Skip to content
هذه الصفحة بالإنجليزية. اقرأها بالعربية
UpgradIQ
Insights

A backup you have never restored is a claim

Everybody has backups. Far fewer have ever restored one, and the difference between those two states only becomes visible on the worst day.

5 min readWeb developmentAI transformation
The short answer

Restore a backup into a separate environment this quarter and time how long it takes. Until that has happened, you do not have a backup, you have a scheduled job that reports success.

Backups fail silently, by design

A backup job reports on whether it ran, not on whether what it produced can be used. A file can be written every night for a year and be unusable because a table was excluded, an encryption key was rotated, or the format cannot be read by the version you now run.

None of that appears in the report. It appears at the moment you need the data, which is also the moment you have the least time to deal with it.

What to verify this quarter

The exercise is half a day and it either confirms the arrangement or finds the gap while the gap is still cheap.

  • Restore last night's backup into a separate environment, end to end
  • Time it, and write the number where the business can see it
  • Confirm what is missing: uploaded files, mailboxes, third-party data
  • Check that somebody other than one person can perform the restore
  • Confirm at least one copy is somewhere a compromised account cannot reach
  • Check how far back the copies go, and whether that matches any obligation you have

Two numbers, in plain words

How much data can you afford to lose, and how long can you afford to be down. Those two answers set everything else: how often backups run, where they are kept, and what the arrangement costs.

Most offices have never been asked. Answering them takes one meeting and turns backup policy from a technical preference into a business decision somebody has signed off.

The parts outside the database

Databases get backed up because they are obvious. Uploaded documents, generated invoices, mailboxes, the configuration of the systems themselves and data that lives inside third-party services often do not.

Write down what a full recovery would need and check each item separately. A recovered database that references ten thousand missing files is a partial recovery being described as a complete one.

Who can do it, and can they do it alone

If one person holds the credentials and the knowledge, your recovery plan has a single point of failure that takes annual leave. Two people should have performed a restore, and the steps should exist in writing outside the systems being restored.

A recovery procedure stored only inside the system it recovers is a common and entirely avoidable mistake.

Answers

What to take from this

  • 01A backup job that reports success is not evidence of a usable backup
  • 02Restore into a separate environment and record how long it took
  • 03Agree how much data you can lose and how long you can be down, in a meeting
  • 04Files, mailboxes and third-party data need their own answer
Nothing here answers it

Ask the question directly

Our provider says backups are included. Is that enough?
It covers their infrastructure failing. It does not cover a bad deployment, a mistaken deletion or an account compromise, and the retention period is often shorter than people assume. Read the retention and test a restore.
How often should we test?
Quarterly is a reasonable default, and after any significant change to the system. The point of a schedule is that the test happens when nothing is wrong.
Is a copy in the same account acceptable?
Not on its own. A copy that can be deleted by whoever can delete the original protects you from hardware failure and from nothing else.
Where it applies

Related answers

Service 02

Web development

New builds, rescues and re-platforms, measured against what the site earns rather than against how it looks. The brand system that carries it is built in the same engagement.

Service 01

AI transformation

Most AI projects fail because they add a chat box next to the problem instead of removing the step that costs the hours. We start from the workflow, and from the systems and the data underneath it.

Bring the decision you are stuck on

A call, forty five minutes, no deck. We will tell you if we are the wrong firm.