To check whether a business backup works, restore an agreed sample to a separate, protected location and have the person who uses that information confirm it is usable. Record which recovery point was used, how long the exercise took, and what was not tested. A completed backup job alone does not answer those questions.

This guide is for a planned exercise while systems are operating normally. If files are already missing, storage is failing, or compromise is suspected, start with the first steps after data loss and get the incident assessed before experimenting with recovery.

01

Decide what the exercise needs to prove

Choose one business task: opening a current project folder, recovering an older document, or retrieving information needed to resume a specific piece of work. Name the person who can judge the result.

Write down the question before opening the backup console. “Can the office manager retrieve the agreed folder from last week and use it?” is easier to evaluate than “Are our backups good?”

For the wider plan, use the business backup and disaster recovery checklist. A file test is one part of that plan; recovery of identity, applications, devices, and the workplace may require different exercises.

02

Agree the boundaries before restoring

The authorized administrator and business owner should agree on the sample, recovery point, destination, access permissions, and stopping conditions. Use a sample that represents real work without exposing more confidential information than necessary.

Keep the exercise separate from production. Do not delete a live file to manufacture a test or accept an overwrite prompt just to see what happens. If the product cannot restore safely to a separate destination, ask the provider for its supported testing method before proceeding.

Confirm who will remove the temporary restored copy after acceptance and how it will be handled under the business’s existing retention rules. The exercise should not leave an unmanaged second copy of customer or employee data.

03

Check the result with the person who uses it

Successful retrieval and useful recovery are different checks. Follow the provider’s documented restore procedure, then ask the intended user to examine the sample in the appropriate application.

Check Evidence to record
Correct source The agreed folder, account, or workload was selected.
Correct point in time The recovered version matches the requested date or state.
Useful content The expected information is present and readable.
Appropriate access The intended person can use the result without giving unrelated people access.
Dependencies Required applications, linked files, or other dependencies are available, or the gaps are recorded.
Elapsed time Time spent obtaining access, restoring, and checking the result is recorded separately where useful.

For example, a recovered project document might open correctly while its linked images are absent. Record that as an incomplete result for the chosen task. Do not turn a successful download into a claim that the whole project is recoverable.

04

Keep a short restore record

Use the same record for each planned exercise:

  • Date, person performing the exercise, and approving owner
  • Business task and sample selected
  • Backup source and recovery point
  • Protected restore destination
  • Start and finish times
  • Checks completed and who accepted the result
  • Missing items, access problems, and dependencies
  • Workloads and failure scenarios not tested
  • Follow-up owner and next review date
  • Confirmation that the temporary copy was handled as agreed

Do not put passwords, recovery codes, or the recovered data itself in this record. It should describe the evidence and where authorized people can find it.

05

Treat a pass as specific evidence

A successful folder restore supports a narrow conclusion: that sample could be recovered from that point, with the access and systems available during the exercise. It does not establish that the business could recover after losing its administrator account, its entire NAS, or its office.

Review failures and choose the next exercise around the largest unresolved business dependency. Set the review frequency according to the importance of the work and changes in the environment. CISA recommends regularly testing backups; NIST’s contingency planning guidance also treats testing and plan maintenance as part of recovery preparation.

06

How TTCo can help

Tyler’s Tech Company provides backup and disaster recovery planning for Greater Boston small businesses. The published initial assessment covers discovery and a written recovery-priority plan. Restore drills, implementation, backup products, and incident response are separately scoped; a planning engagement does not mean a restore has already been tested.

Bring a description of where important work lives, the backup product if known, who receives failure alerts, and the date of the last documented restore. That is enough to begin the conversation without sending credentials or private files.

07

Official sources