1. What exactly is protected?
List the servers, VMs, application data, SQL databases, file shares, system state and configuration data included in backup scope. Compare the list to what the business actually depends on.
2. Where are the copies?
A local repository can protect against a server failure but may not protect against a site event or compromised administrative credentials. Document the local copy, offsite copy, cloud copy and any immutable or isolated copy.
3. How far back can you recover?
Retention should match the time it may take to discover corruption, accidental deletion or malicious activity. A short retention window can leave the organization with several successful backups that all contain the same problem.
4. How long will recovery take?
Recovery Time Objective is a business requirement, not a backup-software setting. Test enough of the recovery path to estimate how long it takes to restore the service, reconnect users, validate applications and resume operations.
5. Can the recovery process work when production is unavailable?
Store recovery documentation, credentials and escalation information so they are available even if the domain, password vault, file server or primary site is part of the outage.
6. Test the restore, not just the backup
For Veeam, Datto BCDR or another platform, a useful test should validate the restored workload, not merely confirm that files can be read. Check boot, services, application functionality, authentication, network connectivity and data consistency as appropriate to the workload.
7. Record the evidence
- Date and scope of the test
- Backup/recovery point used
- Time to restore or virtualize
- Services and applications validated
- Problems encountered
- Corrective actions and next test date