This worksheet accompanies A backup ransomware cannot delete. Keep the drill safe for production: do not restore test data over a live system.
Test scope
Start date and time (with timezone):
Test owner:
Person accepting the result:
Selected system / service:
Data in scope:
Restore point (date, version, backup identifier):
Backup source and identifier of the technical account used (never record passwords, tokens, or keys):
Isolated test location (VM, VLAN, host, directory):
The test location should not publish an old service into production DNS, send real email, or connect automatically to production integrations.
Before starting
- the correct restore point has been confirmed
- the test location is separated from production
- the restore tool and procedure versions are recorded
- someone has authority to stop the test
- success is defined — what exactly must open or run
Timing
| Stage | Start | End | Duration | Notes |
|---|---|---|---|---|
| retrieve backup | ||||
| restore data | ||||
| start service | ||||
| verify |
Total time to a usable result:
Within the internal target? yes / no / no target defined
Maximum acceptable data loss:
Does the age of the restored data meet this target? yes / no / no target defined
The duration measured in one drill does not guarantee the same recovery time during an outage.
Integrity and usability
- the archive or medium was read without errors
- the checksum matches a trusted value recorded before the test, or the tool’s verification completed successfully
- expected directories, records, or objects exist
- sampled files open and contain the expected data
- permissions, ownership, and timestamps are appropriate for the scope
- the application or service passes the agreed functional check
Sample / query / scenario checked:
Evidence (log, hash, screenshot, ticket number):
Missing dependencies
| Dependency | Available? | Effect if missing | Owner / next step |
|---|---|---|---|
| encryption key / secret | |||
| account and permissions | |||
| system / application version | |||
| database / queue / DNS | |||
| runbook and contact |
Result
Outcome: pass / pass with limitations / fail / stopped
What was actually restored:
What could not be confirmed:
Errors and their safe handling:
Remediation owner:
Next-step deadline:
Next test date:
After the test, remove or protect restored data according to its sensitivity. If the drill reveals an incident or an integrity breach, preserve the facts and follow the response procedure; the exercise can be developed in the incident response lab.