Most organizations can describe recovery. Fewer can demonstrate it. Two short sections compare what your organization believes about its recovery posture against what it can actually prove — the gap between them is the finding.
Based on operational indicators and documented targets.
Percentage of critical systems with active backup protection.
Percentage of scheduled backup jobs that complete successfully.
Has a restore from these backups actually been completed?
The most complete recovery exercise performed to date.
How closely the test mirrored a real incident, and when it last occurred.
Documented recovery time and point objectives, in hours.
Based on demonstrated capability and recovery evidence.
Do you have a current map of what depends on what?
Do you know the order systems must come back online, and has it been tested?
Can recovery occur while production cannot be trusted? Check everything that applies.
Who makes decisions during recovery? Check everything that applies.
The recovery time and point actually achieved during your most rigorous test.
A multiplier tells you the gap exists. Closing it requires mapping dependencies, sequencing recovery order, and assigning recovery authority — work that goes beyond what any tool can score.
A structured review against your Confidence Gap findings — identifying the specific architectural work required to close it.
Weekly breakdowns of recovery architecture, backup blast radius, and the failure patterns that show up after the backups already ran.
Zero spam. Unsubscribe anytime.