1. Know who controls each dependency

Record the business owner for the domain registration, DNS, hosting, content system and email. Keep current recovery contacts and require more than one authorised person where appropriate. Separation can reduce some risks, but it is not a substitute for tested recovery access.

2. Keep a recoverable copy

Use backups outside the failed system’s boundary. Test a restoration, including content, media, configuration and required data. A search engine cache is not a backup and should not be part of the recovery plan.

3. Return the response that matches the situation

For genuinely temporary maintenance, a 503 response can tell clients and crawlers that the service is unavailable. Use Retry-After only when there is a defensible estimate. Do not leave a temporary response in place indefinitely, and do not return a successful page that hides a failed application.

4. Restore known URLs and customer journeys

Keep an inventory of important URLs, forms and purchase steps. After recovery, test responses, redirects, canonical URLs and monitoring. If addresses changed, redirect each old URL only to a relevant replacement.

See our hosting ownership checks, domain migration guide and agent-operated website work.