Skip to content

IT & Resilience

Your backups are worthless until you've tested a restore

11 July 2026 · Syprical

Almost every business believes it has backups. Far fewer have tested them. And there’s a painful gap between “we have a backup” and “we successfully restored the business from that backup”, a gap people usually discover at the worst possible moment.

Backups are your insurance policy against ransomware, hardware failure, accidental deletion, and honest human error. But an untested backup is a guess, not a guarantee.

Why this matters more than it used to

Ransomware changed the stakes. Modern attackers don’t just encrypt your files and demand payment. They specifically hunt for and delete or encrypt your backups first, because they know your backups are the thing that lets you say “no” to their ransom. If your backups survive, you can recover on your own terms. If they don’t, you’re negotiating with criminals.

That single shift is why “do you have backups?” is no longer the right question. The right questions are: are they isolated, are they recent enough, and have you proven you can restore from them?

The 3-2-1 rule (still the best starting point)

A simple, durable guideline:

  • 3 copies of your important data,
  • on 2 different types of media/locations,
  • with 1 copy kept off-site and offline (or otherwise isolated from your network).

That off-site, isolated copy is the one ransomware can’t reach. It’s the difference between a bad week and a closed business.

The part everyone skips: testing

A backup you’ve never restored is a theory. Real backup testing answers concrete questions:

  • Does the restore actually complete, or does it error out halfway?
  • How long does it take? If restoring your systems takes five days, that’s five days you’re not trading.
  • Is the data usable once restored: the right version, not corrupted, not missing the last month?
  • Do you know the steps, or will you be improvising during a crisis?

Schedule a restore test on a regular cadence, at minimum a few times a year, and treat it like a fire drill. The first one almost always surfaces a surprise, which is exactly why you want to find it now.

Two numbers worth agreeing on

Talk through these with whoever runs your IT:

  • RPO (Recovery Point Objective): how much data can you afford to lose? If backups run nightly, a bad day could cost you up to a day’s work. Is that acceptable, or do you need more frequent snapshots?
  • RTO (Recovery Time Objective): how quickly do you need to be back up and running? This drives how your backups are designed.

You don’t need the jargon, but you do need the answers, because they define what “good enough” means for your business.

A quick self-check

  • Where exactly are our backups, and is at least one copy isolated from our network?
  • When did we last restore from them successfully, not just confirm they ran?
  • If our main system vanished tomorrow, who does what, and how long until we’re trading again?

If any of those makes you uneasy, that’s the signal to act before you need it.


We can review your backups, set up a properly isolated copy, and run a real restore test so you know, not hope, you’re covered. Talk to us about making your recovery bulletproof.

Want help putting this into practice?

Book a free, no-obligation consult and we'll talk through your situation.

Get in touch