Almost every company I sit down with has backups. There's a dashboard with green checkmarks, a cloud provider, a retention policy someone set up years ago. If you ask the leadership team whether the company's data is protected, the answer is an instant yes.

Then I ask the follow-up question: when was the last time you actually restored something?

That's usually when the room gets quiet.

A green checkmark is not proof

A backup job completing successfully means the software copied files from point A to point B on schedule. That's it. It does not mean the data is complete, that the application can boot from it, or that anyone on your team knows how to put it back together under pressure.

I have seen companies discover this at the worst possible moment. A ransomware event hits on a Friday. The MSP pulls up the backup dashboard, everything looks fine, and then the restore takes eleven hours instead of two. Or the database comes back but won't mount. Or the backup turns out to be three weeks old because a job silently failed and the alert went to an inbox nobody monitors.

The failure wasn't in the backup product. It was in the assumption that backups equal recovery. They don't. Backups are a hope. Recovery is a skill.

What a real restore test looks like

You don't need to shut the company down to test this. A real restore test has three parts, and you can run one this quarter.

First, pick a system that matters. Not the printer share. Pick the file server, the accounting database, the CRM. The thing that would stop work if it vanished.

Second, restore it to an isolated environment and have the actual users verify it. Not your IT guy clicking around for five minutes. Have accounting log in and run a report. Have sales pull up a customer record. If the data loads and the application works, you've got something real.

Third, write down how long it took, who did what, and what broke. That document is your real disaster recovery plan. Everything else is theory.

Do this twice a year and rotate the system each time. That's enough to keep the skill current without turning it into a science project.

The questions to ask this week

You don't have to wait for the next test cycle to learn where you stand. Ask your IT team or your MSP three questions, and don't accept hand-waving for answers.

One: when did we last perform a full restore test, and what were the results? Two: how long would it take to restore our most critical system from scratch, in hours, not adjectives? Three: who on our team knows how to do it if our primary person is unavailable?

If any of those answers is "we're not sure," you don't have a backup strategy. You have a backup bill.

This is one of those areas where a little executive attention goes a long way. Backups are boring. Nobody gets excited about them. But the companies that survive a real data event are the ones whose leaders treated recovery as a business function, not an IT checkbox.

The green dashboard will tell you everything is fine right up until the moment it isn't. Don't find out which one you are on the worst day of your year.


Not sure where your IT really stands? Start with a Clarity Audit: a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.


About the author: Chris McGlasson is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.