The green tick in the backup console means one thing: a job ran and did not report an error. It does not mean the data is complete, or readable, or that anyone knows the password to decrypt it, or that restoring it takes less than a week. Those are different questions, and the console does not ask them.
We have walked into three ransomware recoveries in which the backups were, according to every dashboard, perfect. In one the job had been faithfully backing up an empty folder since a server migration two years earlier. In another the encryption key lived in a password manager on the server that had just been encrypted. In the third the backups were fine, and restoring them over the office internet connection would have taken nineteen days.
Nobody wants backups. What they want is restores.
The Friday test
Once a month, pick a quiet afternoon and restore something real to somewhere it did not come from. Not a single file back to its original folder. A whole mailbox, a whole database, a whole virtual machine, onto different hardware, by someone following only the written procedure.
- Choose at random. If you always test the same small share, you have proven that one small share is recoverable.
- Restore to somewhere else. A spare machine or an isolated cloud instance. If the original hardware is gone, "restore in place" is not an option you will have.
- Time it. Start a stopwatch. The number you get is your real recovery time, and it is the one to give your directors.
- Open the data. Start the database. Open the spreadsheet. Log in to the restored server. A file that exists is not the same as a file that works.
- Write down what went wrong. Something will. That is the point of doing it on a Friday in August rather than a Monday in crisis.
What good looks like
| Question | Bad answer | Good answer |
|---|---|---|
| When was the last restore? | "The jobs are all green." | A date, within the last month |
| How long does a full restore take? | "A few hours, probably." | A measured number |
| Where is the decryption key? | "In the backup software." | Printed, in a safe, off site |
| Can ransomware reach the backups? | "They are on the NAS." | One copy is offline or immutable |
Three, two, one, and one more
The old rule still holds: three copies, on two kinds of storage, one of them off site. The modern amendment is that at least one copy must be somewhere an attacker with your administrator password cannot delete it. Immutable cloud storage does this. So does a disk in a drawer, which is unfashionable and has never once been encrypted over the network.
If you only do one thing
Put a recurring appointment in the calendar for the last Friday of the month, titled restore something. Invite the person who would have to do it for real. The first one will be uncomfortable. By the third it will take forty minutes, and you will know something about your organization that almost nobody knows about theirs.