Nathan Whittacre Check availability

Why your backup probably won't work

Draft copy — unfinished

How do I know if our backups will actually work?

Assume the backup is fine and the restore is not. The failure you will meet is a restore that runs too slowly to matter, or one that recovers files while leaving the system that used them unbuildable. Pick your most important system, restore it against a clock, and record the time.

The backup is the easy half. Backup software runs, reports success, and the report is usually true. What it does not tell you is whether the thing it produced can put a thirty-person company back to work on a Tuesday morning with customers already calling.

If a restore is not tested, it is a wish, not a plan.

Three failures are worth testing for by name.

The restore finishes, too late to matter

Recovery has a deadline set by your business, not by your vendor. A restore that takes four days is a different product from one that takes four hours, and the contract you signed probably describes neither. The number you need is how long your most important system takes to come back with someone actually doing the work, on the connection you actually have.

The files come back and the system does not

File-level backups recover documents. They do not always recover the configuration, licensing, and integrations that made those documents useful. The gap shows up when the application is reinstalled and nobody can find who held the administrator credentials.

The backup contains the problem

If an attacker had access for three weeks, so did your backups. Restoring the most recent copy restores their access with it. Recovery therefore has to include a decision about how far back to go, and someone has to be authorized to make that call at 6am.

What to do this quarter

  1. Pick the one system whose loss would stop revenue. Not the most technically interesting one.
  2. Restore it somewhere isolated, with a clock running, and stop when someone can do real work in it.
  3. Write down the elapsed time, who did it, and what was missing. That document is your recovery plan; everything before it was a purchase.
  4. Put the next test on the calendar before the current one has cooled off.

[EXAMPLE NEEDED: one restore that hit its time target and one that missed badly, with the systems named and the reason for the gap]

The cost of this is real and worth naming: a day of somebody’s attention, and a conversation you will not enjoy if the number comes back bad. You will get the number either way. The choice is whether you get it on a Tuesday you picked or one you didn’t.

From Nathan

Not published yet · NEEDS_NATHAN #9

This article is missing the only part an agent cannot write

personal_note is still PENDING_NATHAN — a client story, a specific observation, or a first-person judgment. Brief §9 makes it required and blocks merge while it says PENDING_NATHAN. The article does not publish until Nathan writes this.

Related talk

What to spend your one budget cycle on

CEOs, boards, and owners of companies that carry real technology risk and have no full-time technology staff to hand it to

Check availability