Resilience
Can your backups actually restore the business?
A recovery test for small businesses that separates sync, retention, backup and operational recovery.
First response
A successful backup job is not proof of recoverability. The useful test is whether authorised people can restore selected data and a critical process within an agreed time, from a clean recovery point, while the normal environment is unavailable or untrusted.
Work through it in this order
- 01
Identify minimum viable operations
List the services, data, suppliers and people needed to operate for the first day, first week and normal recovery.
- 02
Map protection
For each critical item, record source, copy, frequency, retention, administrator, deletion controls and location.
- 03
Choose realistic restore cases
Include a common user error, a deleted account, a damaged shared dataset and at least one system or configuration dependency.
- 04
Run a clean test
Use an isolated or controlled destination, capture times and errors, and confirm the restored information is usable by the business owner.
- 05
Close the gaps
Update procedures, access, retention, monitoring and recovery objectives. Schedule the next test and retain the evidence.
- 06
Rehearse an administrator outage
Confirm that an authorised alternative can reach the recovery service, obtain required approvals and follow the runbook when the usual administrator is unavailable.
From day-to-day administration
Details worth settling early
Test a process, not just a file
A useful exercise restores something a person deleted and something the business needs to operate. That second test may involve an account, application configuration, shared data and the order in which services return.
Separate recovery administration
If the same everyday administrator can change production, delete backups and alter retention, one compromised account can remove both the service and its recovery path.
Keep these points in view
- Define recovery objectives in business terms before comparing products.
- Protect backup administration separately so a compromised everyday account cannot erase recovery copies.
- Test files, identities, configuration, applications and the order in which the business must recover—not only one document.
Before closing the issue
- Critical services ranked
- Recovery objectives approved
- Backup administrators separated
- Clean restore completed
- Business owner validated data
- Recovery times recorded
- Next test scheduled
Easy mistakes under pressure
- Calling file synchronisation a complete backup strategy
- Keeping all copies under the same administrator or deletion path
- Testing restoration without testing whether the business process can resume
Official guidance to keep nearby
- Australian Signals Directorate, Australian Cyber Security Centre — Small business cyber security guide
- Australian Signals Directorate, Australian Cyber Security Centre — Backups
- Australian Signals Directorate, Australian Cyber Security Centre — Essential Eight explained
Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.