Back to Glossary

Entry · Business

Disaster Recovery Site

A disaster recovery site is a separate location, physical or in the cloud, that a business can switch its critical systems to if its primary site becomes unusable. The point is continuity: keeping the operation running through a fire, flood, power failure, cyber attack or extended outage rather than waiting for the original site to be repaired.

Sites are usually described as hot, warm or cold depending on how quickly they can take over.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

When a company's main data centre or office goes down, the cost is not the damaged equipment but the revenue and productivity lost while nothing works. A disaster recovery site is a standing arrangement, paid for in advance, that shortens that outage.

It is insurance bought in infrastructure rather than in premiums. The three standard tiers differ in readiness and cost.

A hot site runs continuously replicated systems and can take over within minutes or a couple of hours, a warm site holds the hardware and periodic data copies and needs hours to a day to come up, and a cold site is essentially empty space with power and connectivity that could take days or weeks to bring into service. Two targets drive the choice.

The recovery time objective is how long the business can tolerate being down, and the recovery point objective is how much recent data it can afford to lose, measured backwards from the moment of failure. A payment processor may need minutes on both, while a small architectural practice might accept a day of downtime and a few hours of lost work.

The investment decision is a straightforward comparison of the annual cost of the site against the expected annual cost of downtime, which is the hourly cost of being down multiplied by the expected hours of outage. Because the probability of a major event in any given year is low, this calculation is where many businesses quietly decide that a cheaper tier is rational.

The nuance that undermines most plans is testing. A disaster recovery site that has never been failed over to is a plausible assumption rather than a capability, and regular tested failovers are what turn the contract into genuine protection.

In practice

Real-world examples.

1

Example

A regional hospital group maintains a hot site 40 miles from its main data centre with continuous replication of patient records. During a lengthy power failure the clinical systems failed over in under twenty minutes and staff continued working from the same screens.

2

Example

An accountancy firm keeps a warm site consisting of a serviced office with pre-installed workstations and nightly backups of its practice management system. When a burst pipe closed its main office for six weeks, staff were working from the alternative site within a day and a half.

3

Example

A manufacturer decides a cold site is sufficient for its non-production systems but pays for a hot arrangement covering the plant control systems alone. Splitting the estate by criticality reduced the annual cost by roughly two thirds compared with protecting everything at the highest tier.

Formula

Calculation

Cost of downtime per hour = annual revenue at risk / annual operating hours Expected annual downtime cost = probability of an event x hours of outage x cost per hour Total annual cost of an option = annual site cost + expected annual downtime cost An online retailer generates $438 million of revenue a year and trades continuously, so its operating hours are 365 x 24 = 8,760. Cost of downtime per hour = $438,000,000 / 8,760 = $50,000. The business estimates a 25% chance in any year of an event that takes the primary site out. A hot site costs $600,000 a year and restores service in 2 hours. A cold site costs $120,000 a year and restores service in 72 hours. Hot site expected downtime cost = 0.25 x 2 x $50,000 = $25,000, giving a total annual cost of $600,000 + $25,000 = $625,000. Cold site expected downtime cost = 0.25 x 72 x $50,000 = $900,000, giving a total annual cost of $120,000 + $900,000 = $1,020,000. The hot site is the cheaper option by $1,020,000 - $625,000 = $395,000 a year, despite costing five times as much to run.

Case study

Seen in the real world.

Kestrel Freight Systems is a fictional logistics business presented here as an illustrative example. It had contracted a cold site for $9,000 a month as a condition of a large customer contract, and the arrangement had sat untouched in a filing cabinet for four years.

When ransomware encrypted its primary systems on a Thursday afternoon, the failover was attempted for the first time. The backup tapes restored, but the routing software required a licence key held only on the encrypted primary server, and the network configuration at the cold site had never been matched to the current production setup. Full service resumed after nine days rather than the three the plan assumed.

In this illustrative account the direct cost of the extra six days of disruption exceeded a decade of the price difference between the cold site and a warm one. The board's conclusion was that the tier had been chosen sensibly on paper but the plan had never been tested, and an untested plan is closer to a cold site than to a warm one no matter what the contract says.

Watch out

Common mistakes.

  • Locating the recovery site close enough to be affected by the same event. A site on the same power grid or in the same flood plain offers far less protection than the contract implies.
  • Protecting data but not the ability to use it. Licence keys, network configuration, authentication systems and documentation all have to be recoverable, not just the database.
  • Treating the plan as finished once signed. Systems change constantly, and a recovery plan that is not retested after major changes decays quickly.

Questions

People also ask.

What is the difference between a hot site and a cold site?

A hot site is running and can take over in minutes to hours, while a cold site is empty space that must be equipped and configured before it can be used.

How often should failover be tested?

At least annually for most businesses, and more frequently where recovery time objectives are measured in minutes or where systems change rapidly.

Does cloud hosting remove the need for a disaster recovery site?

No, it changes its shape, since a cloud region can fail and a misconfiguration or account compromise can affect everything in one provider unless a separate region or provider is arranged.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.