CRE
Ask your MSP for a monthly backup report showing every protected system, job successes and failures, off-site copy status, protected retention where used, restore-test results, unresolved exceptions, and named owners. Review the prior 30 days of backup activity and require evidence of at least one documented restore test.
In This Article
- What should a monthly backup report prove?
- Which backup-job details should we review each month?
- How do we know backups can actually be restored?
- What security and retention evidence matters for commercial real estate?
- Who owns exceptions and recovery decisions?
- What questions should leadership ask during the monthly review?
- Frequently Asked Questions
What should a monthly backup report prove?
A monthly report should prove more than that backup software ran. It should show that the systems your business depends on were included, that backup jobs completed as intended, and that exceptions were identified before they became a recovery emergency.
For a commercial property owner or manager, the protected scope may include accounting platforms, lease and property-management data, shared documents, email, camera-management servers, access-control records, network configurations, and building-operation systems. The exact list will vary, but it should be deliberate and visible.
Ask for a current inventory that identifies each protected workload, its location, backup method, retention period, and business owner. If a system is missing from the inventory, it is difficult to prove that it is recoverable.
The report should distinguish between systems that are fully protected, newly added but still being configured, intentionally excluded, and failing. A green dashboard without this context can hide a serious coverage gap.
Review 30 days of backup activity plus at least one documented restore test every month.
Takeaway: A useful monthly report proves coverage, execution, and accountability, not simply that a backup product exists.
Which backup-job details should we review each month?
Request a job summary for the reporting period that lists successful, warning, failed, and missed jobs. It should identify the affected system, the time of the last successful backup, the reason for any failure, and whether the issue has been resolved.
Do not accept a report that shows only a percentage of successful jobs. A 99% success rate can still conceal the one failed backup involving a critical file server, tenant application, finance platform, or camera archive.
Ask the MSP to explain recurring warnings rather than normalize them. Capacity shortages, expired credentials, disconnected devices, failed snapshots, replication delays, and agent errors can each undermine recoverability if they persist.
The report should also show backup age. For each critical system, decision-makers should be able to see when the most recent recoverable copy was created. This matters when an outage happens after a weekend, holiday, or connectivity disruption.
For multi-tenant commercial real estate environments, ask whether new suite turn-ups, tenant buildouts, network changes, and newly deployed access-control or surveillance systems were reviewed for backup inclusion. Technology often enters a property through separate vendors and separate projects.
Takeaway: Monthly job evidence should make failures visible, explain their business impact, and show the path to resolution.
How do we know backups can actually be restored?
A completed backup job is not the same as a successful recovery. The strongest evidence is a documented restore test showing what was restored, where it was restored, how long it took, who validated it, and whether the recovered data or service was usable.
Ask for test evidence that matches your business risk. Restoring a single file can demonstrate basic access, while recovering a server, virtual machine, database, Microsoft 365 item, or line-of-business application demonstrates a more meaningful recovery capability.
For each test, ask the MSP to state the recovery point used and the actual outcome. The recovery point answers how current the restored data was; the result answers whether the organization could use that recovered data or service.
Testing should reflect the systems that would disrupt property operations, tenant service, payroll, leasing, security, or revenue collection if unavailable. A test that restores an unimportant folder does not validate your disaster-recovery priorities.
As GDS Technology discusses in its guide to controlled data-center relocations, service ownership should be established before operational logistics. Apply the same discipline to recovery testing: identify the business service first, then prove the technical recovery path.
Takeaway: Ask for evidence of usable restores, not merely evidence that data was copied.
What security and retention evidence matters for commercial real estate?
Ask where backup copies are stored, whether a copy is kept separate from production systems, who can administer the backup environment, and how backup access is protected. A ransomware event can affect both production data and weakly protected backup credentials.
Your MSP should identify retention settings in plain language. You need to know how far back you can recover routine files, major systems, and records with legal, financial, leasing, or operational value. Retention should align with business needs and applicable obligations, not an arbitrary default.
For Norcross and the broader I-85 business corridor, continuity planning must account for mixed-use buildings, distributed vendors, tenant expectations, and weather-related interruptions. Georgia organizations also need a practical response plan for incidents involving personal information, including clear ownership for investigation, communications, and recovery decisions.
For properties with cameras, access control, BAS integrations, and amenity or guest Wi-Fi, ask whether backup evidence covers the management systems and configurations behind those services. Replacing hardware does not automatically restore settings, footage indexes, door schedules, integrations, or network segmentation.
Review access reports for shared administrative accounts, former vendors, and remote-support credentials. The Built, Wired & Secured episode on digital keys in building operations explains why unmanaged service access can remain a material operational risk after personnel or vendor changes.
Takeaway: Backup protection includes secure access, appropriate retention, and recovery of the configurations that make building systems work.
Who owns exceptions and recovery decisions?
A report is only valuable when it leads to action. Every failed job, excluded system, capacity concern, overdue test, or unresolved warning should have a named owner, a due date, a current status, and a documented risk decision.
Ask the MSP to separate technical remediation from business acceptance. The MSP may correct a failed agent or expand capacity, but your leadership team should approve any decision to exclude a critical system, shorten retention, or defer a recovery test.
Monthly evidence should also identify changes since the prior report: new protected systems, retired assets, retention changes, failed tests, restored systems, and risks that remain open. This creates a useful audit trail as properties, tenants, and service providers change.
GDS Technology supports commercial real estate teams with commercial real estate technology support, where riser management, structured cabling, security systems, and IT operations can intersect. That coordination matters because recovery ownership is often split between property management, facilities, tenants, and technology vendors.
Real follow-up is part of dependable service. Kawal, a professional-services client, said: “GDS followed up the next day to make sure the door sensor issue is resolved. That kind of attention shows real customer service.” The same standard should apply to backup exceptions: confirm resolution rather than simply close the ticket.
For broader protection planning, review how data backup and recovery services connect with disaster recovery planning. Backups protect recoverable information; a recovery plan defines how people, systems, and priorities return to operation.
Takeaway: Require a monthly exception log with ownership and closure evidence so unresolved backup risks do not quietly roll into the next month.
What questions should leadership ask during the monthly review?
- Which critical systems were protected throughout the month, and which were not?
- Did any critical backup job fail, warn repeatedly, or miss its expected schedule?
- What is the last known recoverable point for each priority system?
- What restore test was completed, what was recovered, and did the business owner validate it?
- Where are copies stored, how are they protected, and who has administrative access?
- Which exceptions remain open, who owns each one, and when will it be resolved?
- What changed in our environment that requires a backup-scope or recovery-plan update?
Keep the discussion business-focused. A monthly backup review should answer whether the organization can restore the services it needs to operate, serve tenants, protect records, and make sound decisions during disruption.
Takeaway: Leadership should leave each review knowing the current recovery posture, the open risks, and the next accountable actions.
Frequently Asked Questions
How often should an MSP test backups?
Ask for at least one documented restore test each month, with the test scope chosen according to business risk. Higher-impact systems may require more frequent or more comprehensive testing. The key evidence is not a schedule alone; it is proof that a usable file, service, database, or system was recovered and validated.
What is the difference between a backup report and a disaster recovery report?
A backup report shows whether protected data and systems were copied, retained, and available for recovery. A disaster recovery report addresses the broader return-to-operation process, including priorities, dependencies, people, communications, alternate procedures, and recovery timing. You need both because copied data alone does not restore a functioning business service.
Should commercial property managers include cameras and access control in backup reviews?
Yes. Include the management servers, cloud configurations, door schedules, user permissions, camera settings, network configurations, and integrations that support cameras and access control. Hardware replacement does not recreate operational settings. Monthly evidence should confirm that these systems are protected and that a meaningful recovery test has occurred.
What should a monthly backup evidence package include?
A useful monthly package includes protected systems, job outcomes, last-successful backup times, storage and retention status, restore-test records, security access review, unresolved exceptions, named owners, and due dates. It should also note scope changes so leadership can see whether recovery protection still matches operations.