.

Verizon’s 2026 Data Breach Investigations Report found that ransomware appeared in 48% of confirmed breaches, up from 44% the previous year. Threats are accelerating, but many businesses are still relying on untested backups, outdated recovery plans, and a single administrator who knows how everything works.

Before Q4 gets busy, use this five-point disaster recovery checklist to identify weaknesses and strengthen your recovery position.

1. Review Your RTO and RPO Before Demand Peaks

Your disaster recovery strategy starts with two questions:

  • How quickly must each system be restored?
  • How much data can your business afford to lose?

These are your:

  • Recovery Time Objective (RTO): the maximum acceptable period a system can remain unavailable.
  • Recovery Point Objective (RPO): the maximum acceptable amount of data loss, measured by time.

For example, an RTO of four hours means your critical application must be operational within four hours of a disruption. An RPO of 15 minutes means your recovery solution must protect data frequently enough to limit loss to approximately 15 minutes.

Your targets should reflect business impact, not what your existing technology happens to deliver.

System or service Example RTO Example RPO What to consider
Customer transactions and billing 1–4 hours Minutes Lost transactions, duplicate charges, compliance
Production databases 4–8 hours Minutes to 1 hour Operational and financial impact
Customer portal or website 4–12 hours 1–4 hours Customer communication and reputation
Email and collaboration tools 12–24 hours Several hours Internal productivity
Archives and non-critical files 24–72 hours 24 hours Can work resume manually?

Do not assume that an old target still works. Your business may have added applications, acquired new customers, changed suppliers, or become dependent on cloud-based services since your last review.

For New York businesses in regulated industries, New York DFS guidance reinforces the need for risk-based continuity planning and timely recovery of critical services.

Your Q4 action: List your five most important systems. Assign an owner to each one. Confirm the RTO and RPO with business leadership, not just IT, and document how your current technology is expected to meet those targets.

2. Test Your Immutable Backups, Do Not Just Check That They Exist

A backup that can be deleted, encrypted, or altered by an attacker is not sufficient protection against modern ransomware.

An immutable backup is a protected copy that cannot be changed or deleted during a defined retention period. It gives you a recovery point that remains available even if an attacker compromises administrator credentials or your primary environment.

But immutability alone does not guarantee recovery.

Your team must verify that the backup is:

  • ✅ Complete
  • ✅ Accessible to authorized recovery personnel
  • ✅ Free from corruption
  • ✅ Recent enough to meet your RPO
  • ✅ Restorable to usable systems
  • ✅ Isolated from the credentials used to manage production

Run a practical restore test before the holidays. Select a representative workload, restore it into an isolated environment, and verify more than whether the server starts.

Check that:

  1. Applications launch correctly.
  2. Databases are consistent.
  3. Users can authenticate.
  4. Network connections work.
  5. Files and permissions are intact.
  6. Critical transactions can be completed.
  7. The recovered data is free from suspicious encryption or malware.

The difference matters. A backup may appear healthy while a required database, configuration file, or application dependency is missing.

Flat vector illustration of immutable backup protection, showing a secure backup vault with a padlock, shield, and recovery checkmark connected to business data, using cool blue and teal accents on a white background

Your Q4 action: Perform at least one documented recovery test before the end of September. Record the actual restore time, the recovery point used, problems encountered, and the person responsible for correcting each issue.

If your business needs stronger protection, review Ron Klink’s guidance on automated disaster recovery and resilient backup design.

3. Verify Your Cloud Based Disaster Recovery Failover

Backups help you recover data. Cloud based disaster recovery helps you recover operations.

With cloud based disaster recovery, critical servers, applications, and data are replicated to a separate cloud recovery environment. If your primary infrastructure fails because of hardware failure, ransomware, fire, flooding, or a regional outage, your business can fail over to that environment rather than waiting for replacement equipment.

That distinction can reduce recovery from days to hours, or less, depending on your architecture and RTO.

However, replication does not mean your environment is automatically ready. You need to test the entire recovery chain, including:

  • Server replication health
  • Application startup order
  • Database dependencies
  • DNS changes
  • Firewall rules
  • VPN and remote access
  • Identity and authentication services
  • Third-party integrations
  • Customer-facing applications
  • Data consistency
  • Failback to the primary environment

A finance application may depend on an Active Directory server. Your customer portal may depend on a database, DNS record, payment gateway, and API connection. If those dependencies are not included in the failover plan, the system may be technically “running” but operationally unusable.

Ron Klink supports Azure Site Recovery, AWS Elastic Disaster Recovery, and IBM i Cloud Disaster Recovery for different infrastructure needs.

Your Q4 action: Schedule a controlled failover test. Measure how long it takes to bring priority applications online, then ask users to perform real business tasks in the recovery environment. A recovery test is successful only when your people can work.

4. Update Your Recovery Runbooks While Everyone Is Available

A disaster recovery plan describes what should happen. A runbook explains exactly how to make it happen.

Your runbook should be detailed enough for a trained alternate, not only your most senior IT administrator, to follow under pressure.

Review and update:

  • Contact names, phone numbers, and escalation paths
  • System owners and recovery priorities
  • Administrator accounts and access procedures
  • Backup locations and retention settings
  • Cloud recovery credentials
  • Network diagrams and dependencies
  • Failover and failback steps
  • Vendor and managed-service contacts
  • Cyber insurance and legal contacts
  • Customer and employee communications
  • Validation checks after recovery
  • Manual workarounds for critical processes

Remove steps that depend on memory. Replace vague instructions such as “restore the database” with clear actions, ownership, expected results, and escalation criteria.

Your runbook should also explain what happens if the incident is ransomware. Do not restore blindly. Include instructions for isolating affected systems, preserving evidence, confirming that recovery points are clean, and involving appropriate security, legal, insurance, and regulatory contacts.

If your business operates subscription services, data accuracy is especially important. New York’s Click to Cancel requirements take effect on October 1, 2026, creating additional pressure to preserve cancellation records and system state. Read Click to Cancel Is Coming: Get Your Data Infrastructure Ready for NY’s New Rule to understand why resilient infrastructure supports both continuity and compliance.

Flat vector illustration of a disaster recovery runbook, showing a checklist, workflow arrows, server icons, and an emergency contact symbol in a clean blue and teal style on a white background

Your Q4 action: Assign one person to review the runbook line by line. Have someone unfamiliar with the process follow it during a tabletop exercise. Every unclear step is a recovery risk.

5. Prepare for Holiday Staffing Gaps

Outages do not wait for the person who understands your infrastructure to return from vacation.

During Q4, your business may have fewer IT staff available, slower vendor response times, and decision-makers travelling or working remotely. A recovery plan that works on a normal Tuesday may fail on Christmas Eve.

Build a specific holiday coverage plan that identifies:

Role Primary Alternate Required access
Incident commander Named leader Deputy Emergency contacts and decision authority
Technical recovery lead IT administrator Cross-trained engineer DR platform and cloud access
Business operations lead Department owner Alternate manager Process validation
Communications lead Executive or communications manager Delegate Staff, customer, and vendor contacts
External support DR or security provider Escalation contact 24/7 response details

Confirm that alternates have:

  • Current credentials
  • Multi-factor authentication
  • Access to the runbook
  • Knowledge of recovery priorities
  • Authority to approve emergency actions
  • A reliable after-hours contact method

Store emergency contacts in more than one location. Keep a secure digital copy, a printed copy for designated leaders, and an offline copy that remains available if your identity platform or email is unavailable.

Run a short holiday tabletop exercise. Give the team a scenario: a ransomware alert arrives at 9:00 p.m. on a holiday weekend. Then ask:

  • Who receives the first alert?
  • Who can declare a disaster?
  • Who starts failover?
  • Who contacts your provider?
  • Who communicates with customers?
  • Who approves legal or regulatory notifications?
  • What happens if the primary contact does not answer?

Your Q4 action: Publish the on-call schedule before holiday leave begins. Test every contact method. Do not wait until an emergency reveals that a phone number is disconnected or a replacement employee lacks access.

Enter Q4 With Evidence, Not Assumptions

A resilient business does not simply claim to have backups or a disaster recovery plan. It can demonstrate that its systems, people, and procedures work together under pressure.

Before the holidays, make sure you can answer “yes” to these five questions:

  • ✅ Are your RTO and RPO targets current and achievable?
  • ✅ Have you restored data from an immutable backup?
  • ✅ Have you tested your cloud based disaster recovery failover?
  • ✅ Can an alternate employee follow your recovery runbook?
  • ✅ Is trained holiday coverage available around the clock?

If the answer to any question is “no,” act now. The closer Q4 gets, the harder it becomes to schedule tests, correct architecture problems, and train alternate staff.

Ron Klink helps New York businesses design, test, and maintain customized disaster recovery environments that protect against server failures, ransomware, data breaches, severe weather, and other disruptions. Whether your infrastructure runs on Azure, AWS, IBM i, or a hybrid environment, the goal is the same: minimize downtime and keep your business moving.

Contact Ron Klink to review your Q4 readiness and enter the holiday season with confidence.

Other articles you may like