A page that saves hours.
WHAT IT SHOULD CONTAIN
Where backups are stored, and how to access them
How to restore: the actual steps, not a description
Who to contact: us, the domain registrar, any developer
Credentials location, not the credentials themselves
What the site depends on: domain, DNS provider, payment gateway, external services
Priorities: what must come back first
WHY WRITE IT
During an incident, people do not think clearly. A written procedure removes the need to.
It also means someone other than you can act.
WHERE TO KEEP IT
Not on the server. A document in shared storage, or printed.
An emergency plan stored only on the thing that failed is useless.
HOW LONG
One page for a small business. Two for something complex.
Anything longer will not be read during an incident.
TESTING IT
Have someone else follow it. The gaps become obvious immediately.
REVIEWING
Annually, and whenever something significant changes.
THE MINIMUM
Where the backups are, how to restore them, and who to call.