All insights

How often should you test your backups?

2 min readBy Brendon Whiting, Founder · 6 February 2026

Spot-check monthly that jobs are completing and the data is where it should be, restore something real every quarter and time it, and run a full test at least annually including the systems everything else depends on. Also test after any significant change, because a backup configured for last year's estate quietly stops covering this one.

The reason the cadence matters is that backups fail silently, and almost always in the same way: not with an error, but with a scope that no longer matches reality. A new server is added and never included. A database moves and the job keeps backing up an empty folder. A retention setting is changed to save space and quietly discards the history you were relying on. Every one of those produces green dashboards for months, which is why a job report is a statement about software and a restore is a statement about your business.

Scale the effort to the tier. The monthly check is minutes: are jobs completing, is the data volume roughly what you would expect, has anything new appeared that is not covered. The quarterly test is the one that earns its keep, and it should be a real restore of something that matters, timed, with a person who uses that system confirming the result is usable rather than merely present. The annual test is the closest thing to the real event: a critical system brought back in dependency order, with the clock running against your recovery target.

Two things make this stick. Write down the date, the duration and who verified it, because that log is the evidence an insurer, a tender panel or an Essential Eight assessment will actually ask for, and reconstructing it later is impossible. And put it on someone's calendar with a name attached, since testing that happens when someone remembers is testing that happens after the incident. If you cannot say when your last real restore was, that is this week's job: 1800 456 567.

When was your last real restore?

If nobody can answer that, it is the gap worth closing this week. We test restores on a schedule and give you the log as evidence.

Frequently asked questions

No, and the gap between the two is where businesses get hurt. A job report says data was written; it says nothing about whether the data is complete, readable, or restorable into a working system. Plenty of green dashboards sit on top of backups that cannot be restored, and the report is exactly what stops anyone checking.

Restoring real data to a usable state, timing it, and having someone who uses the system confirm it is right. Bringing a database back is not the same as the application working with it. Record the date, the duration and who verified it, because that log is your evidence for insurers, tender panels and the Essential Eight.

Your provider should run it and you should see the result, dated. If testing is included, ask for the last three logs; if the answer is vague, you have learned what you needed. The important thing is that somebody is accountable on a schedule, rather than testing happening when someone remembers.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.