Your backup isn't a backup until you've restored from it

Closetags 5 min read

Most organisations discover their backup strategy doesn't work during the incident it was supposed to cover. Test quarterly, and document the test.

We have never been called to a ransomware incident where the client didn't have backups. We have frequently been called to one where the backups couldn't be restored.

The common failure modes

  • The backup ran nightly but silently failed eleven months ago.
  • The backup is on a network share the ransomware also encrypted.
  • Nobody knows the restore credentials because the person who set it up left.
  • The restore works but takes nine days at the available bandwidth.

What to actually do

Follow 3-2-1: three copies, two media types, one offsite and offline. Then, once a quarter, restore something real to a scratch environment and time it. Write down how long it took. That number is your actual recovery time objective, regardless of what the policy document claims.

Got a project in mind?

We'll tell you honestly whether we're the right fit.

Start a project