01
Steps 1–3: know what you protect
Start with inventory and the business tolerance for disruption.
- 1. List critical systems, data and their owners
- 2. Define acceptable data loss (RPO) and recovery time (RTO)
- 3. Verify that backup policy actually covers critical data
02
Steps 4–5: verify backup resilience
Backups should survive both production failure and account compromise.
- 4. Review copy isolation, accounts and administrative access
- 5. Verify retention, job history and availability of required keys or credentials
03
Steps 6–7: perform a real recovery
Only a restore test turns an assumption into evidence.
- 6. Restore an agreed file, service or system into a safe target
- 7. Measure time, verify integrity and document the exact procedure and gaps found