A household can have many backups and still miss the one file that matters. Automatic phone upload may omit messages. A laptop backup may skip an external photo library. A cloud folder may retain only a short version history. An encrypted archive may be intact but unusable because its recovery key is stored on the failed computer.

An overhead backup-audit workspace with a blank matrix of unlabeled rows and checkboxes, text-free category tabs, a pencil, a blank-display calculator, a closed laptop, a phone, a disconnected external drive, and a blank calendar card.
Audit what is actually backed up, not what you assume is: the gap is almost always the one folder you forgot existed.

This audit measures coverage, independence, and recoverability. It does not require opening every sensitive file or exposing passwords. Complete it from trusted devices during normal conditions. If ransomware, unknown access, or physical drive failure is suspected, stop attaching storage and use the ransomware stop rules.

Score the system by outcome

For each data set, assign:

  • 0 - unknown: nobody can confirm where it is or whether it is backed up;
  • 1 - fragile: one working copy or one unverified synchronized copy;
  • 2 - partial: a second copy exists but off-site, isolation, retention, or access is weak;
  • 3 - covered: independent local and off-site paths exist and recent status is known;
  • 4 - recoverable: coverage is complete and a representative restore was tested.

Do not average away a critical zero. One missing medical-device record, only copy of a family archive, or lost disk key can be more important than ten well-backed-up replaceable folders.

Step 1: Inventory data sets

Use one row per meaningful group:

Data set Owner Primary location Change rate Consequence if lost Score
current household records named adult restricted laptop folder monthly claim and recovery delay
new phone photos account holder phone/cloud library daily irreplaceable recent memory
completed family archive archive owner computer library occasional permanent loss
work or school files organization/user managed service daily income or deadline
care information caregiver secure record as needed urgent continuity
device recovery material device owner controlled separate location rare encrypted data lockout

Add messages, scans, application data, shared folders, external drives, old computers, camera cards, website files, and financial or tax records where relevant. Do not copy employer-managed data into personal storage merely to improve the score.

Step 2: Verify inclusion

For each backup system, answer from its current settings or status:

  • Which devices are enrolled?
  • Which user accounts are included?
  • Which folders and external drives are included or excluded?
  • Are online-only files downloaded or represented in the backup?
  • Are messages, contacts, health data, application data, and device settings included?
  • Does phone-photo synchronization preserve originals at expected quality?
  • Are shared folders owned by someone else retained if access disappears?
  • Are failed jobs and storage-capacity alerts visible to a named person?
  • What was the last successful date and time?

Do not infer inclusion because an application icon is present. Check the documented scope and a sample.

Step 3: Test independence

Mark which events can reach each copy:

Failure Working copy Local backup Off-site backup Offline access record
device theft affected? same bag or separate? independent account? separate custodian?
home fire or flood affected? same room? truly off-site? portable or off-site?
account lockout accessible? requires account? same account? contains start path?
ransomware writable? connected? versioned or isolated? clean and separate?
prolonged outage charged? powered device required? internet required? paper or powered?
household role change owner available? authorized successor? recovery contact current? access revoked or transferred?

The 3-2-1 method explains why two copies under one account, in one room, or continuously connected may share a failure domain.

Step 4: Review retention and version history

Record:

  • how frequently new copies or snapshots are created;
  • how long deleted files remain recoverable;
  • how many historical versions are retained;
  • what happens when storage is full;
  • whether a device deletion synchronizes immediately;
  • whether account closure or nonpayment removes backups;
  • whether the service can export data in usable formats;
  • how the household learns that backups stopped.

Retention can change with provider plans and settings. Verify current terms and product behavior; do not rely on memory or a marketing phrase such as “continuous backup.”

Also record the renewal date, storage quota, current plan owner, payment-failure notice path, and estimated cost of a full restore or mailed recovery device where the service offers one. Confirm that data can be exported in a usable form before account closure. A low monthly price is not continuity if the household cannot retrieve a complete, readable copy without the original account or device.

Step 5: Audit encryption and recovery

For every encrypted device, drive, archive, and backup:

  • identify the legitimate unlock method;
  • confirm recovery material is stored away from the protected device;
  • verify the key or reference belongs to the correct asset without displaying it in the worksheet;
  • confirm an authorized person knows how to start official recovery;
  • record whether the provider can help or explicitly cannot recreate the key;
  • review what happens after password, phone number, account, or organization changes;
  • remove obsolete keys only after replacement is confirmed.

Use the photos, documents, and recovery-keys guide and offline credentials guide. Do not place secret values in the audit sheet.

Step 6: Restore representative samples

Choose low-risk samples from every priority data class:

  1. restore to a separate temporary folder;
  2. select the intended historical version;
  3. open the file with the expected application;
  4. compare content, date, and basic metadata;
  5. note time, connectivity, application, cable, account, and key dependencies;
  6. record pass, partial, or fail;
  7. remove temporary copies securely when appropriate.

Test local and off-site paths on different dates. A successful local restore does not prove cloud recovery, and a cloud download from an already signed-in laptop does not prove recovery after that laptop is lost.

Step 7: Audit the human system

Ask:

  • Is one person the only one who understands every backup?
  • Can an authorized adult start recovery if that person is unavailable?
  • Are disability, language, dexterity, memory, and caregiving needs addressed?
  • Is employer, school, estate, or provider authority required?
  • Who receives failure alerts?
  • Who rotates offline storage?
  • Who documents changes after a new phone, computer, carrier, or cloud plan?
  • Is access removed when a household or work role ends?

Recovery access should be sufficient, not universal. Use provider-supported family, delegate, recovery-contact, legacy, or organizational features where available.

Turn findings into a 30-day queue

Prioritize in this order:

  1. irreplaceable data with score 0 or 1;
  2. encryption keys with no independent recovery path;
  3. primary email or password-manager lockout risks;
  4. backups that have not succeeded recently;
  5. copies sharing one device, room, or account;
  6. untested high-priority restoration;
  7. obsolete people, devices, phone numbers, and recovery contacts;
  8. replaceable low-consequence data.

Assign one owner and due date to each fix. Re-run the affected row after completion rather than marking it solved because equipment was purchased.

Quarterly audit record

Keep a short log with date, scope, rows changed, sample restores, failures, owner, and next review. Never paste passwords, keys, codes, complete financial numbers, or sensitive file contents into the log.

After a major operating-system upgrade, new phone, storage migration, account change, or household move, run the affected rows immediately instead of waiting for the quarterly date.

Use the digital continuity hub to connect audit findings to account recovery, MFA, offline access, ransomware, and power planning. Compare storage roles in the home data equipment guide.

Sources reviewed

  • CISA: How to Protect the Data Stored on Your Devices
  • NIST: Data Integrity and Ransomware Recovery Guidance
  • Federal Trade Commission: Five Ways to Keep Scammers and Hackers Away

Sources reviewed July 14, 2026. Provider scope, retention, encryption, authentication, and recovery features change. Verify current official documentation and organizational policy during every audit.