Taking backups is easy; restoring from them is hard. Most firms learn their backup doesn't work on the day they need it.
01. Two Core Targets
RPO is the acceptable amount of data loss. RTO is how quickly the system must be back up. A technical solution can't be chosen until those two numbers are set with the business units.
02. The Three-Copy Rule
There should be at least three copies of the data, on two different media, with at least one in a different location. A second disk in the same server room doesn't count as a backup.
03. Immutable Backups
Ransomware targets backups first. A copy stored so it cannot be deleted or altered may be the only guarantee of recovery after an attack.
04. Restore Testing
What should be measured is not taking backups but restoring from them. A real restore exercise should be run at least once a year and its duration recorded.
05. Dependency Map
Restoring the ERP isn't enough; the database, licence server, integration services and authentication are also needed. The recovery order must be written down.
06. Don't Leave the Plan on Paper
Where the plan is stored matters during a disaster. A recovery document living only inside the failed system is unreachable exactly when it's needed.