Some morning it could be a fire, a burst pipe, a landlord who does not renew, a server that dies, a scam that locks your files, or a laptop that walks off with the only copy of your data.
Any one of these can stop an organization that has not prepared for it, and many have not, because it is nobody's job until it is an emergency. This guide makes sure the disasters that would hurt worst, to your data, your space, and your systems, would be a setback you recover from rather than an ending. It is not a promise that nothing will ever go wrong; it is the work of making sure that when something does, you can recover. It is not your everyday systems and data organizing, which is broader operations work; this is the disaster layer. And it is not the technical work itself; where setting up secure backups or recovering a system genuinely needs an expert, this guide will tell you to bring one in. Use this if a fire, a flood, a lost building, or a systems or data failure could stop your work.
Data and systems you cannot recover are the fastest way a disaster becomes permanent. Identify the data and systems the organization could not function without, your records, your financials, your case and donor information, and make sure each is backed up somewhere separate from the original, automatically and regularly. Then actually recover a file, or a system, from your backup and confirm it works, because a backup you have never restored from is a guess. Set a schedule to test it again.
Open the Data Backup and Recovery Setup →Insurance is how an organization survives the disasters it cannot prevent, and many are underinsured or missing coverage they need. Take the disasters you named and your concentration risks, and check your coverage against them with a broker who works with nonprofits: property, liability, coverage for your board, cyber and data coverage if you hold sensitive information, and coverage specific to your work. Then close the serious gaps and put renewals on your calendar. This is the same coverage review your risk and compliance work uses, so use that tool rather than a second one.
Open the Insurance Coverage Review →If you could not get into your building tomorrow, the work should bend, not stop. Decide where your people and your essential services would operate if your building were suddenly unavailable: another site, partner space, homes, online, and name what each essential service would need to run from somewhere else. Then make sure the things a relocation depends on exist in advance: the ability to work remotely, contact lists for staff and the people you serve, and copies of the records you would need offsite.
Open the Facility and Remote-Operation Backup Plan →Two lines here are not yours to draw alone. Setting up secure, reliable backups, recovering a failed system, or protecting against an attack is genuine technical work, and where your staff cannot do it well, bring in an IT professional, because a backup that quietly was not working is worse than knowing you have none. And what insurance to carry, and how much, is a licensed broker's advice matched to your risks and budget, not a number a worksheet can give you. These are boundaries, not detours.
You have recovered a real file or system from your backup and it worked. Your insurance has been checked against your actual disasters with a broker, and the serious gaps are closed. And you have a written plan for keeping your essential work running if you lost your building.
With your disasters covered, most leaders move to Write the Plan to Keep Serving Through a Shock, to pull the protections into one plan. The everyday data and systems work is operations and systems, and the full insurance and risk program is compliance and risk. If you came in through a crisis and have steadied, the whole-organization check-up is the honest next look once your resilience plan is complete.