Skip to content
PERINGER Data Solutions, back to home

Back

← All articles

Backups: the restore test nobody runs

Published · updated

In late May 2021 the municipal administration of Rolle, on the shore of Lake Geneva, was hit by ransomware from the Vice Society group. In August a specialist found a plain Excel file on the darknet: the identities, AVS numbers, tax data and contact details of 5,393 residents, free for anyone to download. A town of 6,000 people. That’s the exact scale of an SME, with the same IT resources and the same attackers on the other side.

Five years on, the threat hasn’t eased. In its 2025 annual report, the National Cyber Security Centre counts 64,733 voluntary reports and 222 mandatory reports. And since 1 April 2025, public authorities, towns included, and operators of critical infrastructure inside the statutory scope have to report certain cyberattacks within 24 hours.

An SME outside that scope doesn’t have to report. For context, a gfs-zürich survey published in 2021 estimated that roughly one small company in three had already been hit. That’s a 2021 measure of exposure, not a current rate.

The Swiss paradox: everyone backs up, nobody tests

Those same studies point at a paradox. The technical measures are there, since most SMEs run regular backups. The organisational measures are neglected: the plans to follow in an emergency, the exercises, the training. Put plainly, the tape exists and nobody has ever tried to read the tape.

That’s exactly where modern attacks strike. Ransomware no longer stops at encrypting production servers: it first looks for the backups it can reach over the network, and it destroys them. A NAS that stays connected all the time and uses the same admin password may hold a backup copy right next to the server. But that copy isn’t a strategy. Errors, theft or fire can reach the original and the copy at the same time, and so can the encryption.

The rule, then the test

On my own engagements I fix the date of the first restore before agreeing to anything else. Do it the other way round and you get backups nobody ever checks.

The 3-2-1-1-0 rule fits in one sentence: three copies of the data, on two types of media, one off site, one offline or immutable, and zero unresolved errors after you verify. The immutable copy has to resist the production admin accounts, not only the ordinary users.

The rule is worth nothing if you never test it. Quarterly is a useful place to start for many small companies; you set the frequency and the scope to match the recovery time objective (RTO), the recovery point objective (RPO), the impact on the business and the rate of change. Stopwatch in hand:

  1. A file at random: requested by someone other than the person who manages the backups
  2. A complete folder: with its access rights
  3. A complete service: restored in an isolated environment with the application, database, permissions, keys, DNS, network and dependencies it needs to run.

Three questions at the end. Did everything come back intact? How long did the restore take, and can you live with that delay for payroll, for invoicing, for the client files? And above all, who knew how to do it? If the answer is “one person”, you don’t have a plan. You have a dependency.

The cost of the test, and the losses it prevents

For a simple scope, the test may take half a day each quarter. An ERP, an identity platform, several sites or hard objectives will take longer. Against that, look at what Rolle paid: months of crisis management, a commission of inquiry and lasting damage to trust. The data itself is still on the darknet. Nobody “restores” a leak. The revised federal data protection act, in force since 2023, also requires every company to keep its security “appropriate to the risk”. So a documented restore test helps you prove, before and after an incident, that you addressed the risk. It doesn’t replace the other controls.

The record that makes the test useful

Write down the asset and the recovery point. Write down the target RTO and RPO next to the time the restore actually took. Note the integrity result, the permissions, the keys and the dependencies. Note who ran the test, the gap you found, the fix and the date of the next test. Include the SaaS exports and the way back to your identity provider: without identity, a restored server may still be useless to you.

The test costs time. But you can measure the result of the test, and that’s exactly what separates a tested restore from a backup promise.

Sources on the Rolle case

Set the test frequency, the scope and the recovery objectives for each service to match its impact, rather than copying one universal schedule.

Federal reports consulted on 14 August 2026.

A first conversation, no commitment

A few lines about your project or your question are enough: I reply directly, usually within one working day.

Get in touch