Disaster Recovery
Disaster recovery is the process of restoring access to IT systems, applications, and data after a disruptive event such as a fire, flood, cyberattack, or other natural or human-caused incident. It focuses on getting technology infrastructure back up and running so that an organization can resume normal operations. Disaster recovery is one part of a broader resilience effort and is narrower in scope than business continuity, which addresses the continuation of the organization's overall functions and processes.
Disaster Recovery (DR) refers to the IT technologies, processes, and practices designed to restore access and functionality to critical systems, applications, data, and infrastructure following an unexpected disruption, whether natural or human-caused. In many programs DR is scoped specifically to the recovery of technology assets and typically encompasses activities such as risk assessment, planning, and the restoration of critical systems and data. DR should be distinguished from business continuity: DR addresses the technical recovery of IT services, whereas business continuity addresses the broader continuation of business functions, processes, and personnel. As scoped in the available evidence, DR centers on IT infrastructure recovery and does not by itself cover non-IT operational, financial, or supplier-facing continuity concerns; those fall under adjacent disciplines. In third-party contexts, an organization's own DR capability does not extend to a vendor's environment, so the recovery posture of external providers typically requires separate assessment.
Why it matters
For third-party and supply chain risk professionals, disaster recovery matters because an organization's ability to restore its own IT systems after a disruption does not guarantee that the vendors, service providers, and business partners it depends on can do the same. When a critical supplier's applications, data, or infrastructure go offline following a fire, flood, cyberattack, or other disruptive event, the downstream impact can cascade into the buying organization's operations even if that organization's internal DR posture is sound. DR capability, in other words, is only as complete as the recovery readiness of the parties an organization relies upon.
DR is frequently conflated with business continuity, but the distinction has practical consequences for how risk is assessed. DR is scoped to the technical recovery of IT services, systems, applications, data, and infrastructure, whereas business continuity addresses the broader continuation of business functions, processes, and personnel. A vendor may be able to restore its servers while still being unable to deliver a service if non-IT dependencies remain disrupted. Treating a DR attestation as evidence of full operational resilience overstates what the term covers and can leave gaps in a third-party risk assessment.
Because an organization's own DR program does not extend into a vendor's environment, the recovery posture of external providers typically requires separate, direct evaluation. Relying on a supplier's self-description of its DR capabilities is a point-in-time indicator that may not reflect tested, current, or independently verified recovery performance. This is why DR readiness is a recurring theme in vendor onboarding and ongoing monitoring, rather than a matter that can be assumed from a single contractual clause.
Who it's relevant to
Inside DR
Common questions
Answers to the questions practitioners most commonly ask about DR.
