- SituationBackup platform in place · jobs reporting success · confidence high
- RiskUnproven RTO/RPO · retention that didn’t match reality · unclear ownership
- OutcomeTimed restores for critical systems · offsite verified · runbooks with owners
The situation
Backup is the classic silent failure domain: dashboards stay green while restore paths rot. Storage targets fill, credentials expire, application-aware options drift, and “we have backups” becomes a belief system rather than a measured practice.
This client was not careless. They had invested in tooling. What they lacked was the habit of proving recovery — and a clear answer to “who runs the restore when the building is on fire?”
What we did
- Inventory of protected systems vs. what the business actually considered critical
- Restore tests for priority workloads with clocks running and results written down
- Retention and capacity review so “kept for 90 days” matched what the media could hold
- Offsite / secondary path verification (not only the local repository looking healthy)
- Application and guest-level restore notes where image-level alone was not enough
- Runbooks, ownership, and a scheduled restore-test cadence — not a one-time hero weekend
Results
Critical systems had documented restore times leadership could quote. Gaps (missing jobs, wrong retention, unusable offsite copies) were fixed before an incident forced the lesson. Backup became something operations scheduled and reviewed, not something they hoped was fine.
Client identity is withheld by agreement. The pattern is one we repeat: a backup that has never been restored is not a recovery plan.
Related
See our Virtualization and Managed IT practices, or contact us if your jobs are green and your restores are theoretical.
Ready to talk through the next step?
Projects, managed services, or an honest read on your environment. You reach a principal consultant.