Security

Backups your co-op can actually restore

Identify essential data, choose useful recovery points and rehearse a restore before a lost file becomes a crisis.

In this guide

A reassuring backup dashboard does not show whether your co-op can get back to work. The useful question is whether an authorised person can restore the right information, into a usable system, within the time the organisation can tolerate.

Start with a short inventory. Include member records, finance data, shared documents, website files and database, email, configuration and any specialist application. Some services provide version history or recovery tools; others require separate exports or backup products. Confirm the scope rather than assuming one subscription protects everything.

Decide what recovery means for each service

For each item, write down how much recent work you could afford to lose and how long you could operate without it. These are decisions about your work, not technical targets someone else should guess.

An illustrative shop co-op might prioritise current orders and supplier contacts ahead of an archive of old publicity designs. A housing co-op may need emergency maintenance contacts even while its main document service is unavailable. Create a securely held continuity copy for such immediate needs, with an owner who keeps it current.

  • Data: what must be recoverable?
  • Frequency: how often must a usable copy be made?
  • History: how far back might an unnoticed problem require you to go?
  • Location: can the same incident affect the original and the copy?
  • Authority: who may restore it, and who approves overwriting live data?
  • Evidence: when was a restoration last checked?

Separate synchronisation from independent recovery

Synchronisation keeps locations aligned; that can include propagating deletion or damaged files. The NCSC ransomware guidance warns about live and backup data becoming inaccessible together. Understand which versions or protected copies remain available if an ordinary account or administrator account is compromised.

Ask your supplier to demonstrate what its backup actually includes and excludes. Can it recover an individual document, a deleted account, permissions and the entire service? Are backup administration and deletion adequately separated from everyday access? What happens if you stop paying the primary supplier or lose access to its tenant?

Keep backup credentials and recovery instructions available to authorised people through a route that does not depend entirely on the failed system. Encryption is useful only if the recovery key is also available when needed.

Run this small restore exercise

  1. Create a fictional document with a recognisable sentence and a small attachment in a representative workspace.
  2. Record the expected permissions and the time it was created.
  3. Allow the agreed backup process to include it, then verify the backup job's result.
  4. Change or remove the test document in the source location.
  5. Restore the earlier version to a separate safe location using the documented procedure.
  6. Open the restored files, check the contents and confirm who can access them.
  7. Record the recovery point, elapsed time, person performing the restore and any missing instructions.

Do not use a real payroll file merely to make the test convincing. Test representative formats with fictional data. A simple file exercise proves that part of the process; it does not prove a whole website or application can be rebuilt. Schedule a broader service recovery test appropriate to the system's importance.

For WordPress, the official backup lesson covers both files and the database. A downloaded copy of visible pages is not equivalent to a recoverable working site. Coordinate the test with whoever maintains it.

Review retention and act on failed tests

Keep history long enough to meet your actual recovery needs and applicable obligations, while applying your retention decisions for personal data. Avoid an unexamined “keep everything forever” policy. Document how expired backups are removed and how restored data is reconciled with deletions that occurred after the recovery point.

If a test fails, assign the specific fix and repeat the affected exercise. A backup warning without an owner will soon become background noise. Record emergency contacts alongside your incident procedure.

Use the technology health check to identify which service most urgently needs a restore test.

Suggest a correction or improvement →