PikoSystem IT engineering services
Free Audits

Free backup health check: can your backups really be restored?

A backup that has never been restored is an assumption. In a server backup check, we review your backup jobs, where the copies live and when the last good copy was made, using read-only access. With your approval, we also restore a sample file or database in an isolated environment to see whether the backup holds up when you need it.

Tools & technology backup-check
  • Veeam Backup & Replication
  • Proxmox Backup Server
  • Windows Server Backup
  • rsync
  • Restic
  • BorgBackup
  • mysqldump
  • JetBackup
  • Acronis
5work areas
4deliverables
4steps

What is Backup Health Check?

A server backup check is a read-only review of your backup jobs, retention and storage, combined with a sample restore to see whether the backups actually come back when needed. It fits companies that set up backups but never tested a restore, keep every copy on the server being protected, or lost the person who configured them. PikoSystem reviews job schedules and backup types, reads recent logs for failed runs and skipped files, counts copies against the 3-2-1 rule, compares servers, databases and mailboxes with what is really backed up, and with your permission restores a file or database in an isolated environment. Systems covered include Veeam, Proxmox Backup Server and Restic. No settings are changed. You receive a backup status report per server, a list of data with missing backups, and recommendations.

When you need Backup Health Check

  • Backups are set up, but we have never tried restoring one.
  • All our backups sit on the same server they are supposed to protect.
  • The person who set up our backups left, and nobody knows where the files go.
  • Veeam sends a warning email every night and nobody reads it.

What Backup Health Check includes

01

Jobs and schedules

We review backup jobs, run times, backup type (full or incremental) and retention, from the console or the config files.

02

Logs and errors

We go through recent job logs for failed runs, ignored warnings and files that get skipped every time.

03

Storage and the 3-2-1 rule

We count how many copies you have, on how many types of media, and whether any copy is offsite or offline where ransomware cannot reach it.

04

Data coverage

We compare your servers, databases, mailboxes and key folders with what actually gets backed up. Databases copied as raw files while running are flagged separately.

05

Sample restore test

With your permission, we restore a file, a database or a small virtual machine into an isolated environment and verify it. No data leaves your environment.

What you get from Backup Health Check

  • A backup status report for each server and service
  • A list of data with missing or incomplete backups
  • Results of the sample restore test, if one was run
  • Recommendations based on the 3-2-1 rule

Backup Health Check: a practical guide

Automated SQL and MySQL backups: common mistakes

SQL Server Express has no SQL Server Agent, so a maintenance plan created on it never runs. Automated backups there need Windows Task Scheduler calling sqlcmd. Another frequent find is a database in the FULL recovery model with no transaction log backups, where the LDF file keeps growing until the disk fills.

In MySQL, mysqldump without --single-transaction locks tables for the whole dump, or produces an inconsistent copy if locking is turned off. RESTORE VERIFYONLY only confirms that a backup file is readable. Whether the data is intact after a restore is what DBCC CHECKDB tells you.

RPO and RTO: how much data and time can you afford to lose?

RPO is the amount of recent data you can afford to lose. With nightly backups only, a failure late in the day costs almost a full day of work. RTO is how long you can run without a system before it has to be back.

These targets differ by system. An accounting or sales database usually needs a much shorter RPO than an archive file share. Recovery time has to be measured too, since pulling a few hundred gigabytes back from an offsite copy over the internet can take far longer than expected. A restore test gives you the real number.

Why ransomware goes after your backups first

Modern ransomware looks for the backup repository before it encrypts anything. If the Veeam server is domain-joined, accepts the same Domain Admin login, or writes to an SMB share on a NAS that every server can see, the attacker can delete or encrypt the backups with the access they already have.

VM snapshots and RAID do not count as backups either, because they live on the same storage. A copy that survives ransomware is offline, like a removable disk disconnected after each run, or immutable, like a Veeam Hardened Repository or S3 storage with Object Lock.

Keeping your backup strategy healthy after the check

Backup reports should go to a named person, and a failed job should become a tracked task instead of an unread email. Repeat sample restores periodically and after any significant change, such as new storage, a backup software upgrade or a new server.

If backups are encrypted, keep the password or key somewhere safe and separate from the backup system, because an encrypted backup without its key is useless. Write a short restore procedure for each system so recovery does not depend on one person's memory.

How Backup Health Check works

  1. 01

    Fill in the form

    Tell us which backup system you use and how many servers are involved.

  2. 02

    Read-only access

    A view-only account on the backup console, or a remote session with one of your staff, is enough. No settings are changed.

  3. 03

    Review and sample test

    We go through settings and logs and, if you agree, run the sample restore.

  4. 04

    Report

    We send the risk report and recommendations. Once we are done, disable the temporary access.

Backup Health Check: frequently asked questions

Why might a backup that reports success every night fail to restore?

Success only means the job finished without an error. An important path may be excluded, a database may have been copied mid-write, or the backup file may be corrupted on disk. Only a restore test brings these problems to light.

What is the 3-2-1 backup rule?

Keep at least three copies of your data, on two different types of media, with one copy away from your main site. Against ransomware, an offline or immutable copy is also recommended.

What does the free check leave out?

During this check we do not change settings, create new jobs or recover lost backups. Redesigning your backup strategy and setting up disaster recovery are separate services.

Will you have access to our data?

Reviewing settings only needs view access. The restore test runs inside your environment on data you choose, and we keep no copy of it.

Related searches

  • backup restore test
  • backup strategy
  • 3-2-1 backup rule
  • enterprise backup
  • Veeam backup error
  • automated server backup

Free

Request a free audit

Give us your site address or server IP. The check makes no changes to your systems and you get the results as a written report.

  1. 01We agree on access. Most checks only need read-only access.
  2. 02We run the check without changing anything on your systems.
  3. 03You receive a report with issues ranked and fixes suggested.

Your details are only used to answer this request.