A Green Light Every Night Means Nothing If the Restore Fails
Published on 10/02/2026 at 20:01 | Editorial boerse-global.deThe gap between a completed backup and a recoverable one
Backup dashboards across small and mid-sized companies tend to look reassuring: a fresh success message appears every night, logs fill up, and nothing seems wrong. What those logs actually prove is narrow. They confirm that data was written — not that it can still be read weeks or months later, and certainly not that it can be brought back at all.
Data recovery firm Data Reverse surveyed 285 small and mid-sized businesses in the first quarter of 2025 and found that contradiction in plain numbers. While 77 percent of those polled produce a backup at least once a week, 72 percent rarely or never check whether that data can actually be restored.
Storage setups can deepen the false sense of security. With RAID 5, for instance, a single failed drive leaves no further reserve — and the warning messages that should trigger action often land in email inboxes nobody monitors.
What the BSI's baseline actually demands
Germany's Federal Office for Information Security (BSI) spells out the requirement in its IT-Grundschutz Compendium, in module CON.3, "Data Backup Concept" (Edition 2023). Requirement CON.3.A15 states that organisations must test at regular intervals whether backups work as intended — with particular attention to whether stored data can be restored cleanly and within a reasonable timeframe.
Time is where theory collides with reality. A backup that takes four days to reconstruct financial records is useless to a business that would face an existential crisis after just one day of downtime.
Documentation adds a second, organisational trap. If the recovery instructions exist only in digital form on the very systems that are affected, they may be unreachable in a major incident such as a ransomware attack.
What a workable routine looks like
Data Reverse recommends running full restore tests at least once a quarter, on separate hardware, with the time required measured precisely.
Guidance on server migration for mid-sized companies points in the same direction: test backups in advance, define clear recovery objectives, and only move to production after testing with typical user roles. A binding rollback plan — with a fixed point in time and a data reconciliation step — belongs in the package as well.
If a restore attempt fails midway, experts advise a structured response rather than improvisation. Network-attached storage (NAS) should be shut down in a controlled manner, and the drives clearly labelled.
Do-it-yourself rebuilds and drive swaps should be avoided, as should any repair attempts on the production system. Instead, preserve the job logs and pause media rotation for the time being, so the state of the data is not put at further risk.
