Disaster recovery in the public cloud
Building a second data centre just for DR means buying hardware that sits idle most of the year. A public cloud region can act as the DR site instead: you pay to keep data copied there all the time, and pay for servers only when you test or actually fail over. For many organisations that changes DR from a capital project into a modest monthly cost. It also brings its own catches, which this guide covers.
Three ways to use the cloud for DR
| Setup | What it means | Good for | Watch out for |
|---|---|---|---|
| On premises to cloud | Production stays in your data centre; a cloud region is the DR site | Organisations without a second data centre, or replacing an ageing one | Bandwidth for replication, licences at DR, and the cost of bringing data back |
| Cloud region to cloud region | Production runs in one cloud region, DR in another region of the same provider | Workloads already in the cloud | Both regions share the same provider, account and identity system |
| Cloud to a different provider or back on premises | DR outside the provider that runs production | Regulated sectors worried about dependence on one provider | Two platforms to run and test, and services that do not translate one to one |
The most common design: on premises to a cloud region
A worked example
Forty servers, 20 TB of data, an RPO of 15 minutes and an RTO of four hours, with DR in an Indian cloud region. These are planning ranges to show where the money goes, not a quote. Prices vary by provider, region, commitment and discounts.
| Item | Basis | Planning figure |
|---|---|---|
| Staging storage for replicated disks | 20 TB × ₹5–8 per GB per month | ₹1.0–1.6 lakh |
| DR tooling, per protected server | 40 servers × ₹1,500–2,500 | ₹0.6–1.0 lakh |
| Small database replica, always on | One modest instance with storage | ₹0.4–0.8 lakh |
| Backup copy in locked object storage | 30 TB with retention × ₹1.5–2.5 per GB | ₹0.45–0.75 lakh |
| Connectivity | Site-to-site VPN or a small private link | ₹0.3–0.8 lakh |
| Standing cost per month | Sum of the above | about ₹3–5 lakh |
| Compute during a drill or disaster | 40 servers × ₹300–600 per day | ₹12,000–24,000 per day |
| Failback data transfer | 20 TB × ₹7–9 per GB out of the cloud | ₹1.4–1.8 lakh, once |
For comparison, a warm-standby second data centre for the same estate typically needs ₹1.5–3 crore of hardware up front, plus ₹3–6 lakh a month for colocation, power and connectivity. Cloud DR is usually cheaper for this size of estate. It becomes less attractive when DR servers must run all the time, or when large volumes of data move out of the cloud often.
The catches
Where the data may live
Some data must stay in India, for example payment data under RBI rules. Choose an Indian region (Mumbai, Hyderabad, Pune, Chennai or Delhi, depending on the provider) and check your sector regulator’s rules before you start.
Capacity on the day
In a regional event, many customers fail over at once. For critical tiers, reserve capacity or keep a small footprint always running rather than assuming servers will be available.
Licences at DR
Oracle, Microsoft SQL Server and Windows licences have specific rules for DR and for running in a public cloud. Check them during design, not after the first drill.
Getting data back
Data leaving the cloud is charged per GB. After a real failover, bringing tens of terabytes back to the primary site is a real cost and takes time. Plan failback as carefully as failover.
Bandwidth for replication
The link has to carry your daily change rate within the RPO. Measure the real change rate first; a guess here is the most common reason a cloud DR design misses its RPO.
One account, one key
If an attacker gets into the cloud account, both the DR servers and the backups are at risk. Keep backups in a separate account with locked retention and separate administrator credentials.
Common building blocks by provider
| Need | AWS | Azure | Oracle Cloud |
|---|---|---|---|
| Server replication and recovery | Elastic Disaster Recovery | Azure Site Recovery | Full Stack Disaster Recovery |
| Locked backups | AWS Backup with Vault Lock | Azure Backup with immutable vaults | Object Storage retention rules |
| Private connectivity | Direct Connect, Site-to-Site VPN | ExpressRoute, VPN Gateway | FastConnect, Site-to-Site VPN |
| Indian regions | Mumbai, Hyderabad | Pune, Chennai, Mumbai | Mumbai, Hyderabad |
Third-party tools such as Veeam and Zerto also replicate on-premises servers into these clouds, and are often the better choice when you want the same tool across several platforms.
Related guides
DR layer by layer
Traffic, network, databases, storage and messaging, with on-premises and cloud equivalents.
Read the guide →What DR really costs
Where the money goes, with planning ranges and a worked example.
Read the guide →HA, fault tolerance and DR
What each one protects against, and why you usually need all three.
Read the guide →Not sure where your DR stands?
Send us your application list and a short note on how backups work today. We will come back with a plain gap review: which systems are exposed, what a realistic recovery time looks like, and what it would take to close the gap.