§ Cybersecurity proof & diagnostic assets·print-friendly · worksheet

Prove your backups actually restore.

A worksheet to record, system by system, your recovery targets and the last time a restore was actually tested — plus a standard for what counts as restore evidence. Backups you have never restored are a hope, not a control.

About this asset

Audience
IT owners and leaders who need to confirm that critical systems can be restored within an acceptable time and data loss.
Owner service
Incident Response & Ransomware Readiness
Classification
Classification: Public · Version 1.0 · July 2026
Methodology
The worksheet reflects the recovery outcomes in NIST Cybersecurity Framework 2.0 (NIST CSWP 29, the Recover Function) and CISA's #StopRansomware guidance on tested, offline/immutable backups. RTO and RPO are your own targets; nothing here sets them for you.
Limitations
Point-in-time, self-diagnostic worksheet you complete yourself. It is not a DSE assessment, an audit, an attestation, or legal advice, and it produces no compliance result or certification.
Verification
The framework and guidance references were checked against the csrc.nist.gov and cisa.gov landing pages linked below. The two filled example rows are illustrative; the rest are blank for your data.
The worksheet

One row per critical system.

List your critical systems, set an RTO (how fast it must be back) and an RPO (how much data loss is tolerable), and record the last real restore test and its evidence. Two rows are filled as examples; the rest are yours.

Backup & recovery test worksheet — the first two rows are illustrative examples
System RTO target RPO target Last restore test Restore evidence artifact Result Gap / owner
Primary file store 4 hours 24 hours 2026-06-14 Timed restore log + integrity check Pass None · Infrastructure Lead
Line-of-business database 8 hours 1 hour Never tested Unproven Schedule restore test · IT Manager
 
 
 
 
Evidence standard

What counts as restore evidence.

A “yes, we tested it” with nothing behind it is not evidence. A restore test counts when it produces at least these artifacts.

Minimum restore-test evidence

  • Timed restore log. A record of the restore with start and finish times, so recovery time is measured against the RTO rather than assumed.
  • Screenshot of restored data. Visual proof the restored system or dataset opened and showed the expected content, dated to the test.
  • Data-integrity check. A verification (record counts, checksums, or a spot-check by a data owner) that the restored data is complete and not corrupted.
  • Isolation note. Confirmation that at least one backup copy is kept offline or immutable — a copy your production credentials alone cannot modify or delete.

Make restore-testing a habit, with evidence.

A free 30-minute Cyber Risk Check scopes a readiness engagement that builds a restore-test cadence and the evidence standard your leadership and insurer will ask for.

What this is and is not. A point-in-time, self-diagnostic worksheet. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice, and completing it guarantees no recovery, incident, or claim outcome. Restore results depend on your systems, evidence, and the test you actually run.

Primary sources, verified.