The Hidden Risk in Backups: Chirag Goswami Highlights the Danger of Untested Recovery

C

Chirag Goswami

LinkedIn Author

Founder @ Cybernara | Security-First Managed IT & Cloud Partner | Cloud, M365 & GRC | LinkedIn Top Voice

In a recent LinkedIn post, Chirag Goswami highlights a critical oversight in data protection strategies: the assumption that backups are inherently reliable without verification. Goswami shares a cautionary tale from a client engagement where a seemingly robust backup system failed catastrophically when needed, underscoring the importance of proactive testing and defined recovery processes.

The post begins by outlining a common scenario:

“Recently, we worked with a client who was confident everything was in place. Backups were running. Reports were showing success. Storage was filling up.”

This seemingly stable situation quickly dissolved when the client encountered a critical failure. Goswami elaborates on the immediate aftermath:

“Then something broke. They tried to restore. It failed. No one had ever tested it. No recovery process was defined. And critical data was either incomplete or unusable.”

The Fallacy of Untested Backups

Chirag Goswami’s central argument revolves around the misconception that simply having a backup solution in place guarantees data recovery. As Goswami points out, the client’s experience demonstrates that the mere act of backing up data is insufficient. The crucial, often overlooked, step is validating the integrity and usability of those backups through actual restore tests. This lack of validation, Goswami warns, leaves businesses vulnerable.

Defining Recovery Objectives and Processes

Following the client’s critical failure, Goswami’s team intervened to establish a reliable recovery framework. The interventions included:

  • Validating backup integrity
  • Implementing proper restore testing procedures
  • Defining clear Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)
  • Building a robust and dependable recovery process

According to Goswami, these steps are essential for transforming a mere backup system into a true data protection strategy. He emphasizes that the ultimate measure of a backup’s success is its ability to be restored effectively when required.

Assumptions as the Biggest Risk in Cybersecurity

Goswami directly addresses the danger of relying on assumptions in the cybersecurity landscape. He states:

“Because a backup isn’t a backup… until you’ve restored from it. If you haven’t tested yours recently, you’re trusting assumptions. And in cybersecurity, assumptions are risky.”

This stark warning serves as a call to action for businesses to move beyond complacency. Goswami advocates for a proactive approach, urging organizations to regularly test their backup and recovery procedures. This diligence, he suggests, is paramount for ensuring business continuity and mitigating the potentially devastating impact of data loss, especially in the face of threats like ransomware.

Chirag Goswami’s insights from this LinkedIn post provide a valuable reminder for IT professionals and business leaders alike: robust data protection requires more than just storage; it demands rigorous testing and a well-defined recovery plan.

📝 About This Content

This article is based on insights shared by Chirag Goswami on LinkedIn.

📅 Originally posted on March 24, 2026 | View original post on LinkedIn →