The question behind the requirement
When a cyber-insurance questionnaire asks whether you have tested a restore in the last 90 days, it is really asking one thing: can you prove your backup works, or are you guessing? A 'yes' with no evidence is worth little at claim time. What insurers increasingly want is a document.
What a real restore test involves
A genuine restore test is not glancing at a green backup log. It is bringing data back and confirming it is complete and usable. In practice that means:
- Selecting real data — files, a mailbox, or a full application database — to recover
- Restoring it to a safe, isolated location
- Opening and verifying it actually works, not just that files copied
- Recording how long the restore took, so you know your real recovery time
- Noting any errors and confirming they were resolved
What belongs in the report
The written report is the artifact your insurer wants. It should state the date of the test, what was restored, that the restore succeeded and the data was verified usable, how long it took, and who performed it. Kept on file quarterly, it answers the insurer's question before they finish asking it.
How we deliver it
Every quarter we perform a real restore for the businesses we protect and hand over exactly this report. It is not an add-on or an upsell — it is how we think backup should always have worked. When your renewal or a claim comes, the proof is already in your hands.
