Schools · Cybersecurity

A backup is not a recovery plan until someone can show the last successful restore.

Why backup dashboards are not recovery evidence, and how schools can test real services, dependencies and recovery time.

Damien Cantelo

Damien Cantelo

September 9, 2026

Tactile illustration of backup servers and circular recovery arrows pointing to a restored working system

A backup is not a recovery plan until someone can show the last successful restore.

A green backup dashboard confirms that data was copied.

It does not confirm that a school can restore the services needed to resume teaching and administration.

In practice, recovery depends on more than data. Identity services, network access, application settings, licences, devices and supplier support may all need to be available in the right order.

Backup success and recovery readiness are different measures

Backup reports are useful. They help identify failed jobs, capacity problems and systems that have stopped being protected.

But they measure one part of the process.

A successful restore asks harder questions:

  • Is the backup complete and readable?
  • Can the school access it when normal identity services are unavailable?
  • Are the application and configuration settings available as well as the data?
  • Are encryption keys, licences and supplier contacts accessible?
  • Can interconnected systems be recovered in a workable sequence?
  • How long does the process actually take?

The Australian Cyber Security Centre's Essential Eight assessment guidance distinguishes routine restoration of individual files from disaster recovery exercises that restore data, applications and settings to a common point in time.

That is a useful distinction for schools. Recovering one deleted document does not demonstrate that a student management system, finance platform or identity environment can be returned to service after a significant incident.

Start with three important systems

Testing everything at once may be unrealistic.

A useful starting point is to choose the three systems whose loss would create the greatest disruption. Consider both the sensitivity of the information and the operational effect of an outage.

For each one:

  1. Document the recovery sequence and its key dependencies.
  2. Restore the service to a known point in time in a safe test environment.
  3. Confirm that authorised users can sign in and complete important tasks.
  4. Record what worked, what did not and how long it took.
  5. Assign an owner and due date to every unresolved issue.

The exercise does not need to simulate every possible disaster. It needs to produce credible evidence about whether the school can recover an important service within an acceptable period.

Test the dependencies, not just the database

Modern school services rarely operate alone.

A restored application may still be unusable if identity federation is unavailable. A database may be intact while its application configuration is missing. A cloud service may depend on a supplier to initiate recovery. Network rules, certificates or domain name services may need to be restored before users can connect.

Map the dependencies before the exercise and then compare the plan with what actually happened. Unexpected dependencies are valuable findings when they are discovered during a controlled test rather than during an incident.

This is also where recovery objectives become real. A documented target may say four hours, but the test may show that access approvals, data transfer or supplier response makes that impossible. Leadership can then decide whether to accept the gap, change the target or invest in a better recovery capability.

Protect the recovery environment

It is worth reviewing who can administer backups and how those administrators authenticate.

Separate backup administration credentials can make recovery more resilient if the school's primary identity environment is affected. Administrative access should be limited, protected and monitored. Recovery instructions, critical contacts and required secrets should also be available through a controlled method that does not depend entirely on the systems being recovered.

The goal is not to make backups difficult to reach when they are needed. It is to prevent the same compromise from taking control of both production systems and their recovery path.

Give leaders evidence they can use

From a governance perspective, the board does not need another report showing backup completion percentages.

It needs evidence that the school can recover its most important services within an acceptable period.

A concise recovery report can show:

  • the service tested and business impact considered
  • the recovery point achieved
  • the time taken to restore usable service
  • important dependencies and assumptions
  • unresolved gaps, owners and target dates
  • the date and scope of the next exercise

That creates a better conversation about operational resilience, risk appetite and priorities.

The most useful backup question is not whether the jobs ran overnight.

It is: When did we last restore a real system, and what did we learn?

#CyberSecurity #CyberGovernance #Education

Make Cyber Compliance Simple

See how Apollo Secure can help you manage cyber risk, compliance and customer trust without enterprise complexity.

Book a Demo