
When I sit down with a new client for the first time, I don’t start by asking what software they use or what their network looks like.
I ask one simple question: When was the last time you actually tested your backup?
Not “do you have a backup.” Almost everyone says yes to that. I mean REALLY tested, like we do at Tech Experts. Restore a file, open it, and make sure the contents are really there.
The answer tells me more about a business’s real risk than almost anything else I could ask. Most of the time, people pause.
They know backups are running and they’ve seen the “green checkmark” or the automated email confirming success. What they haven’t done is actually try to get their data back.
The action of making sure the backups are restorable matters more than people realize. A backup that runs every night but has never been tested is really just a hope, not a plan.
I’ve seen businesses discover their backups were incomplete, corrupted, or hadn’t run properly in months, and they only found out when they needed the files most, or when disaster struck.
By then, it’s too late to fix quietly. It becomes a crisis instead of a non-event.
The second question I ask
Once we’ve talked about backups, I ask something else: who can see what on your network?
This one usually gets a longer pause. Most business owners can tell me who has a login. Most can’t tell me what each of those logins can actually access. In a busy office, permissions pile up over time. That employee who got access to the accounting share for a one-time project keeps it long after the project ends. Even worse (and we see this all the time) is when a former employee’s account gets disabled but never fully removed.
By themselves, none of these seem like an urgent problem. Together, they add up to a business that doesn’t really know who can touch its data. That’s a hard position to defend from, whether the threat is a hacker or just an honest mistake.
Why I ask these two first
Neither question is technical. I’m not asking about firewalls or encryption or anything like that. I’m asking whether you actually know what would happen if something went wrong today. This helps me understand a client’s risk tolerance, and how much importance they place on their IT systems.
Most businesses I meet have invested in tools. They have antivirus and a firewall, and some kind of backup system. What they often haven’t done is confirm that any of it actually works the way they think it does.
Untested backups and unmanaged access are two of the most common ways I’ve seen businesses get hurt. These companies aren’t careless, they just didn’t know they should be checking these things.
That’s really what these two questions are getting at. It’s not about whether you have the right tools. It’s about whether you actually know your own risk. Most business owners are surprised by how much clarity comes from just asking.
