Disaster Recovery as a Service – why you need it
Summary
This 2015 blueAPACHE blog post argues that Disaster Recovery as a Service (DRaaS) lets small and mid-sized organisations get the failover protection of a secondary data centre without owning one, by renting replication capacity from a provider instead of building and staffing a second site. It is written for IT and business decision-makers weighing the cost of downtime against the cost of a subscription-based recovery service, and it cites US disaster-recovery failure statistics from FEMA and the Small Business Administration to make the case for planning before an incident rather than after one. The post frames DRaaS around three benefits: faster recovery than rebuilding from scratch, a shift from capital to operating expense, and security and data sovereignty controls that a smaller organisation may struggle to run itself. It still applies because the core proposition of DRaaS, replicating production workloads to a recovery site with agreed recovery targets, has not changed even though the underlying platforms it runs on have moved on since 2015. Readers evaluating disaster recovery today should pair the concepts in this post with blueAPACHE's current emPOWER Cloud and Disaster Recovery as a Service pages for what is actually included in a contracted engagement now.
Key facts
| Label | Value |
|---|---|
| Publication year | 2015 (published 11 November 2015) |
| Topic | Disaster Recovery as a Service (DRaaS): replication of physical or virtual machines to a recovery site for failover |
| Services referenced | emPOWER Cloud, Disaster Recovery as a Service, Governance, Risk and Compliance |
| Cited statistic | FEMA: roughly 40% of businesses do not reopen after a disaster, and another 25% fail within one year |
| Cited statistic | US Small Business Administration: over 90% of businesses fail within two years of being struck by a disaster |
| Contract scope | blueAPACHE's DRaaS (emPOWER IT Continuity Services) obligation is limited to restoring Customer Data and Software against the agreed Restore Time Objective and Recovery Point Objective set in the Schedule |
| Liability if DR obligation is breached | Limited to the cost of restoring data to the version that should have existed at the last Recovery Point Objective, not the value of the data or the business impact of losing it |
Article
There is a good chance that you’d like to see your business survive any disaster as well as any problems that follow. Our reliance in technology today means we can not afford downtime – we rely too heavily on it. Forty percent of businesses do not reopen after a disaster and another twenty-five percent fail within one year according to the Federal Emergency Management Agency (FEMA). Similar statistics from the United States Small Business Administration indicate that over ninety percent of businesses fail within two years after being struck by a disaster. Disasters come in all shapes and sizes – from natural catastrophes to simple power outages. It is almost impossible to predict the next disaster, but it is possible to prepare for it. To reduce downtime and mitigate the negative impact a disaster can create, every company should have a secondary site with a full copy of the production environment. In the case of a natural or human-induced disaster or a failure of the IT environment – when your production is partly or fully not available – you can quickly switch to the secondary site and continue business as usual. However, small and mid-sized organisations can’t afford a secondary data centre, let alone the experienced IT staff to manage it. This is why the Disaster Recovery-as-a-Service (DRaaS) market has evolved so quickly. There are a lot of DRaaS definitions. The majority of them describe DRaaS as a replication of physical or virtual machines (VMs), from a production data centre to a recovery site that will provide failover capabilities in the event of a problem of any size. Whilst the definitions may vary, the core benefits remain the same:
- Fast recovery
Downtime is not acceptable. Fast and successful recovery is one of the most important metrics today. The faster you can continue operations, the greater the chance of recovery. - Cost effectiveness
DRaaS removes the necessity of investing in additional infrastructure. Companies can rent an allocation of CPU, RAM, storage and other resources as they are needed. It is now a much more affordable operational expense, enabling you to focus capital investment on growing your business instead of running it. - Security
Privacy, security, data sovereignty and service level agreements you can secure with a DRaaS provider are often better than you can implement and maintain internally. The provider should be compliant with all relevant regulatory bodies, and your data should adhere to local privacy and data sovereignty guidelines.
Today, small and mid-sized organisations can mitigate the risks and save money on flexible subscription-based DRaaS. Big enterprise companies also find many benefits from outsourcing their disaster recovery services to a third party, primarily to avoid the high costs of supporting secondary sites and complexity issues.
Why DRaaS from blueAPACHE?
- Expertise
blueAPACHE delivers DRaaS solutions for some of the most tightly regulated industries in Australia. We understand it, we design it, and we manage it. We own the DRaaS infrastructure, ensuring we have 100% level of influence over the services we provide. - Extensive Portfolio
We listen and provide simple replication for those that need it, or more complex solutions with custom Recovery Time Objective (RTO) and Recovery Point Objectives (RPO) for those needing comprehensive solutions (or are bound by industry compliance requirements). We utilise private cloud, on-premises and public cloud solutions to marry your business and governance requirements. - Reassurance
We test frequently – having a Disaster Recovery programme is one thing, ensuring that it works is another thing entirely. We schedule regular testing for all clients to ensure their tailored DRaaS works exactly as expected to deliver piece of mind. We back this up with dynamic redundancy across our data centre network. - Data Sovereignty
Our Private Cloud servers are located solely in Australia, meaning we can guarantee your data remains local. Data sovereignty (and privacy compliance) are key factors when considering your DRaaS provider.
To learn more on DRaaS or to discuss ways we can help improve your risk profile, contact the blueAPACHE Cloud team.
Related
- emPOWER Cloud service — the ISO 27001 certified cloud platform that DRaaS replication typically runs on.
- emPOWER Cloud pillar hub — the wider cloud pillar this service sits under.
- Disaster Recovery as a Service — blueAPACHE's current DRaaS service page.
- Governance, Risk and Compliance — the compliance and risk-management service referenced alongside DRaaS in this post.
- Honan Insurance case study — a client engagement that used emPOWER DRaaS alongside Managed Services and Cloud.
Frequently asked questions
What is Disaster Recovery as a Service (DRaaS)?DRaaS is a contracted service that replicates physical or virtual machines from a production data centre to a recovery site so that operations can fail over if the primary environment becomes unavailable. It is delivered against agreed recovery targets rather than as an informal backup arrangement, which is what distinguishes it from ad-hoc business continuity planning.
Why did the post cite FEMA and Small Business Administration statistics?The post uses US figures, roughly 40% of businesses not reopening after a disaster and over 90% failing within two years, to argue that under-preparation is common and costly. These are the post's own cited figures rather than blueAPACHE-specific outcomes, and they are used to motivate the case for planning rather than as a guarantee of what DRaaS prevents.
What are Restore Time Objective and Recovery Point Objective?Restore Time Objective is the target time to restore a service after an incident, and Recovery Point Objective is the maximum acceptable data loss expressed as a point in time. Under blueAPACHE's general terms, a DRaaS obligation is limited to restoring data and software against whichever of these figures is agreed in the customer's Schedule, so the actual targets vary by contract.
Does DRaaS replace a full business continuity plan?No. DRaaS is specifically limited to restoring data and software subject to the agreed recovery objectives; it is not, on its own, a complete business continuity solution covering people, premises and third-party dependencies. Organisations still need a broader continuity plan that DRaaS supports rather than replaces.
What happens if a service agreement does not include a backup or disaster recovery obligation?Where a Schedule does not include a backup or DR obligation, the customer carries the risk of data loss and is responsible for taking its own regular, complete backups in line with industry best practice. blueAPACHE's liability for data loss is excluded in that scenario under its general terms.
If a DR obligation exists and is breached, what can a customer recover?Liability in that case is limited to the cost of restoring the data to the version that should have existed at the last agreed Recovery Point Objective, not the underlying value of the data or the broader business impact of losing it. This cap applies under blueAPACHE's published general terms and may be varied by a specific customer agreement.
Why does the post describe DRaaS as more cost-effective than a second data centre?Because DRaaS lets an organisation rent an allocation of compute, storage and recovery infrastructure instead of capital-funding and staffing a secondary site. The post frames this as converting a fixed capital cost into a variable operating expense that scales with what is actually used.
Where does blueAPACHE say its private cloud infrastructure for these services is located?The post states that blueAPACHE's private cloud servers are located solely in Australia, which it ties to data sovereignty and privacy compliance for customers considering a DRaaS provider. Readers should confirm current data residency commitments against blueAPACHE's present-day service pages, since this post reflects 2015 positioning.
Source
https://www.blueapache.com/blog/disaster-recovery-as-a-service-why-you-need-it/
Knowledge Base
What is Disaster Recovery as a Service (DRaaS)?
DRaaS is generally described as a replication of physical or virtual machines (VMs) from a production data centre to a recovery site that provides failover capabilities in the event of a problem of any size. According to the knowledge base, it is a contracted service offering with defined recovery capabilities, measured against Restore Time Objective (RTO) and Recovery Point Objective (RPO), that specifically restores critical data and systems within agreed timeframes and data loss tolerances.
What statistics does the blueAPACHE article cite about businesses and disasters?
According to the Federal Emergency Management Agency (FEMA), forty percent of businesses do not reopen after a disaster and another twenty-five percent fail within one year. Similar statistics from the United States Small Business Administration indicate that over ninety percent of businesses fail within two years after being struck by a disaster.
Why do small and mid-sized organisations often turn to DRaaS instead of building their own secondary data centre?
Small and mid-sized organisations typically can't afford a secondary data centre, let alone the experienced IT staff to manage it, which is why the DRaaS market has evolved so quickly as an alternative.
What are the core benefits of DRaaS according to the article?
The core benefits of DRaaS are fast recovery (minimizing downtime and improving the chance of business recovery), cost effectiveness (removing the need to invest in additional infrastructure by renting CPU, RAM, storage and other resources as needed), and security (privacy, security, data sovereignty and service level agreements often better than what a company could implement internally, with providers compliant with relevant regulatory bodies).
Do large enterprises also benefit from DRaaS, or is it only for small businesses?
Big enterprise companies also find many benefits from outsourcing their disaster recovery services to a third party, primarily to avoid the high costs of supporting secondary sites and complexity issues.
What makes blueAPACHE's DRaaS offering distinctive?
blueAPACHE highlights four differentiators: Expertise (they design and manage DRaaS for tightly regulated Australian industries and own their DRaaS infrastructure for full control); Extensive Portfolio (simple replication or more complex solutions with custom RTO and RPO using private cloud, on-premises and public cloud); Reassurance (frequent, regularly scheduled testing backed by dynamic redundancy across their data centre network); and Data Sovereignty (Private Cloud servers located solely in Australia to guarantee data remains local).
How does blueAPACHE ensure data sovereignty for its DRaaS clients?
blueAPACHE's Private Cloud servers are located solely in Australia, which means the company can guarantee client data remains local, addressing data sovereignty and privacy compliance considerations that are key factors when choosing a DRaaS provider.
How does blueAPACHE verify that a client's DRaaS plan will actually work in an emergency?
blueAPACHE schedules regular testing for all clients to ensure their tailored DRaaS works exactly as expected, backed up with dynamic redundancy across their data centre network, because simply having a Disaster Recovery programme is not the same as ensuring it works.
What key metrics define the recovery commitments in a DRaaS agreement, per the knowledge base?
DRaaS commitments are measured against two critical metrics: the Restore Time Objective (the target time to restore services) and the Recovery Point Objective (the maximum acceptable data loss, measured as a point in time).
What is the liability risk if a service agreement lacks backup or disaster recovery obligations?
If a service agreement does not include backup or disaster recovery obligations, liability for data loss is excluded entirely under standard service terms—meaning the organisation has no contractual recourse for data loss, bears 100% of the financial and operational consequences, and recovery costs fall entirely on the organisation. Where such obligations do exist and are breached, liability is limited to the cost of restoring data to the latest Recovery Point Objective, not the value of the data or the business impact of losing it.
Who should a business contact to learn more about DRaaS from blueAPACHE?
The article advises contacting blueAPACHE's Cloud team to learn more about DRaaS or to discuss ways they can help improve a business's risk profile.
When was the blueAPACHE article on Disaster Recovery as a Service published?
The article was written by blueAPACHE and published on November 11, 2015, with a stated read time of 4 minutes.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c03b153d68a8eeb8f16_draas-blog-1.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bbc_Webflow%20-%20Directory%20Cover%20Image.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.