
Test backups and prepare a verified recovery
A backup is useful when it can recover a service and its data under known conditions. A successful-copy notification proves neither the integrity of the content nor that the application works after restoration. Prepare a bounded, documented exercise separate from production.
Photo: Markus Spiske / Unsplash · Context photograph; no affiliation with FDS is implied.
Define what needs to be restored
List essential services: website, database, media, documents, forms and messaging used to process enquiries. For each, identify who can validate the result and which dependencies it needs. Recovering a file is insufficient if reading it requires unavailable software or configuration.
Set two objectives specific to your activity: acceptable time to resume service and the amount of recent data you can afford to lose. Discuss these with the people using the service. They are neither market averages nor guarantees supplied by your hosting provider.
Distinguish synchronisation from backup
Synchronisation can propagate deletion or corruption. Check that the solution preserves recoverable versions and that copies do not all depend on the same account or device. Check data retained by external tools too: exporting it may require a separate action.
Document frequency and retention according to need. Protect access to copies and avoid arrangements where compromising an administrator allows deletion of both originals and every version. The protection design depends on the service; assess it with the technical owner.
Restore in an isolated environment
Choose a copy and a test destination that will not replace live data. First verify that outgoing messages, payments and automations can be disabled. A test restoration should not trigger real actions involving customers or partners.
Record the copy date, scope, required versions, operations and elapsed time. Verify that an authorised user can locate a document, navigate pages and complete a test journey. Check attachments and recent files rather than relying solely on the home page.
Define evidence of successful recovery
Compare the result against criteria established before the test: present data, readable files, correct permissions and working essential journeys. A test that exceeds its time target or misses a dependency reveals work to do even if some pages respond.
Write a report identifying gaps and owners. Retest corrected items. Keep the procedure somewhere accessible when the usual service is unavailable, with verified recovery contacts. Do not copy secrets into it; identify the authorised way to retrieve access.
Organise the recovery decision
Recovery following an incident must account for its cause and the system’s condition. Restoring onto compromised infrastructure may reintroduce the problem. The designated owner should authorise recovery in coordination with the necessary specialists.
Plan how to inform affected users, verify resumed service and process enquiries received during interruption. After the exercise or incident, update the procedure and objectives. Repeat testing when data structure, provider or application changes substantially.
A record to keep with the decision
| Item | Evidence |
|---|---|
| Scope | Services, data and dependencies to restore. |
| Objectives | Target time and acceptable data loss agreed with the activity owner. |
| Exercise | Chosen copy, isolated environment and test journeys. |
| Result | Duration, present data, gaps, corrections and acceptance decision. |
Frequently asked questions
My host already backs up the site: should I test?
Yes. Check contractual scope, retention, delays and recovery arrangements. Testing confirms what can actually be restored and what remains your responsibility.
Is the newest copy always the best?
It may contain the defect or deletion you are trying to correct. Identify a version suited to the incident and verify it in an isolated environment before recovery.
Reference material
Cybermalveillance.gouv.fr · Sauvegardes
The practical checklist is an editorial synthesis to adapt to your service. It does not constitute a certification or an audit result.