Backup dashboards usually show green checkmarks. Jobs completed, storage consumed, no errors. It is easy to conclude that everything is fine. But a successful backup job proves only that data was copied. It does not prove that you can get the right data back, in a usable state, quickly enough to matter.
Restore testing is how you find out. Many firms never do it, because it feels like extra work when nothing is wrong. The best time to find a backup problem is during a scheduled test, not during a ransomware incident.
What can go wrong
Consider a few ways a backup can look healthy and fail anyway.
- A key database or application was never included in the backup set.
- Backup files are corrupt or incomplete.
- The encryption key or password needed to open the backup is lost or stored only on the server that failed.
- The backup restores, but the application does not start because of a missing component.
- The restore works, but takes days instead of hours, because of limited bandwidth.
- Retention was configured shorter than anyone realized, so the version you need is gone.
None of these show up in a "job completed" message.
Three levels of testing
Level 1: File-level restores
Choose a handful of files and folders at random, including some from older dates, and restore them to an alternate location. Open them and confirm they are readable and complete. Do this monthly. It is quick and catches basic problems.
Level 2: System and application restores
Restore a full server, a virtual machine or a key application, such as your document management database or accounting system, into an isolated test environment. Confirm it boots, the application runs and the data looks right. Do this at least quarterly for your most important systems, or twice a year if resources are tight.
Level 3: Full disaster recovery exercise
Simulate the loss of your environment. Practice rebuilding critical systems from backups in a clean location, ideally the way you would after a ransomware attack, and measure how long it takes. Do this at least once a year. Include the humans: who calls whom, who has the credentials, where the documentation lives.
What to measure
Two concepts help frame expectations.
- Recovery time objective: how long you can be down before the damage becomes unacceptable.
- Recovery point objective: how much recent data loss you can tolerate.
Compare test results against those targets. If your partners believe the firm can be back in four hours but the test shows two days, that gap is the most valuable finding of the exercise.
Test the pieces people forget
- Credentials and keys. Confirm you can get into the backup system if the main directory is gone. Store recovery credentials and encryption keys offline, in a place several authorized people can reach.
- Documentation. Is there a current network diagram and a prioritized recovery order?
- Cloud data. Test restoring Microsoft 365 mailboxes and files, if you have a separate backup for them.
- Immutability. Verify that backup copies cannot be altered or deleted with ordinary admin credentials.
Record the results
Keep a simple log with the date, what was restored, who performed the test, how long it took, problems found and fixes made. Insurance applications and client security questionnaires often ask whether you test backups. A dated log is a clear answer.
Who should be involved
Include IT, the firm administrator and at least one attorney who can confirm that restored data is useful. Technical success does not always mean business success. A lawyer who opens a restored matter folder and says "this is current and complete" is a better test than a log message.
Common objections
"We do not have time." A file-level test takes minutes. Start there.
"We might break something." That is why you restore to a separate location.
"Our provider handles it." Ask your provider for the test log. If none exists, ask for one to be scheduled.
A simple annual calendar
- Monthly: file-level restores.
- Quarterly: one application or server restore.
- Annually: full disaster recovery exercise and review of recovery targets.
- After any major change: confirm new systems are covered by backup.
Getting support
Counsel Cyber builds restore testing into its backup and disaster recovery services for law firms, with written results you can share with partners, insurers and clients. If you do not know when your last test occurred, we can help you run one.