Your backup is a hope until you've restored it

Most businesses have backups they've never once restored. The day you find out whether they work is the worst possible day to find out. Test it on a good day instead.

Ask a business owner if they’ve got backups and the answer is almost always yes. Ask when they last restored one and watched it come back whole, and the room goes quiet.

That gap is where disasters live. A backup you’ve never restored isn’t a safety net. It’s a belief. You believe the files are there, you believe they’re complete, you believe you could get them back if it came to it. Belief is lovely right up until a server dies, a laptop gets stolen, ransomware locks the lot, or someone deletes the wrong folder on a Friday afternoon. That’s when belief meets reality, and reality doesn’t care how confident you were.

The uncomfortable truth is that a backup is a guess until the moment you’ve proven it. And the only way to prove it is to actually restore from it, on a normal day, when nothing’s on fire.

The backups that fail are the ones nobody checked

Backup failures are rarely dramatic. The drive isn’t smoking. The problem is quieter and meaner than that.

The backup ran every night and emailed a green tick, but it stopped including the database three months ago after a config change nobody noticed. The cloud sync was on, but it was syncing deletions too, so when the ransomware encrypted everything, the encrypted versions dutifully synced over your good copies. The external drive in the drawer has last year’s data because the person who used to swap it left. The backup covers the file server but not the accounting software, which lives somewhere else entirely. The whole thing was set up beautifully in 2021 and hasn’t been looked at since.

Every one of those looks fine from the outside. The backup “exists.” It’s only when you try to bring something back that you learn the copy is partial, or stale, or corrupted, or missing the one system you actually needed. And you learn it at the exact moment you can least afford to.

The 3-2-1 rule, and why the “1” is the one that saves you

The old rule still holds because it keeps working: three copies of your data, on two different types of storage, with one kept off-site. It’s not complicated, and most failures come from quietly breaking one leg of it.

Three copies means the live data plus two backups, so a single failure never leaves you with nothing. Two types of storage means you’re not trusting one device or one vendor to never let you down. And the off-site copy is the one that saves you from the disasters that take the whole building or the whole account: the fire, the flood, the theft, the ransomware that reaches every drive on the network at once.

That off-site, offline copy matters more than people think, because modern ransomware specifically hunts for connected backups. If your backup drive is plugged in and mapped, or your backup account uses the same login as everything else, the attack takes your backups along with your live data. A copy that’s genuinely disconnected, or held by a service the attacker can’t reach with your stolen password, is often the difference between a bad week and a closed business. Immutable or versioned backups, where a copy can’t be altered or deleted for a set period, are worth asking your provider about by name.

The test that takes an afternoon and tells you the truth

Here’s the exercise, and it’s not glamorous. Pick a real file, or better, a real system, and restore it. Not check that the backup ran. Restore it, open it, and confirm it’s whole.

  • Restore something real, to somewhere safe. Pull a document, a database, a mailbox, from the backup to a separate location, and actually open it. Does it work? Is it the current version or last quarter’s? Are the attachments there, or just the records that point to them?
  • Time it. Note how long the restore takes, because “we have a backup” and “we’re back trading” are different sentences. If restoring your main system takes three days, that’s three days shut, and you need to know that now, not then.
  • Restore the thing you’d actually need, not the easy thing. The file server is usually the easy restore. The hard one is the line-of-business system: the accounting package, the job database, the customer records with all their history and links intact. Test that one, because that’s the one whose loss stops the business.
  • Check what’s not covered at all. Walk the list of systems you run and tick off which are actually in the backup. The SaaS tools are the classic blind spot. Plenty of businesses assume their cloud provider backs up their data, when the provider’s job is to keep the service running, not to undo your accidental deletion from six weeks ago. Read what your critical SaaS tools actually promise about recovery, in writing.

Do this once and you’ll find at least one surprise. Everyone does. The point of finding it today is that today you can fix it calmly.

Ransomware changed the question

Backups used to be about accidents: a dead drive, a fat-fingered delete, a flood. Those still happen. But the threat that’s put a lot of small businesses out for good is ransomware, and it changes what a good backup has to survive.

A ransomware attack doesn’t just encrypt your live data. It looks for your backups and tries to take those too, because the criminals know that a business with a clean, reachable backup won’t pay. That’s why the offline, off-site, unchangeable copy has gone from good practice to the thing that decides whether you’re negotiating with criminals or restoring from Tuesday. If every copy of your data can be reached from one compromised login, you don’t have three backups. You have three copies of the same single point of failure.

This isn’t only a big-company problem. Small businesses get hit precisely because they’re assumed to have weaker recovery, and often the assumption is right. Good backup and security practice isn’t paranoia. It’s the cheapest insurance you’ll ever run, and unlike most insurance, you can test the payout before you need it.

Write down what “back to normal” actually means

The last piece is the one nobody enjoys, and it’s the one that turns backups into a plan you can trust.

Decide, in plain numbers, two things. How much data can you afford to lose, measured in time? An hour? A day? A week? That tells you how often the backup has to run. And how long can you afford to be down while you recover? That tells you how fast your restore has to be, and whether last night’s copy on a slow drive is good enough or whether you need something quicker to bring back.

Those two numbers, written down and agreed, turn “we have backups” into “we can be trading again within X hours and lose at most Y hours of work.” That’s a sentence you can actually rely on. The vague version isn’t a plan. It’s the same hope you started with, wearing a nicer shirt.

None of this needs to be a big project. It needs an afternoon, an honest test, and a note in the calendar to do it again every few months. If you’re not sure your backups would survive a bad day, or you’ve never once watched a restore come back whole, tell us what you’re running and we’ll help you test it while the building’s still standing.

Back to all insights

Turn the thinking into a plan.

Send the process, risk or idea. We'll help you work out what's worth doing first.