Skip to content
Continuity

A backup you have not restored is a hypothesis

Green checkmarks in a backup console measure whether a job ran. They do not measure whether your business can come back.

5 min read

Backup software is very good at telling you that a backup job completed. It is considerably less good at telling you that the data inside it is usable, that you have somewhere to restore it to, or that anybody knows the sequence to bring the business back in.

Those are different claims, and only the first one is on the dashboard. The gap between them is where most disaster recovery failures actually live — not in a missing backup, but in a backup nobody had ever tried to use.

The three questions a green tick does not answer

  • How long would a full restore actually take? Not the marketing figure — the measured one, for your data volume, over your connection, onto hardware you have available.
  • Can the backups be deleted by an account an attacker might compromise? If yes, they are a copy, not a backup. Ransomware operators encrypt backups deliberately and they do it with valid credentials.
  • Who does the restore, and in what order? Domain controller, file server, line-of-business database, mail — the sequence matters, and working it out during an incident costs hours you do not have.

Test restores, on a schedule

The fix is unglamorous. Pick a system, restore it somewhere isolated, confirm the application actually starts and the data inside is current, write down how long it took, and file the result. Do it quarterly. Do it for a different system each time.

The first test restore at a new client almost always surfaces something: an excluded folder nobody noticed, a database that was backed up while running and is therefore inconsistent, a recovery that technically works but takes eleven hours against a stated objective of four. Every one of those is far better discovered on a Tuesday afternoon than during an outage.

A recovery time objective nobody has measured is not an objective. It is an aspiration.

Write down what you find

The test restore log is also the artifact that answers the insurance question, the audit question, and the board question. It converts “we have backups” — which everyone says — into a documented, dated demonstration that the business can be recovered, with a number attached to how long it takes.

That number is the one worth managing. Everything else on the backup dashboard is just telling you a job ran.

Written by the team at Summex Technologies.

Ask us about this

Next step

Wondering how your own setup would hold up?

We will look at it and tell you what we find, in plain language, whether or not it leads anywhere commercially.