Disaster Recovery Risk Assessment: A Step-by-Step Guide
Published July 14, 2026
A disaster recovery risk assessment is the process of listing the events that could take your business down, scoring each one by how likely it is and how much damage it would do, and ranking the results so you fix the biggest risks first. It is the foundation a real recovery plan is built on, because it replaces "back everything up and hope" with a short, honest picture of what would actually hurt you. This guide is for the owner or office manager of a small or mid-sized business, especially in healthcare, legal, and other regulated fields, who wants less downtime and a plan that holds up to an insurer or an auditor. You don't need a consultant's 40-page workbook to do this. You need an afternoon, the steps below, and a one-page worksheet.
What a disaster recovery risk assessment covers
Strip away the jargon and the assessment answers four plain questions. What does the business run on? What could realistically break it? How likely and how bad is each of those? And which ones deserve money and attention first? The answers become the priorities of your backup and disaster recovery plan: what gets backed up most aggressively, which systems must come back first, and where a little prevention is cheaper than any recovery. You will also see it called a disaster recovery plan risk assessment. Same exercise, same worksheet.
The federal preparedness site Ready.gov describes a risk assessment as identifying potential hazards and analyzing what could happen when they occur, including the weaknesses that would make the damage worse. That definition scales down well. For a 15-person practice, the "hazards" are usually not hurricanes. They are a ransomware email, a dead server, a construction crew cutting the fiber line, and someone deleting the wrong folder on a Friday.
What is the first step in a disaster recovery effort?
In planning, the first step in a disaster recovery effort is the risk assessment itself, paired with a business impact analysis. During an actual disaster, the first step is making sure people are safe, then assessing the damage and activating the plan you wrote on a calmer day. Which answer you need depends on when you are asking. This post covers the planning one, because it is the one you can control: the assessment and the impact analysis together decide what you are protecting and how fast it has to come back, and everything else in the plan follows from them.
How to run the assessment, step by step
Step 1: List what the business actually runs on
Before you can rank threats, you need the inventory they threaten. Write down the systems and data your business cannot operate without: the practice management or line-of-business software, the server or cloud services it lives on, email, phones, the file shares, the internet connection, and the two or three people who know how things work. For each one, note where it lives and whether a copy exists somewhere else. Most owners are surprised twice here, first by how short the truly critical list is, and second by how many items on it have no second copy.
Step 2: List the threats that are realistic for you
Generic templates love volcanoes and tsunamis. Your list should reflect what actually takes small businesses offline. In the environments we manage, the realistic short list looks like this:
- Ransomware and account compromise. The disaster most businesses actually face, and the one that can take every system at once, backups included, if the copies are reachable from the network.
- Hardware and software failure. A server drive, a firewall, or the one aging machine that runs something critical. Cloud services fail too, just less often and usually for hours rather than days.
- Power and internet outages. Common, usually short, and mostly an inconvenience, but an extended outage during your busiest week is a different animal.
- Human error. Deleted folders, overwritten files, a bad change made in a hurry. Usually more frequent than anything else on this list, and usually the cheapest to recover from if backups are in place.
- Fire, water, and theft. Rare, but they remove the whole site, which is exactly the scenario that separates businesses with an offsite copy from businesses with a very bad year.
Add anything genuinely local to you, like monsoon-season outages or wildfire evacuations if you are in the Southwest, but don't let exotic scenarios crowd out the boring ones. The boring ones are what usually happen.
Step 3: Score each threat by likelihood and impact
Now put rough numbers on it. Rate each threat from 1 to 5 on likelihood, and 1 to 5 on impact if it happened, then multiply the two for a risk score. The scores are estimates and that's fine. Their job is not precision. It is forcing an honest comparison, so the risk you read about in the news stops outranking the risk sitting in your server closet.
| Rating | Likelihood | Impact |
|---|---|---|
| 1 | Hard to imagine here | An annoyance, no real downtime |
| 2 | Could happen in a bad year | Hours of disruption for some staff |
| 3 | Will probably happen eventually | A full day down, some data at risk |
| 4 | Happens to businesses like ours regularly | Multiple days down, real revenue lost |
| 5 | Expected, only a question of when | Threatens the business itself |
Step 4: Turn the scores into downtime and dollars
A risk score tells you where to look. The business impact analysis tells you what is at stake when you look there. For each of your top risks, ask two questions in plain English: how long can we be down before the damage becomes serious, and how much recent work can we afford to lose? Those two answers have formal names, the recovery time objective (RTO) and the recovery point objective (RPO). Both are defined in NIST's contingency planning guide, SP 800-34, which treats the business impact analysis as a key early step in its contingency planning process. You don't need the federal formality, but you do need the numbers, because "restore the patient schedule within four hours, losing no more than one hour of entries" is something a plan can be built and priced against. "Get back up as soon as possible" is not.
Think through the costs while you are here. Ready.gov's business impact analysis guidance lists the usual suspects: lost or delayed income, overtime and outsourcing to catch up, contract penalties, regulatory exposure, and customers who quietly leave. Timing matters too. The same outage costs a tax office very different amounts in April and in August.
Step 5: Decide what you will do about the top risks
Work down the ranked list and give each of the top four or five risks a decision. Some risks you reduce, like moving backups offsite and out of ransomware's reach, or adding multi-factor authentication (MFA). Some you plan around, like documenting how to run on paper through a half-day outage. Some you transfer, which is what cyber insurance is for. And some small ones you consciously accept. Write the decision next to the score, and revisit the sheet once a year or whenever the business changes. An assessment from three years and two systems ago is protecting the business you used to be.
A worked example you can copy
Here is what the finished worksheet can look like for a fictional 20-person medical practice with one office, one server, and cloud email. Five rows is genuinely enough to start.
| Threat | Likelihood | Impact | Score | Decision |
|---|---|---|---|---|
| Ransomware | 3 | 5 | 15 | Offsite, tamper-resistant backups; MFA everywhere; restore test twice a year |
| Server hardware failure | 3 | 4 | 12 | Onsite full-server backup for fast restore; replacement plan for the aging server |
| Staff deletes or overwrites files | 4 | 2 | 8 | Versioned backups of the file share; recycle-bin retention in Microsoft 365 |
| Extended power or internet outage | 4 | 2 | 8 | Paper intake procedure; phone failover to mobile; battery backup (UPS) on network equipment |
| Office fire or flood | 1 | 5 | 5 | Covered by the offsite copies; insurance reviewed annually |
Notice what the scoring did. The rare-but-total risks did not top the list, and neither did the frequent-but-trivial ones. The top of the list is the intersection of plausible and painful, which is exactly where your recovery money should go first.
Risk assessment vs business impact analysis
The two terms travel together and get mixed up constantly, so here is the clean split. The risk assessment identifies what could go wrong and how likely it is. The business impact analysis measures what each disruption would cost you in downtime, dollars, and obligations. Ready.gov's guidance draws the same line, noting that the loss scenarios a business impact analysis prices out should be identified during the risk assessment. In a small business you will usually do both in the same sitting, and that's fine. The point is that both questions get asked: what can hurt us, and how much would it hurt?
If you are in healthcare, this is not optional
For medical and dental practices, the assessment is more than good practice. The HIPAA Security Rule requires covered entities, which includes virtually every medical and dental practice, to conduct a risk analysis, and its contingency plan standard requires a data backup plan and a disaster recovery plan for systems holding electronic patient records. An auditor, and increasingly a cyber insurance carrier, often asks to see this work. Insurers have been tightening what they expect around backups and recovery for several years, and we cover those expectations in our guide to cyber insurance requirements. The good news: the one-page assessment above, kept current, is the honest starting point for both conversations, and it ties into the broader framework work on our compliance page.
Frequently asked questions
What is included in a disaster recovery risk assessment?
A list of the systems and data your business depends on, the realistic threats to each, a likelihood and impact score for every threat, and a ranked result that tells you which risks to address first. Most small businesses can capture all of it on a one-page worksheet.
What is the first step in a disaster recovery effort?
In planning, the first step is a risk assessment paired with a business impact analysis, which together decide what you protect and how fast it must come back. During an actual disaster, the first step is keeping people safe, then assessing the damage and activating the recovery plan.
What is the difference between a risk assessment and a business impact analysis?
The risk assessment identifies what could go wrong and how likely it is. The business impact analysis measures what each disruption would cost you in downtime, dollars, and obligations. The risk assessment finds the threats, the impact analysis prices them, and a disaster recovery plan needs both.
How often should a disaster recovery risk assessment be updated?
Review it at least once a year, and any time the business changes in a way that changes the risks: a new location, new software your operations depend on, a new line of business, or after any real incident. A stale assessment protects the business you used to be.
Does HIPAA require a disaster recovery risk assessment?
HIPAA's Security Rule requires covered entities to conduct a risk analysis, and its contingency plan standard requires a data backup plan and a disaster recovery plan. If you run a medical or dental practice, this work is not optional, and a documented disaster recovery risk assessment is the natural starting point.
Getting your disaster recovery risk assessment done
A disaster recovery risk assessment doesn't need to be a project. List what you run on, list what could realistically break it, score each threat by likelihood and impact, put downtime and dollar figures on the worst of them, and write a decision next to each one. An afternoon of honest work produces the one page that makes the backup and recovery decisions after it easier, and it is the same page your insurer and your auditor want to see.
If you'd rather walk through it with someone who does this every week, Desert Lakes Solutions offers a no-pressure discovery call. We will look at what you run, where the gaps are, and what the easy wins would be. Book a discovery call.