Cold Site
A cold site is a backup facility that provides the basic infrastructure needed to run computer systems, such as physical space, power, cooling, and network connectivity, but does not have any computer equipment installed and ready to use. Because the systems must be brought in and set up before operations can resume, recovering from a disaster using a cold site typically takes the longest, often measured in days to weeks. Cold sites are generally the least expensive of the standby recovery site options.
A cold site is a disaster recovery standby facility equipped with the necessary environmental and physical components of a computer facility, including electrical power, cooling, and network connectivity, but without preinstalled or preconfigured computing equipment, systems, or current data. Restoring operations at a cold site requires procuring and installing hardware, configuring systems, and restoring data from backups, which results in recovery time objectives (RTOs) that are typically the longest among cold, warm, and hot site options, often ranging from days to weeks. As the least resource-provisioned and typically least costly of the standby site types, a cold site trades lower ongoing cost for slower recovery, in contrast to a warm site (partially provisioned) and a hot site (fully provisioned and ready for near-immediate failover).
Why it matters
For security and continuity leaders, the choice of recovery site directly shapes how quickly an organization can resume operations after a disruptive event such as a data center failure, natural disaster, or facility loss. A cold site represents the low-cost end of the standby recovery spectrum, offering the basic environmental foundation of a computer facility, such as space, power, cooling, and network connectivity, without any preinstalled computing equipment. This makes it attractive when budgets are constrained, but it also means recovery is the slowest of the standby options, typically measured in days to weeks because hardware must be procured, installed, configured, and loaded with data before operations can resume.
Understanding this tradeoff matters because a cold site is only appropriate for systems and business functions that can tolerate extended downtime. Selecting a cold site for a workload with a short recovery time objective creates a dangerous mismatch between the recovery capability an organization believes it has and what it can actually deliver under pressure. A virtual or fractional CISO advising on business continuity strategy will typically help a client map recovery site choices to the criticality of each system rather than defaulting to the cheapest option across the board.
Accountability for these decisions generally remains with the client organization and its officers. A vCISO advises on the risk tradeoffs, helps define acceptable recovery objectives, and directs continuity planning, but the organization retains responsibility for funding, provisioning, and maintaining the chosen recovery arrangements. The value of that guidance depends heavily on organizational maturity, stakeholder cooperation, and honest assessment of downtime tolerance.
Who it's relevant to
Inside Cold Site
Common questions
Answers to the questions practitioners most commonly ask about Cold Site.