Skip to content
AspirecoStart
All answers

Cybersecurity

Why doesn't a backup count until you've restored it?

The short answer

Because a backup is only a claim until you have restored from it. Restores fail for ordinary reasons — missing files, missing credentials, a copy nobody checked, a restore that takes far longer than the business can wait — and those are better found on a quiet day.

Updated

Where untested backups fail

  • The copy covers the database but not the files or configuration it depends on.
  • The credentials needed to bring systems back were never included.
  • The backup is incomplete or corrupt, and nobody has looked.
  • The restore works but takes much longer than the business can be down.

What testing means

Actually restore into a separate environment, check that what comes back works, and time it. Then write the steps down, so the next person follows a procedure instead of improvising under pressure.

Where it sits

A tested backup and restore — plus a written path for the day something is breached — is one deliverable of an application security review. More in what a first security review covers.

Asked next

How often should we test restoring a backup?

Often enough that the procedure is current: after major changes to the system, and on a regular schedule otherwise. A restore tested once, years ago, describes a system that no longer exists.

Isn't our cloud hosting already backed up?

Some of it, sometimes. A provider may back up its infrastructure without giving you your data in a form you can restore on your own schedule. Check what is covered, how long it is kept, and who can actually run the restore.