Co-Working
When an enterprise tenant asks for proof of backup testing or security awareness training, scope the ask before you react. Identify what system or population they mean, find where your records live, and determine whether the gap is a real practice gap or just a paperwork gap. You can typically assemble the relevant documentation within 48 to 72 hours if you know what exists - the goal is to show the practice is real, documented, and owned, not to produce a perfect binder overnight.
In This Article
- Why does an enterprise tenant want backup testing or security awareness training documentation?
- What does "proof of backup testing" actually mean?
- What does "security awareness training" documentation look like in a co-working context?
- How do we gather and package this documentation without disrupting daily operations?
- When should a co-working operator bring in outside IT or compliance help?
- Frequently Asked Questions
Why does an enterprise tenant want backup testing or security awareness training documentation?
“Answers Every Question and Solves the Problem GDS Technology answers every question we throw at them and actually follows through to solve it. You get real answers, not deflection — and the problem gets fixed, not just talked about. They make it easy to bring them anything and walk away with a result. — Ashlee Castellano (Commercial Real Estate)”
Ashlee, commercial real estate
The tenant is usually not auditing you for sport. Their internal risk, compliance, or procurement team has flagged the requirement as a lease condition, and the leasing contact does not have authority to waive it. That happens routinely in markets like the I-85 corridor around Norcross, where a single floor can hold a CPA firm, a law practice, and a medical administration team - and at least one of those tenants will have an IT contact who asks hard questions before the lease is signed.
The request is also a signal about how the tenant evaluates vendors. A company asking for documented backup testing and security awareness training has likely been burned before - by an outage they could not recover from, or a phishing incident that could have been prevented. Your documentation is the fastest way to give them confidence. A co-working operator that can produce a dated restore test log and a security awareness completion record is signaling operational maturity, not just handing out Wi-Fi passwords and keys.
One commercial real estate contact we work with described the dynamic plainly: the team completed its work "while minimizing disruption to the tenants and building." That is the same posture you want when producing this documentation - evidence the discipline was already built in, not a scramble that interrupts member operations.
The practical takeaway: treat the request as a qualification question, not a crisis. The tenant is telling you what they need to sign. Your job is to determine whether you already have it, whether you can assemble it quickly, and whether the gap is real or just paperwork.
What does "proof of backup testing" actually mean?
Backup testing is not the same as a backup job that ran successfully. A backup software report saying "completed without error" is not evidence that data can be recovered when it matters. A tenant asking for proof of backup testing is generally looking for one or more of the following:
- A recent restore test log showing what was recovered, from which system, and whether the recovered data matched expectations.
- A written backup and disaster recovery plan that describes what is backed up, how often, where copies live, and who is responsible for testing - covered in more depth under our disaster recovery planning service.
- Evidence of a regular testing cadence - quarterly, semi-annual, or annual - depending on the tenant's risk appetite and the systems involved.
- For co-working operators running shared infrastructure - badge access systems, network core devices, camera recording platforms - evidence that those systems are covered, not just the front office file server.
The depth they want depends on what you are actually safeguarding for them. If you are hosting a private office tenant that stores its own data on its own equipment behind its own VLAN, your obligation may be limited to proving the building's shared systems are backed up and tested. If you are running managed IT or managed print services on their behalf, the bar is higher, and you should be honest about that distinction before you promise anything - the scope of your data backup and recovery services determines what you are actually on the hook for.
A useful distinction is the one we make on our Built, Wired & Secured podcast around ownership of outcomes rather than ownership of equipment: a backup power system fails when no one owns the testing, the transfer sequence, and the operational documentation - not when the generator itself breaks. The same is true for backup testing. A log that reads "restored sample file from Tuesday backup, confirmed intact, date, name" is worth more than a twelve-page plan nobody has actually acted on.
A single, well-documented restore test - one clean recovery of a representative data set, dated and signed off - frequently satisfies an enterprise tenant's backup testing requirement, because the ask is usually evidence of a real process, not a mandated number of tests per year.
If you do not have a restore test log, you can produce one. Pick a representative data set, restore it to an isolated location, verify the contents match, date and sign the result, and save it where you can find it again. That single exercise, properly documented, often clears the requirement.
What does "security awareness training" documentation look like in a co-working context?
When a tenant asks for security awareness training documentation, the first question is whose training they are asking about - because the answer changes what you need to produce. The likely candidates are:
- Your own staff who touch the building's shared systems - front desk, network operations, badge access administration, camera system management.
- Any managed services team you have engaged that logs into tenant-facing systems on your behalf.
- In some cases, tenants want to see that you require or facilitate security awareness training for member companies that connect to a shared network segment - though that is less common and harder to enforce contractually.
For most co-working situations, the tenant is checking whether you run a baseline phishing and security awareness program for your own people. That typically means a training platform with completion records, an annual or semi-annual cadence, and ideally some evidence of simulated phishing tests. If you cannot produce completion records, the gap is real and you should remediate before the tenant's deadline - not explain it away as "we will get to it." Our cybersecurity services practice can help an operator stand up that program with completion reporting if it is not already in place.
The tenant may also be indirectly asking whether your environment is segmented well enough that one person's mistake cannot reach their data. That is where multi-tenant network design becomes part of the answer: separate SSIDs, VLANs, guest isolation, captive portal, and bandwidth shaping. A tenant is more comfortable signing when they can understand, in a thirty-minute call, that your guest network cannot reach their private office traffic and that your staff's management access is constrained to the systems it actually needs.
The physical layer matters here too. If your camera and access control systems run on the same network as member traffic with no segmentation, a tenant with a security team will notice - and they will ask about it. Designing those systems with their own pathways and telecom room discipline is the kind of upfront work that prevents awkward conversations at lease signing, as we covered in our piece on physical security network design that holds up.
The practical takeaway: know whose training completion records you can produce on demand, what cadence you run, and whether your network segmentation is documented well enough that a tenant's IT contact can understand it without a whiteboard session.
How do we gather and package this documentation without disrupting daily operations?
The sensible sequence is to scope the ask, inventory what exists, fill the real gaps, and package it - in that order. Do not start by writing a narrative for the tenant. Start by asking your team what they already have.
Step one is to ask the tenant for the exact standard. Is there a vendor security questionnaire? A specific backup test frequency? A training platform they accept? A list of acceptable evidence formats? The answer may be "attach whatever you have" - which is easy - or it may be a multi-page checklist. You cannot plan the work until you know the target.
Step two is to inventory existing records. Pull your backup software's job history, any restore test logs, your DR plan document, and any incident or test reports from the last twelve months. If your backup platform runs automated verification, that counts as part of the picture. For training, export completion reports for the relevant staff group from whatever platform you use, or confirm that you do not yet have that program in place - and decide what to do about it.
Step three is to confirm your network segmentation in writing. A one-page diagram or description showing how guest, member, management, camera, and access control traffic are separated goes a long way when a tenant's IT contact is evaluating your environment. If you need to build that diagram from memory, that is itself a sign the documentation gap is real and worth closing before the next tenant screening - and is exactly the kind of thing our IT compliance services team helps document in a form an auditor or tenant IT contact will accept.
Step four is to package and date everything. A clean folder with a cover note, dated evidence, and a named contact who can answer follow-up questions is usually enough to move the deal forward. The tenant's team does not need a binder - they need confidence that the practice exists and that someone is responsible for it.
The timeframe is rarely as tight as it feels. Most procurement reviews give you a few business days to a week. If you need to produce a restore test and you do not have one on hand, you can schedule and execute one within a day or two and document the result cleanly. If you need a security awareness program, the gap is bigger - but you should know that before you promise a date, not after.
The practical takeaway: most backup testing and training documentation requests clear in days, not weeks, provided you know what exists, are honest about what does not, and package it cleanly.
When should a co-working operator bring in outside IT or compliance help?
Bring in help sooner than you think if any of these are true: you are not sure whether your backup coverage includes the systems a tenant would reasonably expect; you cannot produce a network segmentation diagram without reconstructing it from memory; you do not run any security awareness training at all; or the tenant's questionnaire touches regulated data handling - PCI, HIPAA, CMMC, or FTC Safeguards - and you are not sure which rules apply to the services you are actually providing.
A managed IT partner familiar with co-working and commercial real estate environments can help you scope what backup coverage you actually need for the systems you operate, build a restore test cadence that produces evidence on a schedule, stand up a security awareness program with completion reporting, and document your network segmentation in a form a tenant's IT contact will accept. That is not about looking bigger than you are - it is about making sure the documentation you hand over is accurate and defensible when the tenant's risk team reviews it.
If the tenant is also asking about physical security - camera coverage, badge access, visitor management - those are separate but related conversations, and the same principle applies: evidence beats assurances. A site with documented access control discipline and a clear owner for each system is easier to trust than one that describes its security verbally.
Norcross operators sit in a corridor where regulated tenants are common enough that this is not a one-off exercise. Building a habit of dated backup tests, completion records, and a clean one-page network description is the kind of quiet infrastructure that makes the next tenant screening faster - and that is the point: you want the second and third requests to take hours, not days.
The practical takeaway: if the gap is documentation rather than capability, you can close it quickly. If the gap is that you are not doing the underlying practice, start there before the tenant deadline - and decide whether a managed partner is the fastest path to doing it correctly.
Frequently Asked Questions
What if we do not currently perform documented backup restore tests?
Start with one clean restore test of a representative data set, document the date, the data restored, and the verification step, and save that record where you can find it. One well-documented test is often enough to satisfy an enterprise tenant's evidence-of-process requirement while you build a regular cadence. The goal is to show the practice exists and is executable, not to produce a years-long log you do not have.
How often should backup testing actually happen?
The right cadence depends on the data and the systems involved. Critical infrastructure - access control, network core, surveillance retention - should be tested at least quarterly. General file backup restore tests often run monthly or quarterly depending on risk. The tenant's standard, if they have one, may specify a frequency; if they do not, quarterly for critical systems is a defensible default to document and communicate.
Does a co-working space need security awareness training for tenants?
Usually not as a condition of the lease, but it can be a service differentiator if you choose to offer it. Most tenants are responsible for training their own staff. What they want from you is evidence that your own team is trained and that your shared network is segmented so that one tenant's exposure does not reach another's. Some operators offer training as a member benefit - that is a choice, not a requirement.
What if the tenant's questionnaire asks about PCI, HIPAA, or CMMC compliance?
Answer only what is true for the services you actually provide. If you are not handling payment card data, protected health information, or controlled unclassified information on their behalf, say so directly and point to the scope of your services. If you are providing managed services that touch any of those data types, that is a different conversation, and you should confirm your compliance posture before signing anything that implies otherwise - the scope of what you handle determines which frameworks apply, and our IT compliance services can help you map that honestly before a tenant's risk team forces the question.
Can we negotiate the documentation requirement instead of fulfilling it?
Sometimes. If the tenant's standard is internally driven and not legally mandated, a conversation with their procurement or IT contact may produce a narrower evidence set - for example, a one-page backup summary instead of a full restore test log. Do not assume the ask is negotiable, but do ask before you spend time assembling evidence they may not actually need.
What is the fastest way to prove our backup testing is legitimate?
The fastest legitimate proof is a dated restore test log showing a specific recovery from a specific backup set, with a verification step and a name on it. If you have automated backup verification, include that as supporting evidence. Do not substitute a policy document for a test result - the tenant is asking whether the recovery has been demonstrated, not whether it is written down that it should be.