Man calmly completing IT tasks successfully while chaotic server failure occurs behind him with lightning and fire damage.

How Often Should a CPA Firm Test Its Backups and Disaster Recovery Plan?

August 05, 2026

A CPA Firm Should Review Backups Daily and Perform Recovery Tests at Least Quarterly

A CPA firm should monitor critical backup jobs every business day, perform sample file-restoration tests monthly, test critical application or server recovery quarterly, and conduct a full disaster-recovery exercise at least annually.

Firms with 25–50 employees, strict client deadlines, or a high dependence on tax and document-management systems may need more frequent testing. Recovery procedures should also be tested after major software migrations, server replacements, cloud changes, office moves, or significant security incidents.

The objective is not merely to confirm that a backup job completed. The firm must verify that its data is usable, its systems can be restored, employees can resume critical workflows, and recovery can occur within an acceptable timeframe.

Why Successful Backup Notifications Are Not Enough

A backup dashboard may show a green status even when the firm cannot restore the information it needs. A completed job confirms that data was copied somewhere. It does not necessarily confirm that:

  • The correct systems and folders were included.
  • Tax databases are consistent and usable.
  • Microsoft 365 data is protected.
  • Backup copies are isolated from ransomware.
  • Encryption keys and credentials are available.
  • The retention period is long enough.
  • The recovery environment has enough capacity.
  • The firm can restore systems before a filing deadline.

Recovery testing turns a technical assumption into evidence. It shows whether the firm can retrieve information after accidental deletion, equipment failure, ransomware, cloud disruption, or a larger disaster.

The 911 IT Five-Level CPA Backup Testing Framework

A reliable backup program should include five different levels of review and testing. Each level answers a different question about recovery readiness.

Level 1: Daily Backup Monitoring

Critical backup jobs should be reviewed every business day. Automated alerts can identify failures, but a qualified technician should investigate exceptions and confirm that corrective action was completed.

Daily monitoring should review:

  • Job completion status
  • Devices or systems that did not report
  • Unusual changes in backup size
  • Storage capacity
  • Authentication or connectivity failures
  • Retention and replication status
  • Malware or security alerts affecting backup systems
  • Repeated warnings that may indicate a developing problem

A failed backup should not remain unresolved for several days. The provider should document the cause, remediation, and whether a successful backup was completed afterward.

Level 2: Monthly File and Folder Restoration

At least once per month, restore a selection of files and folders from different systems and recovery points.

The test should confirm that:

  • The requested file can be located.
  • The correct version can be selected.
  • The restored file opens successfully.
  • Permissions remain appropriate.
  • The recovery time is reasonable.
  • The result is documented.

Test several file types relevant to CPA workflows, such as spreadsheets, PDFs, tax documents, scanned source records, email, and shared-office files.

Sample testing is valuable, but it should not replace application and server recovery. Restoring one PDF does not prove that a tax application database or document-management system can be returned to service.

Level 3: Quarterly Application and Server Recovery Testing

Critical applications and infrastructure should be recovery-tested at least quarterly. The exact method depends on whether the firm uses local servers, cloud-hosted applications, virtual machines, or a combination of platforms.

Quarterly tests may include:

  • Restoring a server into an isolated test environment
  • Recovering a tax application database
  • Validating document-management data
  • Testing file shares and permissions
  • Restoring Microsoft 365 email or files
  • Testing a virtual server failover
  • Confirming application licensing and vendor dependencies
  • Measuring the time required to restore service

The restored system should be checked by someone who understands the business workflow. A technician may confirm that a server starts, while a tax professional verifies that client records can actually be opened and used.

Level 4: Annual Disaster-Recovery Exercise

At least once per year, the firm should simulate a major disruption affecting several systems or the entire office.

A disaster-recovery exercise should test:

  • Emergency contact information
  • Decision-making authority
  • Recovery priorities
  • Backup access
  • Alternative infrastructure
  • Remote-work procedures
  • Vendor coordination
  • Employee communication
  • Estimated recovery time
  • Return-to-normal procedures

The exercise does not always require shutting down production systems. Many firms can test recovery in an isolated environment or use a tabletop exercise combined with technical restoration.

Level 5: Event-Driven Testing

Backup and recovery procedures should be retested after significant changes, even when the next scheduled test is several months away.

Events that should trigger additional testing include:

  • Replacing a server
  • Migrating applications to the cloud
  • Changing backup products or providers
  • Moving offices
  • Adding a new tax or document-management platform
  • Changing Microsoft 365 configurations
  • Experiencing a security incident
  • Discovering a failed or incomplete recovery
  • Adding a new office or large group of employees
  • Changing data-retention requirements

Testing after a major change confirms that the new environment is included in the recovery strategy and that old assumptions remain valid.

A Practical Backup Testing Schedule for a 25–50 Employee CPA Firm

Frequency Recommended activity Primary objective
Daily Review backup job status and investigate failures Confirm scheduled backups are completing
Weekly Review storage, retention, replication, and unresolved alerts Identify developing capacity or configuration issues
Monthly Restore representative files, folders, email, and cloud data Verify that individual information can be recovered
Quarterly Restore critical applications, databases, or servers Validate system-level recovery and measure timing
Annually Conduct a disaster-recovery and business-continuity exercise Test the complete people, process, vendor, and technology response
After major changes Repeat affected recovery tests Confirm new systems and configurations are protected

What Data and Systems Should a CPA Firm Back Up?

The backup inventory should include every system that stores information or supports a critical business workflow. Do not assume that a cloud vendor automatically provides the level of backup and retention the firm needs.

A CPA firm may need to protect:

  • Tax preparation databases
  • Accounting and bookkeeping data
  • Document-management systems
  • Scanned source documents
  • Client portal information
  • File servers and shared folders
  • Microsoft 365 email
  • SharePoint and OneDrive files
  • Teams data
  • Practice-management systems
  • Payroll information
  • Virtual servers
  • Application configurations
  • Network and firewall configurations
  • Encryption keys and recovery information
  • Critical workstation data that is not stored centrally

The firm should maintain a written inventory showing which system protects each data source, how often it runs, how long information is retained, and who is responsible for recovery.

What Is the Difference Between Backup, Disaster Recovery, and Business Continuity?

These terms are related, but they do not mean the same thing.

Backup

A backup is a separate copy of data that can be used to restore information after deletion, corruption, hardware failure, or an attack.

Disaster Recovery

Disaster recovery is the process of restoring technology systems and applications after a major interruption.

Business Continuity

Business continuity explains how the firm will continue serving clients while technology, facilities, employees, or vendors are disrupted.

For example, a backup may contain a tax database. Disaster recovery restores the database and application to working infrastructure. Business continuity determines how employees access the restored system, communicate with clients, prioritize deadlines, and continue working while the primary office remains unavailable.

Review business continuity services to learn how backup, recovery, redundancy, and operational planning work together.

How Much Data Can the Firm Afford to Lose?

The recovery point objective, or RPO, defines the maximum acceptable amount of recent data loss measured in time.

For example:

  • An RPO of 24 hours means the firm could lose up to one business day of changes.
  • An RPO of four hours means backups or replication must capture information at least every four hours.
  • An RPO of 15 minutes requires significantly more frequent protection.

During tax season, a 24-hour RPO may be unacceptable for systems where dozens of employees continuously update client records. The firm should establish separate objectives for different systems based on business impact.

System Illustrative RPO Reason
Tax preparation database 15 minutes–4 hours Frequent changes and filing deadlines
Document-management system 1–4 hours High volume of client documents
Microsoft 365 email 1–24 hours Depends on communication and retention requirements
Archived records 24 hours Information changes less frequently

These ranges are planning examples. The appropriate objective depends on the firm’s workflows, risk tolerance, technology, and contractual or compliance requirements.

How Quickly Must Critical Systems Be Restored?

The recovery time objective, or RTO, defines how long a system can remain unavailable before the disruption becomes unacceptable.

A CPA firm may establish objectives such as:

  • Email restored within four hours
  • Tax software restored within two hours during peak season
  • Document-management access restored within four hours
  • Archived systems restored within one or two business days

Recovery objectives should be based on operational impact rather than technical preference. Leadership should consider:

  • Number of employees affected
  • Billable time lost per hour
  • Client deadlines
  • Availability of manual alternatives
  • Vendor recovery capabilities
  • Cost of faster recovery technology

If 40 employees cannot access a critical system for four hours, the incident consumes 160 employee-hours. A faster recovery design may cost more each month but reduce a much larger interruption.

How Should Microsoft 365 Be Backed Up?

CPA firms often store important information in Exchange Online, SharePoint, OneDrive, and Teams. The firm should determine whether native Microsoft retention and recovery options are sufficient for its operational and recordkeeping needs.

A separate Microsoft 365 backup service may provide:

  • Longer retention periods
  • Point-in-time recovery
  • Restoration after accidental or malicious deletion
  • Recovery of former employee data
  • Search across mailboxes and files
  • Protection from administrative mistakes
  • Independent recovery when an account is compromised

Monthly testing should include restoring representative email, OneDrive files, and SharePoint documents. The provider should also document how data is preserved after an employee leaves the firm.

How Should Backups Be Protected From Ransomware?

Ransomware can target backup systems to prevent recovery. A resilient design should prevent one compromised administrator account or infected network from deleting every recovery copy.

Backup protections may include:

  • Immutable storage
  • Offline or logically isolated copies
  • Separate administrative credentials
  • Multi-factor authentication
  • Encryption
  • Restricted network access
  • Deletion protection
  • Multiple retention points
  • Monitoring for unusual changes
  • Independent cloud replication

The firm should verify that backup administration is separated from ordinary employee accounts and that recovery information is available during a Microsoft 365 or network compromise.

Explore managed cybersecurity services for layered protection of identities, endpoints, email, cloud services, networks, and backups.

What Should Be Included in a Quarterly Recovery Test?

A quarterly test should follow a documented process and produce written evidence.

1. Define the Test Scenario

Select a realistic failure, such as:

  • The tax application server has failed.
  • A document database has become corrupted.
  • Ransomware has encrypted a file server.
  • A Microsoft 365 mailbox has been deleted.
  • The main office cannot be accessed.

2. Select the Recovery Point

Choose a backup version from a specific date and time. Confirm that the selected recovery point existed before the simulated corruption or attack.

3. Restore in an Isolated Environment

When possible, perform the test without affecting production. Isolated testing helps prevent conflicts and allows the team to examine restored systems safely.

4. Validate the Information

Confirm that:

  • The system starts successfully.
  • The application launches.
  • Users can authenticate.
  • Client records can be opened.
  • Permissions remain correct.
  • Recent transactions or documents are present.
  • No corruption is detected.

5. Measure the Recovery Time

Record the time required to locate the recovery point, restore the system, validate the application, and make it available to users.

6. Document Problems and Improvements

Record missing credentials, slow downloads, licensing problems, application errors, vendor delays, capacity shortages, and procedural gaps.

Each improvement should have an assigned owner and target completion date.

What Should an Annual Disaster-Recovery Exercise Test?

An annual exercise should test more than technology. It should evaluate whether the firm’s people, vendors, communication methods, and decision-making procedures can support recovery.

A realistic scenario might state:

The CPA firm’s primary server and network are unavailable on a Monday morning during tax season. The office cannot be accessed for 48 hours, and 35 employees need tax software, email, and client documents.

The exercise should answer:

  • Who declares the disaster?
  • Who contacts 911 IT and other vendors?
  • Which application is restored first?
  • How do employees receive instructions?
  • Where will employees work?
  • How will multi-factor authentication and secure access function?
  • How will clients receive updates?
  • How long will restoration take?
  • What information could be lost?
  • How will the firm return to its normal environment?

The result should be an updated recovery plan, not merely a discussion. Missing contact information, unclear roles, and untested assumptions should be corrected.

How Should Backup Testing Change During Tax Season?

Backup monitoring should become more stringent during periods of high activity. The firm may also need shorter recovery objectives because more employees are working and more client records are changing.

During tax season:

  • Review critical backup jobs daily.
  • Escalate failures immediately.
  • Confirm storage capacity more frequently.
  • Avoid unnecessary backup-system changes.
  • Verify that new seasonal users and systems are included.
  • Confirm after-hours recovery contacts.
  • Maintain recent recovery-test documentation.
  • Monitor for attempts to alter or delete backups.

Major disaster-recovery exercises are usually better scheduled before peak season. However, smaller restoration tests should continue so the firm does not assume protection is working for several months without verification.

Seven Common CPA Firm Backup Mistakes

1. Backing Up Files but Not Applications

Individual documents may be protected while databases, configurations, permissions, and application servers remain difficult to restore.

2. Assuming Cloud Applications Are Fully Protected

Cloud availability does not automatically provide the retention, point-in-time recovery, or independent backup the firm requires.

3. Keeping Every Backup on the Same Network

A security incident or administrative error may affect production systems and connected backups simultaneously.

4. Using Shared Administrator Credentials

Shared accounts reduce accountability and increase the risk that one compromised password can access or delete backup data.

5. Testing Only Once Per Year

Technology changes continuously. Quarterly system testing identifies problems sooner and provides more current evidence of recovery readiness.

6. Failing to Document Recovery Time

A successful restoration that takes three days may still fail the firm’s business requirements.

7. Excluding Employees From Testing

Technical recovery is incomplete until an authorized employee confirms that the restored application and data support the required workflow.

What Documentation Should the CPA Firm Receive?

The firm should have access to current documentation describing:

  • Protected systems and data
  • Backup frequency
  • Retention periods
  • Storage locations
  • Encryption and access controls
  • Recovery point objectives
  • Recovery time objectives
  • System recovery priorities
  • Vendor and emergency contacts
  • Recent test dates
  • Test results
  • Open remediation items
  • Responsible personnel

The documentation should use business language that firm leadership can understand. It should clearly identify any important system or cloud service that is not protected.

The 911 IT CPA Backup and Recovery Checklist

Backup Coverage

  • Tax application databases are included.
  • Document-management data is included.
  • Shared files are included.
  • Microsoft 365 protection has been evaluated.
  • Critical cloud applications have documented recovery options.
  • Network and application configurations are protected.
  • Excluded systems are documented.

Backup Security

  • Backup data is encrypted.
  • Administrative access uses multi-factor authentication.
  • Backup credentials are separate from daily user accounts.
  • At least one recovery copy is isolated or immutable.
  • Deletion and retention controls are enabled.
  • Backup security alerts are monitored.

Testing

  • Backup jobs are reviewed daily.
  • File restorations are tested monthly.
  • Critical systems are tested quarterly.
  • A full disaster-recovery exercise occurs annually.
  • Additional tests occur after significant changes.
  • Business users validate restored applications.

Recovery Planning

  • Recovery point objectives are documented.
  • Recovery time objectives are documented.
  • System priorities are approved by leadership.
  • Emergency contacts are current.
  • Remote-work procedures are tested.
  • Recovery results and problems are documented.
  • Corrective actions have owners and deadlines.

Real Client Scenario: Proactive Planning Protected Tax-Season Operations

One accounting-industry client worked with 911 IT to prepare remote-work and business-continuity procedures before they became urgently necessary. When employees needed to move out of the office during tax season, the firm already had a plan for secure access and continued operations.

“They are proactive and always looking towards the future to solve potential problems before they become actual problems.”

The value came from preparation rather than last-minute troubleshooting. Systems, access methods, responsibilities, and support procedures had been considered before the disruption occurred.

Backup and disaster-recovery testing follows the same principle. A documented, successful test before tax season is more valuable than discovering a recovery problem after critical systems have already failed.

How 911 IT Helps CPA Firms Protect and Recover Critical Data

911 IT provides managed IT services and recovery planning for CPA and financial firms that need dependable backups, responsive support, and measurable business continuity.

Services may include:

  • Daily backup monitoring
  • File and system restoration testing
  • Microsoft 365 backup
  • Server and application recovery
  • Immutable or isolated backup design
  • Ransomware-resistant protection
  • Recovery objective planning
  • Business impact analysis
  • Remote-work continuity
  • Annual disaster-recovery exercises
  • 24/7 technical support
  • Strategic technology planning

911 IT combines CPA-industry experience with cybersecurity-first technology management, local Salt Lake City-area support, 24/7 access to live technicians, vCIO guidance, and a 100% satisfaction guarantee.

Explore IT support for CPA and financial firms or read experiences from 911 IT clients.

Frequently Asked Questions

How often should a CPA firm check its backups?

Critical backup jobs should be reviewed every business day. Failures and unusual warnings should be investigated immediately.

How often should backup restoration be tested?

Test representative files monthly, critical applications or servers quarterly, and the complete disaster-recovery process at least annually.

Is one annual recovery test enough?

Usually not. An annual exercise is useful for the complete response, but monthly and quarterly tests identify technical problems sooner and provide more current evidence.

Should Microsoft 365 be backed up separately?

CPA firms should evaluate a separate backup based on retention, deletion recovery, former employee data, ransomware risk, and operational requirements. Native recovery features may not satisfy every need.

What is an immutable backup?

An immutable backup cannot be changed or deleted during a defined retention period, helping protect recovery copies from ransomware, compromised administrators, and accidental deletion.

How long should CPA firm backups be retained?

Retention depends on business, legal, contractual, insurance, and recordkeeping requirements. The firm should define separate retention periods for operational recovery and long-term records with appropriate advisors.

Who should verify a restored tax application?

An IT technician should validate the infrastructure, while an authorized employee familiar with the application should confirm that client records, permissions, and workflows function correctly.

Should backup testing occur during tax season?

Daily monitoring and smaller restoration tests should continue. Large exercises are usually scheduled before peak season unless a major system change or incident makes additional testing necessary.

What happens if a backup test fails?

Document the failure, identify its cause, correct the configuration or capacity issue, complete a new backup, and repeat the restoration test. Leadership should be informed when a critical system remains unprotected.

Does a backup guarantee business continuity?

No. Business continuity also requires working infrastructure, employee access, vendor support, communication procedures, recovery priorities, and alternative operating plans.

Test Recovery Before the Firm Has to Depend on It

A backup program is successful only when the CPA firm can restore usable data and return critical systems to operation within its required timeframe. Daily monitoring, monthly file restoration, quarterly system testing, and annual disaster-recovery exercises provide layered evidence that the plan works.

Testing also reveals missing data, outdated contacts, inaccessible credentials, slow recovery speeds, vendor dependencies, and procedural gaps while there is still time to correct them.

Schedule a discovery call with 911 IT to review your CPA firm’s backup coverage, recovery objectives, ransomware protection, and disaster-recovery testing schedule.