RESOURCE / EN

Backup restore test worksheet

A restore drill worksheet for the system, restore point, isolated location, timing, integrity, dependencies, result, and owner.

This worksheet accompanies A backup ransomware cannot delete. Keep the drill safe for production: do not restore test data over a live system.

Test scope

Start date and time (with timezone):
Test owner:
Person accepting the result:
Selected system / service:
Data in scope:
Restore point (date, version, backup identifier):
Backup source and identifier of the technical account used (never record passwords, tokens, or keys):
Isolated test location (VM, VLAN, host, directory):

The test location should not publish an old service into production DNS, send real email, or connect automatically to production integrations.

Before starting

  • the correct restore point has been confirmed
  • the test location is separated from production
  • the restore tool and procedure versions are recorded
  • someone has authority to stop the test
  • success is defined — what exactly must open or run

Timing

Stage Start End Duration Notes
retrieve backup
restore data
start service
verify

Total time to a usable result:
Within the internal target? yes / no / no target defined
Maximum acceptable data loss:
Does the age of the restored data meet this target? yes / no / no target defined

The duration measured in one drill does not guarantee the same recovery time during an outage.

Integrity and usability

  • the archive or medium was read without errors
  • the checksum matches a trusted value recorded before the test, or the tool’s verification completed successfully
  • expected directories, records, or objects exist
  • sampled files open and contain the expected data
  • permissions, ownership, and timestamps are appropriate for the scope
  • the application or service passes the agreed functional check

Sample / query / scenario checked:
Evidence (log, hash, screenshot, ticket number):

Missing dependencies

Dependency Available? Effect if missing Owner / next step
encryption key / secret
account and permissions
system / application version
database / queue / DNS
runbook and contact

Result

Outcome: pass / pass with limitations / fail / stopped
What was actually restored:
What could not be confirmed:
Errors and their safe handling:
Remediation owner:
Next-step deadline:
Next test date:

After the test, remove or protect restored data according to its sensitivity. If the drill reveals an incident or an integrity breach, preserve the facts and follow the response procedure; the exercise can be developed in the incident response lab.

Want this implemented or scoped?

The resource stays open. The form is for implementation, not an email gate.

The inquiry is stored on the server. You will get a short confirmation from hello@tomek.st. The operator is also notified on Telegram and email.