Offer · IT Services & Advisory

Backup and recovery verification

You know the backup job is green. But do you know the business can actually be recovered?

ReviewRPO and RTORestore testRansomware readinessAction plan

Who it is for and when

A successful backup is not the same thing as a working recovery capability. That only shows when the information is genuinely needed.

Backup and recovery verification is a defined engagement for organisations that want an independent, practical answer to what you protect today, what is missing, how quickly you can recover — and whether you have actually tested it.

NCSC recommends that organisations not only take backups but also test restoring them. Their current recommendation is to test at least annually or after major changes to the IT environment, and that both partial and full restores should be tried.

The offer suits situations such as when:

  • the backup has been in place for years but has never been properly tested,
  • a new IT environment or Microsoft 365 has been introduced,
  • the organisation wants to verify its RPO and RTO,
  • the backup platform is to be replaced,
  • ransomware readiness is to be strengthened,
  • an audit, a customer requirement or regulation calls for better evidence,
  • the continuity plan rests on assumptions about recovery,
  • a supplier runs the backup but you want to check the result,
  • the business is unsure which systems and configurations are actually covered.

What we do

  1. Preparation. The systems, the requirements and the backup environment are mapped.
  2. Technical review. Configuration, coverage, protection and monitoring are reviewed.
  3. Restore test. The agreed test cases are carried out.
  4. Report and action plan. The result is compiled and prioritised.

What is included

Scoping the critical systems

We start by identifying which systems, services and information the verification is to cover. That can be, for example:

  • servers,
  • virtual machines,
  • databases,
  • file servers,
  • Microsoft 365,
  • system configuration,
  • critical network components,
  • applications.

Not every system needs reviewing to the same depth. We prioritise by business criticality.

RPO and RTO

We go through whether the organisation has defined requirements for RPO, meaning how much data may be lost, and RTO, meaning how quickly you need to be running again. The requirements are then compared with what the technical solution actually supports.

If the business requires recovery within four hours, it helps little that the backup can technically be restored in two days.

What the backup covers

We review what is actually backed up. NCSC recommends that the need is assessed for system documentation, logs, configuration settings, applications, operating systems, virtual machines and containers among others.

We also look at whether important dependencies are missing.

Protection of the backup environment itself

The backup is an attractive target in a ransomware attack. We therefore look at questions such as:

  • administrative permissions,
  • authentication,
  • separation from the production environment,
  • offline or otherwise protected copies,
  • immutability where relevant,
  • storage locations,
  • logging,
  • protection against modification.

NCSC recommends in particular that backups are kept in a way that protects them from unauthorised modification and from malicious code.

Monitoring and deviation handling

We check:

  • how failed backup jobs are detected,
  • who receives the alert,
  • how deviations are followed up,
  • how long a fault can sit before someone acts,
  • whether storage capacity and retention are monitored.

Controlled restore test

The most important part. We carry out one or more agreed restore tests. That can be, for example:

  • File level. Restore a specific file or set of information.
  • System level. Restore a chosen server, VM, database or application component in a controlled environment.
  • Microsoft 365. Restore selected data where your solution supports it.
  • Scenario. Test what it takes to recover an important service after a simulated larger outage.

The exact test is scoped in advance to avoid unwanted impact on production.

Dependencies

Recovery is rarely about one system at a time. We therefore review, for example:

  • identity,
  • DNS,
  • certificates,
  • licences,
  • the network,
  • databases,
  • integrations,
  • suppliers.

NCSC explicitly raises the need to understand system dependencies in backup and recovery.

What you get

The delivery can contain:

  • the documented scope,
  • an overview of the current backup solution,
  • a coverage analysis,
  • an assessment against RPO and RTO,
  • identified risks and gaps,
  • the restore tests carried out,
  • measured or observed recovery times,
  • a test record,
  • deviations,
  • a prioritised action plan,
  • a summary for management.

The result should be usable both by IT and as input to risk, continuity or audit work.

Scope and price

The offer is a review and a verification. A full DR test of the organisation’s entire IT environment is not included unless specifically agreed. Remediation and replacing the backup platform can be carried out as a next step.

The price varies with how many systems are included and how many restore tests are to be carried out. You get an estimated cost proposal and, where possible, a fixed price.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.

Frequently asked questions

Can you review a backup another supplier runs?

Yes. That is a common and sensible use case.

Do we have to test the whole IT environment?

No. The tests can be chosen on a risk basis and start with the most important systems.

Can Microsoft 365 be included?

Yes. Which parts can be tested depends on the backup solution and retention model you use. Microsoft today also has its own Microsoft 365 Backup service, covering Exchange, OneDrive and SharePoint among others.

Is this the same as a DR exercise?

No. Backup and recovery verification focuses on the recovery capability itself. A full DR exercise normally covers more technical and organisational parts.

Reviewed by Kristensson i Skåne AB. .

Sources: NCSC: back up and test restoring information · Microsoft Learn: Microsoft 365 Backup · CIS Controls

Do you know the backup can actually be restored?

Contact us