HNORIGIN · TOOLS

Backup Readiness Score

20 questions, about 6 minutes. Find out how recoverable your backups really are, and what to fix first.

$ Runs in your browser. Nothing is sent or stored.

Answer honestly for your most important systems. Choose Not sure rather than guessing: an unknown is a gap until it is confirmed.

01Coverage

01Do you have an up-to-date list of every system and data set that needs protecting (servers, VMs, databases, file shares, SaaS)?

Including who owns each one and whether it is actually being backed up.

02Are Microsoft 365 or Google Workspace backed up by a separate backup tool?

The provider's recycle bin and retention policies are not a backup. If you don't use either service, answer Yes.

03Are databases and applications (such as SQL Server, Oracle or Exchange) backed up in an application-consistent way, including transaction logs where needed?

Crash-consistent VM snapshots alone can restore a database that will not start or has lost recent transactions. If you run no databases or applications, answer Yes.

04Are backup schedules and retention based on agreed RPO and RTO targets for each system?

RPO: how much data you can afford to lose. RTO: how long you can afford to be down.

02Copies and isolation

05Do you keep at least three copies of critical data (production plus two backups) on at least two different storage systems?

The 3 and the 2 in the 3-2-1-1-0 rule.

06Is at least one backup copy kept off-site, at another site or in a different cloud region?
07Is at least one copy offline, air-gapped or isolated so that attackers on your network cannot reach it?

For example, tape stored offline, or a vault with separate credentials and no standing network access.

08Do your backups go back far enough to restore from before an attack or corruption started, not just the last week or two?

Attackers often stay hidden for weeks before encrypting, and silent corruption can go unnoticed for longer.

03Protection

09Is at least one backup copy immutable, so it cannot be changed or deleted before it expires, even by an administrator?

Often called WORM, retention lock or object lock.

10Is multi-factor authentication (MFA) required for every login to backup consoles, storage and cloud accounts?
11Do backups run under dedicated accounts that are not domain admins, with backup systems separated from the main domain where possible?
12Are backups encrypted, with the encryption keys stored somewhere you could still reach during a disaster?

04Recovery testing

13Do you test restores on a schedule (at least quarterly) and record the results?
14In the last 12 months, have you recovered a complete server or VM, not just individual files?
15Have you measured how long real restores take and compared that with your RTO targets?

05Operations

16Are backup failures and warnings sent to someone who reviews them every day and owns fixing them?
17Are you alerted to unusual backup activity, such as mass deletions, retention or policy changes, or sudden spikes in changed data?

These are often the first visible signs of an attack in progress.

18Are your backup software, agents and appliances on supported, patched versions?

06Recovery readiness

19Is the backup server itself protected, with its catalog and configuration (for example the management database) backed up and stored separately?

If the backup server is lost, the backups it manages can become hard or impossible to use.

20Is there a step-by-step recovery runbook, including recovery order, stored somewhere reachable if your main systems and domain are down?

For example, identity and DNS before the applications that depend on them.

0 of 20 answered
–

0 / 100

By area

Fix these first

    Want a second pair of eyes?

    HNOrigin offers scoped backup and data protection reviews: what is actually protected, how recoverable it is, and a prioritised fix list.

    Request a backup review
    How the score works

    Yes scores full points, Partly scores half, No and Not sure score zero. Controls that most directly decide whether you can recover after ransomware or a site loss (off-site, isolated and immutable copies, MFA, restore testing and protection of the backup server itself) carry more weight than the others.

    Two conditions cap the grade at D, however high the score: having neither an isolated nor an immutable copy, or not testing restores. These are the 1 and the 0 in the 3-2-1-1-0 rule: one copy attackers cannot change, and zero unverified recoveries.

    Grades: A 90 and above, B 75 to 89, C 60 to 74, D 40 to 59, F below 40.

    This is an indicative self-assessment based on common backup and recovery good practice. It is not an audit and does not replace a review of your actual environment. Your answers stay in your browser and are not sent anywhere.

    Scroll to Top