Test your business backups by actually restoring data, not by checking that the backup job says “successful.” At least quarterly, restore a sample of files, a full server or virtual machine and a Microsoft 365 mailbox to a safe location, time how long it takes and confirm the data opens. Keep one copy offline or immutable.

Almost every organization we talk with around Dallas-Fort Worth has backups. Far fewer know how long a full restore would take, whether last night’s job captured the right data or what happens if the backup server gets encrypted along with everything else. A backup you’ve never restored is a hope, not a plan. This guide walks through what to test, how often and what a good result looks like, in plain English.

Why isn’t a successful backup job enough?

A green checkmark means the software copied something somewhere. It doesn’t tell you whether the copy is complete, whether it can be read, whether it includes the database that changed folders last spring or whether you can bring it back fast enough to keep the business running. Those answers only come from restoring.

The numbers from 2025 make the point. In Veeam’s 2025 Ransomware Trends Report, a survey of 1,300 organizations, only 10% of ransomware victims recovered more than 90% of their data, and 57% recovered less than half. The same report found that 98% had a ransomware playbook, but only 44% of those playbooks included backup verification. Sophos’s State of Ransomware in the US 2025 found that just 43% of US organizations whose data was encrypted used backups to recover it, down from 61% the year before.

Truthfully, most backup failures aren’t dramatic. They’re quiet. A job that skipped a locked file for six months. A retention setting that kept two weeks when you needed ninety days. A password to the backup console that left with a former employee. Testing is how you find those before they find you.

What should a business backup strategy include?

The long-standing guideline is the 3-2-1 rule: three copies of your data, on two different types of storage, with one copy offsite. Many backup vendors now extend it to 3-2-1-1-0, adding one copy that is offline, air-gapped or immutable (it can’t be changed or deleted, even by an administrator) and zero errors after verification.

CISA’s #StopRansomware Guide puts it directly. It recommends maintaining offline, encrypted backups of critical data and regularly testing their availability and integrity in a disaster recovery scenario. It also explains why the offline copy matters: many ransomware variants go looking for accessible backups to delete or encrypt them.

Backups are also Control 11 in the CIS Critical Security Controls. If you’re working toward CIS Implementation Group 1, or toward Texas’s cybersecurity safe harbor for businesses with 20 to 99 employees, tested backups are part of the bar. Our guide to the CIS Controls for small businesses explains how that fits together.

How do you test business backups?

Good testing is a routine, not an event. Here’s a practical approach for an organization of 20 to 150 people.

1. Start with a recovery goal for each system

Before testing anything, decide two numbers with leadership. Recovery time objective (RTO) is how long a system can be down before it seriously hurts the business. Recovery point objective (RPO) is how much data you can afford to lose, measured in time. Accounting during month-end close may need a four-hour RTO. An archive share might be fine at three days. Without these numbers, you can’t tell whether a test passed.

2. Restore individual files

Pick a handful of files from different locations and dates, including something from the oldest restore point you keep. Restore them to an alternate folder and open them. This is the quickest test and catches missing folders and retention problems.

3. Restore a full server or virtual machine

Spin up a critical server in an isolated environment, such as a sandbox or a separate network segment, so it doesn’t conflict with production. Confirm it boots, the application starts and someone who uses it every day can log in and see current data. Time it from start to finish.

4. Restore cloud data, including Microsoft 365

Microsoft keeps its services running, but protecting your data from deletion, ransomware and account compromise is still your job. Built-in recycle bins and retention help with small mistakes, but they aren’t an independent backup, which is why Microsoft offers a separate Microsoft 365 Backup service alongside third-party options. Test restoring a mailbox, a OneDrive folder and a SharePoint or Teams site. If you’re comparing licensing options at the same time, see our post on Business Premium vs Standard.

5. Check the offline or immutable copy

Confirm the copy that’s supposed to be out of an attacker’s reach actually is. Can a domain administrator delete it? Is the cloud storage locked for the full retention period? Pull a restore from that copy too.

6. Write down the results

Record what you restored, how long it took, whether it met the RTO and RPO and what broke. That record is what your cyber insurer, auditor or board will ask for. It’s also what makes the next test faster.

How often should you test backups?

Test Suggested frequency
Review backup job reports and alerts Daily or every business day
Restore sample files and folders Monthly
Restore a full critical server or VM Quarterly
Restore Microsoft 365 mailbox and site data Quarterly
Full disaster recovery exercise with leadership At least annually

Also test after any big change, such as a server migration, a new line-of-business application or a switch in backup vendors. Changes are when backups quietly stop covering what they used to.

What does a full disaster recovery exercise look like?

Once a year, walk leadership through a realistic scenario. Ransomware on a Monday morning works well because it tests backups and decisions at the same time. Who declares an incident? Who calls the cyber insurer and outside counsel? Which systems come back first, and in what order? Can people work while that happens?

That exercise ties directly to your incident response plan. Our guide to the first 72 hours after a cyberattack covers the steps that happen alongside recovery, including isolating systems, preserving evidence and Texas breach notification deadlines.

What are the most common backup testing mistakes?

  • Testing only file restores. Files are easy. Rebuilding a whole server, domain controller or accounting system is what takes days.
  • Restoring over production. Always restore to an isolated location so a test can’t overwrite live data.
  • Keeping backups on the same network credentials. If the account that runs the business can also delete the backups, so can an attacker who steals it.
  • Forgetting SaaS and cloud apps. Microsoft 365, line-of-business cloud apps and even phone system settings all hold data you’d miss.
  • Not timing the restore. Leadership usually assumes hours. Without a stopwatch, nobody knows whether it’s really days.

Frequently asked questions

How often should a small business test its backups?

Restore sample files monthly and a full critical server or Microsoft 365 data quarterly. Run a full disaster recovery exercise with leadership at least once a year and after any major system change.

What is the 3-2-1 backup rule?

Keep three copies of your data on two different types of storage, with one copy offsite. Many organizations now add one offline or immutable copy and zero errors after verification, known as 3-2-1-1-0.

Does Microsoft back up my Microsoft 365 data?

Microsoft keeps the service running and offers recycle bins and retention settings, but those aren’t an independent backup. Microsoft sells a separate Microsoft 365 Backup service, and third-party tools are also common. A separate backup protects against deletion, ransomware and account compromise.

What is an immutable backup?

An immutable backup can’t be changed or deleted for a set retention period, even by an administrator. That protects it from ransomware and from attackers who steal admin credentials.

What is the difference between RTO and RPO?

Recovery time objective (RTO) is how long a system can be down. Recovery point objective (RPO) is how much data, measured in time, you can afford to lose. Both should be set for each critical system.

How The Fulcrum Group helps

We help North Texas organizations build backups they can actually count on. Through SPOT Protect backup and disaster recovery and SPOT Managed IT Services, that means setting recovery goals with leadership, protecting servers and Microsoft 365, keeping an immutable copy out of reach, running scheduled restore tests and documenting the results for your insurer. Cities, utilities and water districts can learn more on our local government page.

If you’d like to know whether your backups would hold up on a bad Monday, Schedule a Discovery Call.