Backups You Have Actually Tested
Almost every business will tell you they have backups. Far fewer can tell you when somebody last restored one, what was in it, or how long a full recovery would take. That gap is where most of the trouble lives.
A backup you have never restored is not a control. It is an assumption with a monthly bill attached.
The four questions worth answering
You do not need a technical review to work out whether your position is sound. Four plain questions do most of the work, and any provider should be able to answer them without hesitating.
- What is actually backed up. Files and email are the obvious ones. What about the CRM, the accounting system, the booking platform, the shared drive somebody set up in 2021.
- How often, and how much would we lose. A nightly backup means up to a day of work is gone. That may be fine or it may not, and it should be a decision rather than a default.
- How long would it take to get back. Restoring a single file is minutes. Rebuilding a system is a different exercise, and the honest number is usually longer than people expect.
- When did somebody last prove it works. Not a green tick in a console. An actual restore, performed by a person, with the result checked.
Cloud systems are not automatically covered
This is the most common misunderstanding in small businesses. If your data sits in a well known cloud service, the provider is protecting their infrastructure. They are usually not protecting you from your own mistakes.
Most platforms keep deleted items for a limited window, often thirty days, and then they are gone. That covers an accidental deletion noticed quickly. It does not cover a record quietly corrupted six months ago, a departing employee who cleared a folder, or an integration that overwrote a field across thousands of records.
Read what your key platforms actually promise. Then decide whether you need your own copy of anything important.
The provider protects their service. Protecting yourself from what happens inside your own account is still your job.
Test the restore, not the backup
Testing sounds like a project. It is not. Once a quarter, pick something and get it back.
One month, restore a single document from three months ago and check it opens and is the right version. Another quarter, export a full copy of the customer data from your main system and open it. Once a year, walk through what a full rebuild would involve, even if you only do it on paper.
Write down what you tested, who did it, how long it took and what went wrong, because something always does the first time. That record is the difference between believing you are covered and knowing it.
Keep one copy out of reach
The classic advice still holds. Several copies, on more than one kind of storage, with at least one held somewhere separate.
The part that matters most now is separation. A backup that can be deleted by the same account that manages your live systems is only protecting you from accidents, not from anything deliberate. At least one copy should require different credentials to remove, or be immutable for a set period.
Know who can restore, and how they reach it
The people question defeats more recoveries than the technology does. If one person holds the credentials and they are unreachable, you do not have a backup, you have a dependency.
Two people should be able to start a restore. The instructions should exist somewhere that does not require the system being restored. And whoever answers the phone at your provider should be a known contact rather than a general support queue you meet for the first time on a bad day.
Decide what you can afford to lose
Not everything deserves the same protection, and treating it all equally is how businesses overspend and still miss the important thing.
Sort your systems into three groups. The ones where losing a day of work would be serious. The ones where a week would be survivable. And the ones where it would barely register. Then match the frequency and the effort to each group.
That conversation usually surfaces something interesting. Often the most critical data set is the one nobody had classified at all, because it lives in a platform somebody signed up for without telling anyone.
Put it on a schedule with a name next to it
Backup checks belong in the same category as the access review and the continuity plan. A quarterly item, an owner, a short written record, and a place on an agenda that already exists.
This is process work rather than technical work, and it is the kind of thing we help businesses put in place. Working out what matters, writing down who does what, and making sure somebody actually tries a restore before the day it counts.
The question is not whether you have backups. It is when somebody last proved it.
Want a straight answer on what is covered and what is not? Book a consultation, or visit www.expertechsolution.com.