"We have backups" is not the same as "we can restore."
Most companies discover their backups don't work in the worst week of their year. The snapshot job was running every night. The dashboard was green. The reports went to an inbox nobody read. And the restore process had been silently broken for eight months, because a credential expired, or a target filled up, or a software update changed a setting that nobody noticed. By the time anyone tried to actually recover, the ransomware was already encrypting the only copy that mattered, and the backup that was supposed to be the safety net turned out to be a screenshot of one.
We test restores quarterly. We document the recovery time and compare it to the target everyone agreed to. We fix the silent failures before they become live ones, because a backup that has never been restored is an untested assumption, not a plan. None of that testing costs extra. It is simply the bar, the same way changing the oil is part of owning the car rather than a premium service.
"The restore drill caught a misconfiguration that would have cost us three days of revenue. We've never been happier to fail a test."
Good backup is also the last line of a ransomware defense, the control that turns an extortion demand into a bad afternoon. If the worst happens and an attacker encrypts your environment, a tested, immutable, off-site backup is what lets you decline to pay and restore on your own terms. That's why we treat backup as a security control, not just a chore, and why it sits alongside detection and response rather than off in an unrelated corner.