Skip to main content
Category: Business Continuity & Resilience

Cold Site

Also known as: Cold Backup Site, Cold Recovery Site
Simply put

A cold site is a backup facility that provides the basic infrastructure needed to run computer systems, such as physical space, power, cooling, and network connectivity, but does not have any computer equipment installed and ready to use. Because the systems must be brought in and set up before operations can resume, recovering from a disaster using a cold site typically takes the longest, often measured in days to weeks. Cold sites are generally the least expensive of the standby recovery site options.

Formal definition

A cold site is a disaster recovery standby facility equipped with the necessary environmental and physical components of a computer facility, including electrical power, cooling, and network connectivity, but without preinstalled or preconfigured computing equipment, systems, or current data. Restoring operations at a cold site requires procuring and installing hardware, configuring systems, and restoring data from backups, which results in recovery time objectives (RTOs) that are typically the longest among cold, warm, and hot site options, often ranging from days to weeks. As the least resource-provisioned and typically least costly of the standby site types, a cold site trades lower ongoing cost for slower recovery, in contrast to a warm site (partially provisioned) and a hot site (fully provisioned and ready for near-immediate failover).

Why it matters

For security and continuity leaders, the choice of recovery site directly shapes how quickly an organization can resume operations after a disruptive event such as a data center failure, natural disaster, or facility loss. A cold site represents the low-cost end of the standby recovery spectrum, offering the basic environmental foundation of a computer facility, such as space, power, cooling, and network connectivity, without any preinstalled computing equipment. This makes it attractive when budgets are constrained, but it also means recovery is the slowest of the standby options, typically measured in days to weeks because hardware must be procured, installed, configured, and loaded with data before operations can resume.

Understanding this tradeoff matters because a cold site is only appropriate for systems and business functions that can tolerate extended downtime. Selecting a cold site for a workload with a short recovery time objective creates a dangerous mismatch between the recovery capability an organization believes it has and what it can actually deliver under pressure. A virtual or fractional CISO advising on business continuity strategy will typically help a client map recovery site choices to the criticality of each system rather than defaulting to the cheapest option across the board.

Accountability for these decisions generally remains with the client organization and its officers. A vCISO advises on the risk tradeoffs, helps define acceptable recovery objectives, and directs continuity planning, but the organization retains responsibility for funding, provisioning, and maintaining the chosen recovery arrangements. The value of that guidance depends heavily on organizational maturity, stakeholder cooperation, and honest assessment of downtime tolerance.

Who it's relevant to

Business Continuity and Disaster Recovery Planners
Those responsible for DR strategy use the cold, warm, and hot site distinction to match recovery capabilities to the downtime tolerance of each system. A cold site is typically suited to functions that can accept days-to-weeks recovery windows, and it should not be assumed adequate for workloads with short recovery time objectives.
Virtual and Fractional CISOs
In continuity and resilience engagements, a vCISO or fractional CISO often advises on the cost-versus-recovery-speed tradeoffs of standby site options and helps align them with defined recovery objectives. Their role is generally to direct strategy and governance rather than to perform the hands-on procurement, installation, and configuration required to stand up a cold site, and accountability for those decisions typically remains with the client organization.
IT and Infrastructure Leaders
Teams that would execute a recovery need to understand that a cold site is essentially an empty, environmentally prepared facility. They are responsible for the procurement, hardware installation, system configuration, and data restoration that determine whether the days-to-weeks recovery estimate holds in practice.
Finance and Executive Stakeholders
Because a cold site is often the least costly standby option, executives weighing budget against risk benefit from understanding that the lower ongoing cost is paid for with the longest recovery time. This helps avoid a mismatch between assumed and actual recovery capability.

Inside Cold Site

Physical facility space
Floor space and a controlled environment intended to house IT equipment during a recovery, provided without the equipment itself pre-installed.
Power and cooling infrastructure
Electrical supply and environmental controls sufficient to support computing hardware once it is brought in and set up.
Network connectivity
Communications links that can be used to reconnect systems and users, though configuration is typically required at activation time.
Absence of standing hardware and data
Unlike warm or hot sites, a cold site generally has no provisioned servers, no configured systems, and no replicated or standing data, which is the defining characteristic driving its longer recovery timeline.
Dependency on backups
Restoration relies on transporting or restoring data from the organization's most recent recoverable backups, so the achievable recovery point depends on backup currency.
Recovery time and recovery point implications
A cold site is associated with a comparatively long RTO and an RPO tied to the last usable backup, in contrast to the faster recovery profiles of warm and hot sites.

Common questions

Answers to the questions practitioners most commonly ask about Cold Site.

Does a cold site let us get back up and running immediately after a disaster?
No. This is a common misconception. A cold site typically provides only facility infrastructure such as space, power, and connectivity, without pre-installed servers, applications, or current data. Before operations can resume, hardware must be brought in and configured and data restored from backups, which generally means a longer recovery time than warm or hot sites.
Is a cold site just a cheaper version of the same thing as a hot site?
Not exactly. While a cold site is generally less costly, the difference is not only price but recovery capability. A hot site is typically fully provisioned with systems and often near-real-time data replication, whereas a cold site requires provisioning and restoration after a disaster. Treating them as interchangeable but cheaper versions overlooks the substantial difference in recovery time and data currency.
How do we decide whether a cold site is appropriate for our organization?
The decision typically turns on your Recovery Time Objective and Recovery Point Objective relative to budget. If the business can tolerate a longer outage and some data loss bounded by backup frequency, a cold site may be a reasonable fit. Where downtime tolerance is low, a warm or hot site is often more appropriate. This is a business risk decision, so it is best made with input from stakeholders who understand the operational impact of downtime, not solely technical staff.
What needs to be in place for a cold site to actually work when we need it?
Effectiveness depends on several factors beyond the facility itself: current and tested backups, a documented and rehearsed recovery procedure, a reliable means of obtaining or relocating hardware, and clarity on who executes each step. Without these, a cold site can look adequate on paper yet fail to deliver during an actual incident.
Should we test a cold site, and how?
Yes, periodic testing is generally advisable because much of a cold site's recovery process happens only after a disaster is declared. Testing may involve validating that backups can be restored, confirming hardware provisioning arrangements, and walking through or executing recovery procedures. Testing helps reveal gaps in assumptions about time, availability, and documentation before a real event occurs.
Where does a virtual or fractional CISO fit into cold site decisions?
A vCISO or fractional CISO typically advises on continuity strategy, helps frame the cold site decision within the organization's risk tolerance and governance, and reviews whether recovery arrangements align with business needs. They generally do not perform hands-on tasks such as building out the site or executing restoration unless explicitly contracted, and accountability for the recovery decision remains with the client organization and its officers.

Common misconceptions

A cold site can be activated quickly, like a hot site.
A cold site typically provides only space, power, cooling, and connectivity, with no standing hardware or data. Bringing in equipment, configuring systems, and restoring data takes significant time, making a cold site the slowest of the common recovery options.
Because it is the cheapest option, a cold site is the right choice for all systems.
The lower cost reflects a trade-off against longer downtime. A cold site may be appropriate for functions that can tolerate extended outages, but critical systems with tight RTO and RPO requirements often need a warm or hot site. The decision should follow from a business impact analysis and documented risk tolerance.
Having a cold site means data recovery is guaranteed.
A cold site itself holds no standing data. Recovery depends entirely on the availability and currency of the organization's most recent viable backups and on tested recovery procedures; the site alone does not ensure data can be restored.

Best practices

Base the choice of a cold site on documented RTO and RPO requirements derived from a business impact analysis, rather than on cost alone.
Ensure the recovery plan reflects that a cold site requires equipment procurement or transport, system configuration, and data restoration, and account for the time each step consumes.
Maintain reliable, recent, and recoverable backups, since a cold site's recovery capability depends on the currency and integrity of those backups.
Document detailed activation and restoration procedures so the site can be brought online consistently under pressure, and keep this documentation current.
Periodically test activation of the cold site, including data restoration and system validation, to confirm that stated recovery timelines are realistic.
Clearly assign organizational accountability for accepting the extended downtime risk associated with a cold site, keeping that decision with client leadership even where a vCISO advises on the strategy.