Operations

When a restore log is not a restore test

Notebook with restore test observations beside printed job logs

Backup job screenshots appear in nearly every evidence folder we receive. Restore proof appears far less often — and that gap becomes a finding more often than teams expect.

Success messages answer a different question

A green backup job shows that a copy was taken. It does not show that the application can be recovered to a usable state, that credentials still work, or that the restore finishes inside the recovery window the business believes it has.

What a credible restore record includes

Date of the test, environment used, who performed it, which application version was restored, how completeness was checked, and how long it took. Photos of a login screen after restore help; a one-line email saying “all good” does not.

Schedule tests away from peak posting

Restoring during month-end is a poor habit. Pick a quieter window, document it, and keep the record with the application owner — not only with infrastructure staff.

During a full application control audit, we sample restore evidence specifically because it separates hopeful procedures from practised ones.