Skip to Content

Backups: how to know they will actually restore

6 August 2026 by

Most companies have backups. Far fewer have ever restored one. The difference only becomes visible on the worst day of the year.

A backup that has never been restored is a hypothesis

Backup software reports success when it finishes writing files. It does not tell you whether those files can be turned back into a working system, whether the database inside them is consistent, or whether the one folder that matters was excluded two years ago.

What a real test looks like

  • Pick something specific: last month's accounts file, a mailbox, a whole server.
  • Restore it somewhere safe — not over the live copy.
  • Open it. Actually open it: the file, the mailbox, the application.
  • Write down how long it took. That number is your real recovery time.

Three questions worth answering in writing

How much work can we afford to lose? If backups run nightly, the answer is one day. If that is too much, they need to run more often.

How long can we be down? Restoring a mailbox is minutes; rebuilding a server from scratch can take a day. Knowing which one you are buying matters more than the size of the disk.

Where is the copy that ransomware cannot reach? A backup drive permanently connected to the machine it protects is not a backup, it is a second copy waiting to be encrypted with the first.

How we handle it

On managed contracts backups are monitored and restore-tested regularly, and the results are part of the periodic IT review — so the answer to "when did we last check" is never "nobody knows".

Cyber security and backup · Free IT health check

Microsoft 365 in a small company: five settings that make your mail safer