Scenario

A drill, concretely.

The question we get before a first drill is always the same: could this break something. Here is exactly how it runs, and why the answer is no.

How it runs

  1. 01

    Before: the scope is fixed in writing

    Which service, restored from which backup, onto which separate environment, with which success criterion. Anything that would touch production is explicitly excluded and cannot be added mid-drill.

  2. 02

    During: we time it and write it down

    Every step is timestamped, including waiting and searching. A recovery stuck twenty minutes on a password nobody can find counts towards the time: that is exactly what we are measuring.

  3. 03

    After: the report and the gaps

    The time achieved, compared with the agreed target. The list of gaps, each with an owner and a deadline. And an update to the procedure wherever it proved wrong or incomplete.

Production is not touched

Drills run on a restored environment, separate from production. Any action that would affect it is announced, scheduled and approved by you first. A drill that would require a production outage is proposed as such, with its window, and remains your decision.

The first drill often fails, and that is useful

On a setup that has never been tested, a first drill rarely meets the target time. That is not a bad result, it is the expected one, and it is what justifies running it early rather than postponing it.

What matters is the gap between the first drill and the second. If the items raised have been closed, the framework is improving. If they are still open, the problem is not technical: it is one of decision or resources, and it needs to go back to management.

We refuse to present a first drill that succeeds immediately as proof of robustness. It usually means the scope tested was too simple.

Request an assessment

Start by knowing where you stand

Tell us which applications you cannot lose, how long you could hold out without them, and when a restore was last actually tested. We reply within two working days.

  • Swiss engineering
  • Reply within two working days

Email Contivaro

Tell us when a restore was last tested. If the answer is “never”, let’s start there.

Email Contivaro