Quarterly report
Recovery Test Report
Harbour & Finch LLP · Q3 2026
Results against targets
| Service | Recovery time target | Achieved | Data loss target | Achieved | Result |
|---|---|---|---|---|---|
| Practice management system | 4 h | 2 h 40 m | 1 h | 15 m | Passed |
| Document management | 4 h | 3 h 10 m | 1 h | 30 m | Passed |
| Microsoft 365 mailbox restore | 8 h | 1 h 05 m | 24 h | 4 h | Passed |
| Finance system | 24 h | 6 h 20 m | 24 h | 12 h | Action |
How we tested
Each service was restored from its backups into an isolated environment, so live systems were not affected. We timed each step and asked the service owner to confirm that the restored service worked.
Evidence collected
- Backup job logs for each service
- Restore timings, recorded at each step
- Data integrity check results
- Sign-off from the business owner of each service
- Screenshots of the restored services in use
Finding
Finance system: bank feed did not reconnect
The finance system was usable 6 hours and 20 minutes after the test started, well inside its 24-hour target. Staff could post transactions, but bank transactions could not import until the bank feed was set up again by hand.
Test timeline, 17 September
- Test started. Latest backup selected from the finance system backup vault.
- Server and database restored into an isolated recovery environment.
- Data integrity checks passed. Ledgers and invoices matched the source system.
- Staff from the finance team confirmed they could log in and post transactions.
- Bank feed failed to reconnect. The API token for the bank was not in the backup.
- Test closed. Service usable without the bank feed. Action raised.
Cause
The bank feed uses an API token that was stored only on the original server, outside the backed-up data. The recovery runbook did not include a step to restore it.
Impact in a real outage
The finance team would work without automatic bank imports for about one day, until the bank issued a new token. Payments and invoicing would continue.
Actions
| Action | Owner | Due |
|---|---|---|
| Store the bank feed API token in the shared secrets vault | IT provider | 31 Oct |
| Add the token restore step to the finance system recovery runbook | Elmfort | 31 Oct |
| Retest the finance system recovery, including the bank feed | Elmfort | 28 Nov |