Failover, Backups and Disaster Recovery
Power cuts, server crashes and broker outages happen. Learn how traders and trading systems plan for disasters, with backups, failover and tested recovery steps.
Disaster recovery is the plan for what happens when something big breaks: a server dies, a data centre loses power, the internet goes down, a broker has an outage or a bad deployment corrupts the system. Trading makes these events especially costly because open positions keep moving while you are offline. A good recovery plan defines how quickly you need to be back, how you will get there and how you will manage open risk in the meantime. For a solo trader it can be a one page checklist; for a firm it is a tested, documented process.
Key concepts#
| Term | Meaning |
|---|---|
| Recovery time objective (RTO) | How quickly the system must be running again |
| Recovery point objective (RPO) | How much data loss is acceptable, measured in time |
| Failover | Switching to a backup system |
| Backup | A copy of data or configuration that can be restored |
| Runbook | Step by step instructions for a specific failure |
Common disaster scenarios#
| Scenario | Impact | Mitigation |
|---|---|---|
| Home internet or power outage | Cannot reach broker | Mobile hotspot, battery backup, broker phone desk, run bots on a remote server. See VPS, Cloud and Bare-Metal Servers |
| Server crash | Bot stops; positions unmanaged | Automatic restart, standby server, broker side stops |
| Data centre outage | Whole system down | Second location or cloud region. See Fault Tolerance, High Availability and Redundancy |
| Broker outage | Cannot trade or exit | Accounts at a second broker, hedging with other instruments |
| Bad deployment | Wrong behaviour | Rollback plan, staged releases |
| Data corruption | Wrong positions or history | Regular backups, reconciliation with broker records |
Broker side protection#
The single most useful protection for many traders is placing stop orders at the broker rather than only inside a local program. If your system disappears, broker side stops still protect positions. Bracket and OCO orders keep exits alive even when you are offline. See Bracket Orders and OCO Orders. Note that stops do not protect against gaps. See Price Gaps and How to Trade Them.
A recovery runbook#
- Assess: what failed and what positions and orders are open?
- Protect: ensure open positions have protective orders; if unsure, reduce risk through any available channel, including the broker's phone desk.
- Restore: bring up the backup system or restore from backup.
- Reconcile: confirm positions and orders match the broker's records before trading resumes. See Trade Accounting and Reconciliation.
- Resume carefully: restart with reduced size or in a monitoring mode.
- Review: document what happened and improve the plan.
Backups#
| What to back up | How often |
|---|---|
| Code | Every change, in version control |
| Configuration and parameters | Every change |
| Trade and order records | Daily or continuously |
| Historical data | Regularly, with checksums |
| Credentials | Stored securely, recoverable by authorised people only |
A backup that has never been restored is not proven to work. Test restores periodically.
Testing the plan#
Run drills: shut down the main server and fail over, restore a database from backup, practise reaching the broker by phone. Time each step and compare against your recovery time objective. Firms often run scheduled disaster recovery tests, and some regulations require them.
Frequently asked questions#
What is disaster recovery in trading?#
The plan and tools for restoring trading systems and protecting open positions after major failures such as outages, crashes or data loss.
How can retail traders protect against outages?#
Place stops at the broker, keep a mobile app and broker phone number ready, use backup internet and power, and run automated systems on a remote server.
What are RTO and RPO?#
Recovery time objective is how fast you must recover; recovery point objective is how much recent data you can afford to lose.
Next, learn how to keep complete records of every action in Logging, Audit Trails and Incident Response.
3 quick questions on this lesson. Get them all right to finish it.
Turn on JavaScript to take the quiz.
Mentioned in
- Automated vs Semi-Automated TradingAlgorithmic Trading
- Building Trading BotsProgramming and Data
- Data Storage, Compression and CachingProgramming and Data
- Trading Infrastructure ExplainedTrading Infrastructure
- Record Keeping for TradersThe Trading Industry