Five questions to ask after your last disaster recovery test

07/08/26 Wavenet
Disaster recovery testing

Completing a disaster recovery (DR) test can provide valuable reassurance that your recovery plans work as expected. But in modern IT environments, testing isn't the finish line. It's a point-in-time validation.

From cloud migrations and software as a service (SaaS) adoption to infrastructure upgrades and supplier changes, technology environments evolve continuously. The challenge is that every change has the potential to affect recovery processes, dependencies, and priorities.

That's why you should look beyond whether a test was successful and ask a more important question: Does our recovery strategy still reflect the environment we're operating today?

In our recent blog, "Why annual disaster recovery testing is no longer enough", we explored why a single annual exercise falls short of providing sufficient assurance in modern IT environments. This article builds on that discussion by providing five practical questions to help you assess whether your recovery plans still reflect the systems, services, and dependencies your business relies on today. It can also act as a useful disaster recovery assessment and support a wider disaster recovery plan review process.

Use the five questions below as a practical self-assessment to help identify whether additional testing, validation, or review may be needed.

1. What significant technology changes have taken place since your last disaster recovery test?

Technology rarely stands still. Since your last disaster recovery exercise, you may have upgraded applications, migrated workloads, introduced new integrations, moved systems to the cloud, or retired legacy platforms. Each change can alter how systems interact and how they need to be recovered.

Even if recovery was successful during your previous test, those results may no longer accurately represent your current environment.

Ask yourself:

  • Have any critical systems been upgraded or replaced?
  • Have new integrations been introduced?
  • Has infrastructure been migrated or modernised?
  • Have any applications been retired?

Reviewing technology changes is an important part of any disaster recovery assessment and helps ensure your recovery strategy reflects your current environment.

2. Have you added new cloud or SaaS applications since your last disaster recovery test?

Cloud and SaaS adoption continue to reshape how businesses operate. From collaboration platforms and CRM systems to industry-specific applications and business-critical services, you're likely to be relying on a growing number of cloud-based tools to support day-to-day operations. As these environments expand, it's important to ensure your cloud disaster recovery strategy evolves alongside them.

Effective cloud disaster recovery planning requires you to understand how applications, data, backups, and dependencies can be recovered across cloud, hybrid, and on-premises environments.

A common misconception is that cloud services are automatically protected, while in reality, backup, recovery, retention, and resilience responsibilities remain shared.

Consider:

  • Have any new SaaS platforms been introduced?
  • Are they included in your recovery plans?
  • Have backup and recovery requirements been assessed?
  • Are dependencies between cloud and on-premises systems fully understood?

If the answer is unclear, it may be time to revisit your recovery strategy.

3. Have your business priorities changed since your last disaster recovery plan review?

Business priorities evolve over time. Applications or services that were once considered non-critical may now support revenue generation, customer service, remote working, or operational delivery. Equally, systems that previously required rapid recovery may no longer be business critical.

This can have a direct impact on:

  • Recovery time objectives (RTO)
  • Recovery point objectives (RPO)
  • Recovery sequences
  • Resource allocation during an incident

A recovery plan is only effective if it aligns with current business priorities. Regular reviews are a core disaster recovery best practice and help ensure recovery objectives continue to meet business requirements.

Ask yourself:

  • Would we recover the same systems in the same order today?
  • Do current RTOs still meet business requirements?
  • Have critical business processes changed?

If priorities have shifted, recovery plans need to evolve alongside them.

4. Are supplier and cloud dependencies still understood and documented for recovery testing?

The growing reliance on suppliers, cloud services, and external partners means critical dependencies can change quickly and become difficult to track without regular review.

Today's business services often rely on a combination of:

  • Cloud providers
  • SaaS vendors
  • Connectivity suppliers
  • Managed service providers
  • Data centres
  • Internal teams

This is becoming increasingly important as many business-critical services now rely on a combination of internal teams, cloud providers, connectivity partners, SaaS vendors, and managed service providers. A recovery plan is only as strong as the dependencies that support it.

Consider:

  • Are supplier dependencies documented?
  • Have any suppliers changed since the last test?
  • Do recovery plans include third-party responsibilities?
  • Are supplier contacts still current and accessible?
  • Could key teams begin recovery without significant preparation?

Understanding dependencies remains an important part of maintaining resilience.

5. Would you be confident in your disaster recovery readiness if an incident happened today?

A recovery plan may have been successful during the last exercise, but how confident are you that it reflects your current environment?

Applications change, suppliers evolve, teams move on, and business priorities shift. The longer it's been since your last review or test, the greater the chance that recovery procedures, contacts, dependencies, or recovery priorities may no longer be fully aligned with reality.

Ask yourself:

  • Are recovery procedures still accurate and up to date?
  • Have contact lists been reviewed recently?
  • Would recovery priorities reflect current business needs?
  • Has the plan been validated since major changes were introduced?

Confidence comes from regular recovery testing, validation, and review, rather than simply knowing a successful exercise took place months ago. Ongoing recovery testing helps strengthen disaster recovery readiness and supports wider resilience objectives.

What your answers could be telling you

Change is a natural part of business and technology. Your answers to these questions may have highlighted gaps where change hasn't been factored in, meaning that your recovery plans would benefit from additional recovery testing, validation, a formal disaster recovery assessment, or a structured disaster recovery plan review.

The goal isn't to repeat full-scale disaster recovery exercises every month. Instead, it's about maintaining confidence that your recovery capabilities remain aligned with your current systems, dependencies, and business priorities.

As we've explored throughout this resource, even relatively small changes can have an impact on disaster recovery readiness. New applications, evolving supplier relationships, infrastructure updates, and changing business priorities can all influence how effectively systems and services can be recovered during an incident.

We recommend the practice of complementing annual disaster recovery exercises with ongoing validation activities that provide greater visibility and assurance throughout the year.

If you're unsure whether your recovery plans still reflect your current operating environment, our business continuity and disaster recovery specialists can help. From reviewing recovery strategies and validating critical dependencies to supporting testing programmes and resilience exercises, we work with organisations to build confidence that recovery plans will perform when they're needed most.

Frequently asked questions about disaster recovery testing

How often should a disaster recovery plan be tested?

There is no single answer. The right frequency depends on the importance of the systems being protected and the rate of change within the environment. It's good practice to combine annual disaster recovery exercises with quarterly testing, regular backup validation, and reviews following significant changes.

What's the difference between disaster recovery testing and business continuity testing?

Disaster recovery testing focuses on restoring systems, applications, and data following an incident. Business continuity testing has a broader scope, validating how people, processes, suppliers, communications, and technology work together to maintain operations during disruption.

What should be included in a disaster recovery test?

A comprehensive disaster recovery test should validate:

  • Recovery procedures
  • Backups and data recovery
  • Recovery time objectives (RTO)
  • Recovery point objectives (RPO)
  • Critical dependencies
  • Third-party supplier involvement
  • Communications processes
  • Escalation procedures
When should a disaster recovery plan be reviewed?

A disaster recovery plan review should take place after significant technology, business, or supplier changes, as well as following recovery exercises, incidents, major infrastructure projects, or changes to recovery requirements. Regular reviews are considered a disaster recovery best practice because they help ensure recovery plans remain accurate and effective.

Does moving to the cloud remove the need for disaster recovery testing?

No. While cloud platforms provide resilience factors, you still retain responsibility for many aspects of recovery planning, including data protection, application recovery, supplier dependencies, business continuity processes, and validating that critical services can be restored within required recovery timeframes.

Cloud adoption can improve resilience, but it can also introduce additional dependencies that need to be understood, documented, and tested. Regular cloud disaster recovery testing helps ensure that cloud, SaaS, hybrid, and on-premises environments can work together effectively during a disruption while maintaining strong disaster recovery readiness.

Not sure how your answers stack up?

If any of these five questions left you unsure, that's a sign your recovery plan could use a closer look. Our disaster recovery specialists can run a full assessment against your current systems, suppliers, and priorities, not just the environment you tested last year.