Resilience

Can your backups actually restore the business?

A recovery test for small businesses that separates sync, retention, backup and operational recovery.

First response

A successful backup job is not proof of recoverability. The useful test is whether authorised people can restore selected data and a critical process within an agreed time, from a clean recovery point, while the normal environment is unavailable or untrusted.

Work through it in this order

  1. 01

    Identify minimum viable operations

    List the services, data, suppliers and people needed to operate for the first day, first week and normal recovery.

  2. 02

    Map protection

    For each critical item, record source, copy, frequency, retention, administrator, deletion controls and location.

  3. 03

    Choose realistic restore cases

    Include a common user error, a deleted account, a damaged shared dataset and at least one system or configuration dependency.

  4. 04

    Run a clean test

    Use an isolated or controlled destination, capture times and errors, and confirm the restored information is usable by the business owner.

  5. 05

    Close the gaps

    Update procedures, access, retention, monitoring and recovery objectives. Schedule the next test and retain the evidence.

  6. 06

    Rehearse an administrator outage

    Confirm that an authorised alternative can reach the recovery service, obtain required approvals and follow the runbook when the usual administrator is unavailable.

From day-to-day administration

Details worth settling early

Test a process, not just a file

A useful exercise restores something a person deleted and something the business needs to operate. That second test may involve an account, application configuration, shared data and the order in which services return.

Separate recovery administration

If the same everyday administrator can change production, delete backups and alter retention, one compromised account can remove both the service and its recovery path.

Keep these points in view

  • Define recovery objectives in business terms before comparing products.
  • Protect backup administration separately so a compromised everyday account cannot erase recovery copies.
  • Test files, identities, configuration, applications and the order in which the business must recover—not only one document.

Before closing the issue

  • Critical services ranked
  • Recovery objectives approved
  • Backup administrators separated
  • Clean restore completed
  • Business owner validated data
  • Recovery times recorded
  • Next test scheduled

Easy mistakes under pressure

  • Calling file synchronisation a complete backup strategy
  • Keeping all copies under the same administrator or deletion path
  • Testing restoration without testing whether the business process can resume

Official guidance to keep nearby

  1. Australian Signals Directorate, Australian Cyber Security Centre — Small business cyber security guide
  2. Australian Signals Directorate, Australian Cyber Security Centre — Backups
  3. Australian Signals Directorate, Australian Cyber Security Centre — Essential Eight explained

Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.

A practical next step

Apply the guidance to the real environment.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.