Insights › Backups & Ransomware

Testing Your Backups: A 30-Minute Quarterly Drill

Conceptual illustration of a backup drive with a verification checkmark being restored on a navy background.

Most Australian businesses back up their data. Far fewer have ever watched that data come back. That gap matters, because a backup you have never restored is not a safety net. It is a hope. The only way to know your backups work is to restore from them on a normal day, before an incident forces you to find out the hard way.

The good news is that proving your backups work does not need a big project or an expensive consultant. A focused 30-minute drill, run once a quarter, will tell you whether your business could actually recover. This guide walks through exactly what to do, what to look for, and why the Australian Cyber Security Centre treats restore testing as a core part of the Essential Eight.

Why an untested backup is just a hope

Backups fail quietly. A scheduled job stops running after a software update and nobody notices. A new folder of important files sits outside the backup scope. Cloud sync gets mistaken for a real backup. A drive fills up and the last three months never copied across. In every one of these cases the dashboard can still show a reassuring green tick, right up until the day you try to restore and discover there is nothing usable there.

This is why the ACSC Essential Eight does not simply ask you to take backups. Its Regular Backups strategy specifically requires that restoration of data, applications and settings from backups is tested as part of disaster recovery exercises. In other words, the framework treats an unproven backup as an incomplete control. Taking the backup is only half the job. Confirming you can bring it back is the other half.

Ransomware makes this even more urgent. Modern attackers hunt for backups and try to encrypt or delete them before they lock your live systems, precisely because a working backup is what lets you refuse to pay. If you have not tested your restore process, you are gambling that it will work on the worst day of your business year. Our guide to the 3-2-1 backup rule covers how to structure backups so at least one copy stays out of an attacker’s reach.

What a good restore test actually proves

A restore test answers three questions that a backup report cannot. First, can the data be recovered at all, and does it open without errors or corruption? Second, how long does recovery take? That is your recovery time objective, the realistic gap between an incident and being back at work. Third, how much data would you lose? That is your recovery point objective, the gap between your last good backup and the moment things went wrong. A nightly backup means you could lose up to a day of work. If that is too much for your business, the drill is how you find out before it costs you.

The ACSC also expects backups to be synchronised so you can restore to a single, consistent point in time, and to be retained in line with your business continuity needs. A drill is where those requirements stop being paperwork and become something you have seen with your own eyes.

The 30-minute quarterly drill, step by step

You do not need to restore everything. The aim is a representative sample that would expose a real problem. Pick one important file share, one key application or database, and one staff mailbox or account. Then work through these steps and write down what happens.

  1. Choose your targets. Before you start, agree on a handful of items that genuinely matter: a finance folder, your customer database, an email account, or your accounting file. Note the date and time so you know which backup you are testing.
  2. Restore to a safe location. Recover the sample to a separate folder, a test machine or an isolated area, never over the top of live data. You are proving recovery works, not risking your production files.
  3. Open and check the files. Do not just confirm they exist. Open the documents, run a report from the database, and read a few of the restored emails. Look for corruption, missing attachments, blank files or password locks you cannot clear.
  4. Time the whole thing. Note how long the restore took from start to usable data. Multiply sensibly in your head for a full recovery, and ask whether that number is one your business could survive.
  5. Test one thing you have never tested. Each quarter, rotate in something new: a laptop rebuild, a cloud app export, or a system setting. Over a year you will have exercised most of what matters.
  6. Write down the result. One short note is enough: what you restored, how long it took, what worked, and anything that failed or surprised you. This record is your evidence and your to-do list.

Thirty minutes is realistic for a small business testing a sample. Larger environments may need longer, but the principle holds: test a slice regularly rather than promising yourself a giant test that never happens.

Look beyond the files themselves

Recovering documents is the obvious part. The parts businesses forget are the ones that turn a quick recovery into a week of pain. When you run your drill, spend a moment on the wider picture too.

Ask who is actually able to perform a restore. If only one person knows the process and holds the credentials, your recovery plan has a single point of failure. Check that the account used to reach your backups is protected and separate from everyday logins, so that a compromised staff account cannot quietly wipe your last line of defence. Confirm where your offline or immutable copy lives and that you could reach it if your main systems were down. A common trap is assuming that cloud services already handle this. They often do not, which is why Microsoft 365 is not a backup on its own and needs a separate, tested copy behind it.

Common reasons a restore fails

When drills go wrong, the causes are usually mundane and fixable. Watching for them means you can close the gap while it is cheap to fix rather than during a live crisis.

Every one of these is far easier to deal with on a quiet Tuesday than in the middle of an incident. If the worst does happen, a tested backup is what lets you follow a calm plan instead of panicking. Our walkthrough of ransomware response in the first 24 hours shows just how much smoother recovery is when you already know your backups work.

Make it a habit, not a heroic effort

The businesses that recover well are rarely the ones with the biggest budgets. They are the ones that made testing routine. Put a recurring 30-minute appointment in the calendar for the same week each quarter, give it to a named person, and keep a simple running log of each drill and its result. That log becomes valuable in its own right: it is proof for insurers, auditors and clients that your backups are more than a checkbox, and it aligns neatly with the disaster recovery testing the Essential Eight asks for.

Treat anything that fails a drill as a small, specific task rather than a disaster. Fix the broken job, widen the backup scope, add a second person to the recovery process, or move a copy offline. Quarter by quarter, your recovery gets faster and your confidence stops being a guess and starts being something you have actually seen.

Related reading: restore testing is one part of being ready. See our guide to backups and ransomware recovery for the full approach, and the complete guide to cyber security for small business in Australia.

Find out where you stand

Restore testing is one piece of a bigger picture. If you are not sure how your business measures up across backups, ransomware readiness and the rest of the Essential Eight, our free self-assessment is a fast way to find out. Answer 27 short questions and you will get a personalised PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2, with clear next steps for your business. It takes about 5 to 10 minutes and the report is instant.

Take the free SecurityScore self-assessment and see exactly where your backups, and your wider security, stand today.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading