AUD / AUD-06
Backup and recovery readiness audit
A review of whether backups cover the right systems, resist malicious use and support recovery requirements.

WHEN IT HELPS
A focused response
to a defined need.
IT, operations or executives; untested restores, ransomware concerns or dependence on one administrator.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Coverage and retention
- access separation
- restore evidence, dependencies and RPO/RTO objectives
Deliverables
- Coverage matrix
- protection gaps
- backup-testing and hardening plan
Acceptance evidence
Business objectives are compared with available evidence; missing tests are reported as uncertainty.
DELIVERY
How the work is structured.
Approach
Scope assets and criteria; gather evidence and interviews; validate gaps; present priorities and limitations.
Prerequisites & responsibilities
Customer: inventory, read access, documents and business contacts. Provider: assessment and debrief. Production changes are not included by default.
Scope factors
Sites, assets, technologies and interviews; assessment depth; inventory quality; access constraints; required reporting. One-off project with optional follow-up.
Questions to clarify
When was the last full restore? Who can delete copies? How much data loss is acceptable?
IMPORTANT BOUNDARIES
A document review does not demonstrate an RTO; recovery testing must be explicitly commissioned and organised.
Sampling and observation date are explicit. No assessment certifies the absence of flaws; remediation, penetration testing and recurring follow-up are separate scopes.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A distributor has an all-green backup dashboard but no ERP recovery test. Project: review coverage and dependencies. Target outcome: an application-recovery test plan; copy success is no longer confused with recovery success.
Scenario 02
An SME’s backups are accessible with the primary administrator account. Project: review separation and retention. Target outcome: separate administration, deletion protection and an isolated test before policy changes.
Technology and reference context
Existing backup products; offline or immutable storage assessed against requirements.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
