Your fire extinguishers get inspected. Your smoke alarms get tested. Somebody knows where the exits are because you walked it once. Nobody argues about this. It costs a little time, it feels slightly silly, and everyone does it anyway because the one time it matters, it really matters.
Now, when did anyone last actually restore a file from your backup? Not checked that the backup ran. Not looked at a dashboard full of green checkmarks. Actually pulled data out, opened it, and confirmed it was the right data from the right day. For most small businesses the honest answer is never, or once during setup three years ago. That gap between having backups and having proven restores is where a bad week turns into a business-ending month.
A Backup Is a Promise. A Restore Is Proof.
A backup job that reports success is telling you it finished. It is not telling you the data is complete, readable, current, or recoverable in a useful amount of time. Those are four separate questions, and the only way to answer them is to try.
The gap between confidence and reality is well documented. Veeam’s Data Trust and Resilience Report 2026, published in April 2026 and based on more than 900 senior IT, security, and risk leaders, found 90% of organizations are confident they can recover from a cyber incident. Only 28% of ransomware victims fully recovered their affected data, and another 44% recovered less than 75% of it. Nearly everyone believes they are covered. Fewer than a third actually were.
Veeam’s earlier 2025 Ransomware Trends report, covering 1,300 organizations, was more specific. 98% had a ransomware playbook. Only 44% of those playbooks included backup verification procedures. The plan existed. The step that proves the plan works was missing from more than half.
Why Untested Backups Fail
Backups do not usually fail loudly. They fail quietly, in ways that only become visible on the worst day of your year.
- Silent job failures. The backup stopped working in March. The alert email went to an employee who left in February, or to a spam folder nobody checks. Everything looks fine because nobody is looking.
- Incomplete coverage. The server is backed up. The accounting database a bookkeeper moved to a different folder is not. Neither is the laptop where your estimator keeps working files, or the cloud app your sales team started using without telling anyone.
- Encrypted along with everything else. If your backup drive is permanently plugged in and visible on the network, ransomware treats it as just another folder. Modern attacks look for backups first, on purpose. This is why an offline or immutable copy matters, and why CISA advises small businesses to keep one copy stored off-site, away from your business location.
- Nobody knows the restore steps. The software works. But the person who set it up is gone, the password was in their head, and the documentation was a sticky note. You have the data and no fast way to reach it.
- Technically possible, practically useless. Yes, you can recover. It will take eleven days over your current internet connection. If your business cannot survive eleven days of downtime, that backup did not solve your problem.
The One-Hour Quarterly Fire Drill
This does not need to be an all-day production. Put an hour on the calendar four times a year and work through the same list every time.
- Pick three real files from three different places. A document from a shared folder, something from your accounting system, and one email or file from a cloud service like Microsoft 365. Choose at random, not the ones you know are safe.
- Restore to a scratch location. Never restore over the live copy. Pull them into a temporary folder so nothing in production changes.
- Open every one. This is the step people skip. A file that restores but will not open is not a recovered file. Confirm the contents and the date.
- Restore something from a week ago, not yesterday. CISA specifically advises testing that you can roll data back at least seven days. Ransomware often sits quietly before it triggers, so yesterday’s backup may already be compromised. Depth matters as much as recency.
- Time it. Write down how long each restore took, then scale it up honestly to estimate a full recovery. That number is your real recovery time, and it is usually a surprise.
- Try one thing that is not a file. Once a year, restore an entire system in a test environment. File restores and full system recovery are different exercises, and only one saves you after a total loss.
Cloud data deserves attention here. Plenty of businesses assume Microsoft 365 or Google Workspace handles backup automatically. Those platforms are excellent at keeping the service running. They are not a substitute for your own retained copy of your own data. More on that assumption in The Cloud Can Go Down.
What to Write Down
An untested backup is a guess. An undocumented restore is a guess with extra steps. Keep a single page, updated quarterly, stored somewhere you can reach when your network is down. Printed and in a folder is not old-fashioned. It is correct.
- What is backed up and what is not. An explicit list of both. The “not” column saves you, because it forces the conversation about the laptop or cloud app nobody thought about.
- Where the copies live. Local device, off-site location, cloud provider. How many copies exist and how far back each one goes.
- The actual restore steps. Written so a competent person who has never done it could follow along, including where credentials live and who can reach them.
- Test results and dates. What you restored, how long it took, what broke, what you fixed. Four lines per quarter is plenty.
- Who to call. Your IT provider, your software vendors, your cyber insurance carrier, in order, with phone numbers.
More Than One Person Has to Be Able to Do This
In most small businesses, exactly one person understands the backups. Sometimes the owner, sometimes the one employee who is good with computers. Either way, that is a single point of failure sitting on top of your most important safety net.
Disasters have terrible timing. The server dies while your technical person is on a cruise. Ransomware hits the week your IT contact changes jobs. Veeam’s 2025 report found only 30% of organizations had a pre-defined chain of command for a ransomware event, meaning most figure out who is in charge while the building is metaphorically on fire.
The fix is simple. At least two people should have done a restore with their own hands, not watched someone else do it. Credentials belong in a shared password manager the owner can access, not in one person’s memory. And your IT provider should run these tests on a schedule and show you the results, not just say backups are running. That is a fair thing to ask when evaluating providers, and we covered what else to look for in Why More Businesses Are Outsourcing IT in 2026.
The Bottom Line
Having backups and being able to recover are two different things, and only one keeps your doors open. The good news: closing the gap is cheap. One hour, four times a year, three files, opened and verified, written down. That is the entire discipline.
You do not need a fancy plan or a big budget. You need to pull the fire alarm once in a while and find out what happens. Better to learn on a Tuesday afternoon in a scratch folder than at 6 a.m. on the day everything is encrypted.
If you are not sure when your backups were last tested, or whether anyone besides one person could restore them, that is worth an hour of attention. We help businesses across Denton County run these tests and document them properly. Contact us today.
Sources:

Comments are closed