Take regular backups of information, software and systems, and test that they can actually be restored. A backup you have never tested may not work when you need it.
What an auditor, or Sekit's evidence engine, asks for.
Backup configuration and restore-test record
How backups are made (what is backed up, how often, where they are stored) and the proof that a restore has been tested successfully.
From the Sekit evidence catalog
In practice
Most small organizations pass the backup question and fail the restore. The pattern that works: automate the backup, keep one protected copy off-site or in a separate tenant, and put a restore drill on the calendar. Quarterly is enough for most SMEs. Ransomware crews target backups first, so the protected copy matters as much as the schedule. Auditors rarely ask to see the backup itself; they ask when you last restored one, how long it took, and what failed.
Common gaps
Backups run on schedule, but no restore has ever been tested. The first real restoration attempt happens during an incident, which is the worst possible moment to discover it fails.
Retention and scope are undefined: nobody can say which systems are covered, for how long, or whether the copy survives a ransomware attack on the primary environment.
Questions your auditor will ask
When did you last restore from backup, and is the result documented?
The most recent restore test ran last quarter, logged in the backup configuration and restore-test record with the system restored, duration, and outcome.
Which systems are excluded from the backup scope, and who approved those exclusions?
The backup coverage review lists every excluded system with a named business owner who signed off on the exclusion and the reason for it.
How is at least one backup copy protected from the same ransomware that could hit production?
At least one copy is stored offsite or in immutable, write-once storage that production credentials cannot delete or modify.
Where regulation demands it
NIS2 Article 21(2)(c) names backup management explicitly among required business continuity measures. ENS op.cont controls expect the same discipline from Spanish public-sector suppliers.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.