FREE TEMPLATE
Backup and Recovery Policy
A backup nobody has restored from is not a backup. RPO, RTO, the 3-2-1 rule, and the restore test record that turns an assumption into a fact.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change
Purpose
A backup nobody has restored from is not a backup. It is a hope with a monthly invoice. This policy defines what gets backed up, how it is protected, and how often restores are actually tested.
Scope
Applies to all [COMPANY NAME] data required to operate the business, wherever it lives — servers, workstations, network storage, and cloud services including email, file storage and line-of-business applications.
Cloud services are not backed up for you
Microsoft 365, Google Workspace and most software-as-a-service providers operate a shared responsibility model: they keep the service running, you are responsible for your data in it.
Their retention is short and designed for accidental deletion, not for ransomware, a malicious departure or a mistake found six months later. Company data in cloud services is backed up separately under this policy.
What gets backed up
| Data | Where it lives | Frequency | Retention |
|---|---|---|---|
| Email and calendars | |||
| Shared files and documents | |||
| Accounting / ERP | |||
| CRM | |||
| Line-of-business applications | |||
| Servers (full image) | |||
| Workstations | |||
| Website and databases | |||
| Configurations — firewall, network, identity |
Fill this in completely. The gap between what you assume is covered and what is actually covered is where the loss happens.
Recovery objectives
For each system above, [COMPANY NAME] defines:
RPO — recovery point objective. How much data you can afford to lose, measured in time. A nightly backup means you can lose up to a day of work.
RTO — recovery time objective. How long you can afford to be without it.
These are business decisions, not technical ones. They are set by [POLICY OWNER] with the business owner, written down, and the backup design is built to meet them — not the other way around.
| System | RPO | RTO |
|---|
The 3-2-1 rule
At minimum: three copies of the data, on two different media or platforms, with one copy off-site.
At least one copy must be immutable or otherwise out of reach of an administrator account — meaning it cannot be altered or deleted for a defined retention period, even by someone holding valid credentials.
This last point is the one that matters most. Modern ransomware operators look for the backup system first and delete the backups before encrypting anything, using credentials they have already stolen. A backup your domain admin can delete is a backup an attacker can delete.
Encryption
Backups are encrypted in transit and at rest. Encryption keys and backup system credentials are stored in the password manager, held by at least two people, and are not stored only inside the environment being backed up.
Monitoring
Backup jobs are monitored and failures are reviewed within [NUMBER] business days. Silent failure is the normal way backups die — a job stops running, nobody notices, and it is discovered during a restore months later.
[POLICY OWNER] reviews backup status at least [WEEKLY / MONTHLY] and records that the review happened.
Restore testing
At least quarterly, [POLICY OWNER] performs a test restore and records:
- Date of the test
- What was restored
- How long it took, measured against the RTO
- Whether the restored data was complete and usable
- Any problems found, and what was done about them
At least annually, the test covers a full system restore rather than individual files.
This record is the single most valuable document in this policy. It is what an insurer asks for, and it is the only thing that turns a backup from an assumption into a fact.
Retention and disposal
Backups are retained per the table in section 4, and no longer. Retaining data indefinitely increases what you can lose in a breach and what you must produce in litigation.
Retired backup media is destroyed or securely erased, and the destruction recorded. Drives leaving on a leased device are wiped, with a certificate, before the device leaves the building.
Responsibilities
[POLICY OWNER] owns backup configuration, monitoring, testing and records.
Business owner approves recovery objectives and the spending required to meet them.
Everyone stores company data in approved company systems, so that it is covered by this policy. Data saved to a local desktop or a personal account is not backed up and is not protected.
Review
Reviewed at least annually by [POLICY OWNER], after any restore failure, and whenever a new system holding company data is added.
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your retention obligations. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
