Security Answer Kit

All guides

Backup and business continuity questions in a security questionnaire

These six questions ask whether you can recover: backups and their frequency, restore tests, a continuity plan, recovery targets (RTO and RPO), key person risk and redundancy.

What the client wants to know

The client wants to know that a failed system, a lost laptop or a sick founder does not end their project. A backup that was never restored is a weak answer, so a tested restore is the detail they look for. Recovery targets show that you have thought about how long an outage lasts and how much work could be lost.

The 6 questions as clients phrase them

The kit covers 6 questions in this area. The wording varies between questionnaires, the control behind it does not.

  1. Do you back up data, and how often?
  2. Are backups tested?
  3. Do you have a business continuity or disaster recovery plan?
  4. What are your recovery time (RTO) and recovery point (RPO) objectives?
  5. What happens if a key person becomes unavailable?
  6. Do you have redundancy for critical systems?

What a good answer contains

Watch out for

If you have not tested a restore, say it is planned. Then do it: restore one backup into a test environment, time it and write down the result.

Controls behind these answers

These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.

Example: how a prepared answer opens

Question: What are your recovery time (RTO) and recovery point (RPO) objectives?

Target RPO is 24 hours (daily backups).

This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.

Back to all guides

Related: Encryption Incident response

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.