Is Backup Enough?
The phrase we have backups looks convincing.
Files are duplicated onto a different server, data is steadily archived, and automated yearly backups might operate every night. On paper, everything looks fine.
But there is another question that also matters:
Do those backups remain retrievable?
A backup that is unavailable during an incident is not much of a backup at all.
Backup and Restore Comparison
What is a backup? A backup is just a copy of your data kept in some other location.
Restore refers to accessing that copy, bringing it back, and making it usable.
That difference matters.
For example, a company might create daily backups of its customer database. However, even if the server crashes and the backup file is corrupt, corrupted, or takes many hours to restore, the company still has a backup.
Kind of like having an emergency exit in the office.
It may be labelled as an "Exit, Emergency Exit" sign above the door, but none of that matters if no one has checked to see if it opens.
Why Recovery Testing Matters?
This is where it mainly involves recovery testing.
Rather than taking it for granted that backups work, periodically a company will restore one in a testing environment.
They check simple things:
Can the files be opened?
Is the data complete?
Is the data tested on data till October 2023 okay? You are tested on bringing the system back, and how long it takes to bring the system back.
Without testing, there is no real way to know if a backup will serve its function when it is required.
What Do RPO and RTO Mean?
You might be familiar with RPO and RTO in your backup planning; both are frequently used terms.
Speaking of RPO, it is the Recovery Point Objective; how much data a company can afford to lose.
When backups are created once every 24 hours, nearly a day's worth of new data can be lost when something goes wrong just before the next backup.
That may be fine for one system and not at all something that can be accepted in another.
RTO refers to the time that the system must be up and running again.
This is a perfectly good backup solution, but if it takes two days to restore it can still be a significant business problem.
Therefore, the question is not if the backup exists at all. But how fast the business can rebound from it.
Ransomware Can Target Backups Too
Before initiating it, attackers may also attempt to delete or encrypt backups.
This is the reason organisations have started using immutable backups.
In fact, an immutable backup simply means that it cannot be deleted or edited during a defined period of time.
This means that even when an attacker gets administrator access, he will not be able to remove every recovery copy.
But the true test comes after you recover
Both are good backups, and there is a second part that both systems depend on; as you know, backups are only realised.
Their true worth comes on display when something goes wrong.
A company should determine if it has full backups, whether a backup can be restored, and the time to recover.
So instead of asking:
“Do we have a backup?”
A better question is:
Asking the question “Will we really be able to recover from this if our system were to stop working?
Disclaimer
This article is for informational purposes only; it does not constitute legal, technical, business, or security-related advice.