Your backup isn't a backup until you've restored from it
Closetags
5 min read
Most organisations discover their backup strategy doesn't work during the incident it was supposed to cover. Test quarterly, and document the test.
We have never been called to a ransomware incident where the client didn't have backups. We have frequently been called to one where the backups couldn't be restored.
The common failure modes
- The backup ran nightly but silently failed eleven months ago.
- The backup is on a network share the ransomware also encrypted.
- Nobody knows the restore credentials because the person who set it up left.
- The restore works but takes nine days at the available bandwidth.
What to actually do
Follow 3-2-1: three copies, two media types, one offsite and offline. Then, once a quarter, restore something real to a scratch environment and time it. Write down how long it took. That number is your actual recovery time objective, regardless of what the policy document claims.
Got a project in mind?
We'll tell you honestly whether we're the right fit.