
Backups
Part of Business backups
Identifying the files and systems that must be recoverable
Trace essential work to the files, application data and settings needed for recovery, then record ownership, location and a usable restore check.
Identify what must be recoverable by tracing essential work to its records, applications and settings. Start with a task that would stop if information disappeared. Record where the information lives, who can check it and what would make a restored copy usable.
Follow a task from start to finish
Choose a normal task, such as receiving a customer request and completing a job. Ask the people who do it which records they create, read and change. Include relevant attachments, messages, calendars and application exports. Note information kept on a laptop, phone, shared drive or supplier-hosted system.
List information and dependencies, not devices alone. Replacing a laptop may be straightforward; recovering the only current job file is not. A copied document may be unusable without the required application, permissions or settings.
| Field | What to record |
|---|---|
| Task and checker | The work that must resume and the person who can confirm it works |
| Information | Required files, messages, database records or application data |
| Current location | The device, shared location or supplier service holding the current record |
| Dependencies | Software, settings, access or related records needed to use it |
| Change pattern | When new work appears or existing work changes |
| Recovery check | An action that would show the restored item is usable |
Key steps to identify recoverable files and systems
- Choose a core business task (e.g. processing a customer order)
- Identify all records created, read or changed during the task
- Note current locationdevice, shared drive, cloud service or supplier system
- List dependenciessoftware, settings, permissions, related data
- Determine how often the information changes
- Define a recovery checkan action proving the restored item works
Find gaps at the edges
Ask where work is saved before it reaches the approved system. Check local folders, downloaded reports, shared mailboxes, scans and specialist applications where relevant. Identify the authoritative record so the backup plan protects the right version.
For a supplier-hosted application, ask what information can be restored or exported, who starts recovery, whether an earlier version is available and how an export could be used if the service were unavailable. A statement that the supplier backs up its systems does not establish that your team can retrieve a deleted record or rebuild its workflow.
Include software and configuration where they matter. A restored application may need permissions, settings and related data as well as files. Record the dependencies and involve the person who administers the system.
Backup coverage vs. actual recovery capability
- Supplier system backup (e.g. cloud accounting tool)
- May protect data but not guarantee access or restore control
- Your own local backups (e.g. external drive)
- You control access and restore process; requires consistent management
- Automated cloud sync (e.g. Google Drive, OneDrive)
- Good for file versions but may miss configuration, permissions or app-specific settings
- Manual exports (e.g. CSVs, PDFs)
- Useful for audit trails but not always sufficient for full workflow restoration
Prioritise by the consequence of loss
For each task, ask how much work staff could recreate from other records and how long they could operate without it. A frequently changed booking record may need a different backup schedule from a rarely edited template. An item that blocks an essential task can be important even if its file size is small.
Record the reason for each priority and have the task owner check it. The register should show which information needs protection and what recovery must achieve. It should not assume that a particular backup service already covers it.
How to assess risk and prioritise backup needs
- Assess impact of losscan work continue? How long?
- Evaluate recreatabilitycan lost data be rebuilt from other sources?
- Assign priority based on operational disruption risk
- Document reason for each priority level
- Have task owner verify priority and recovery requirements
Confirm the inventory
Ask the task owner to inspect the listed locations and describe how they would use a recovered item. Give the register to whoever manages backups so coverage and restore routes can be mapped to each entry. Mark unknown coverage as unresolved until it is checked. Review the register when an application, process or storage location changes.



