An untested DR plan is not a plan
A significant share of organisations that invest in disaster recovery never test the scenario. An untested plan is not a plan.
Building a disaster recovery site is an investment decision. What we see in the field, however, is this: the investment is made, replication is configured, and then it is never tested again for years.
Why does testing not happen? Because a drill looks like putting production at risk. The real risk is discovering during your first genuine outage that the scenario does not work.
The problems we encounter most often in untested plans:
Replication has quietly stopped months ago. Without monitoring in place, nobody notices.
The application server comes up but cannot reach the database, because the IP plan and DNS records at the secondary site were never updated.
The licence server was left out of DR scope; applications start but fail because licence validation cannot complete.
Systems come online, but the VPN and firewall rules users need to reach the secondary site were never defined.
The failback scenario was never considered. When the primary site recovers, nobody knows how to move back.
How should a drill be run? At least annually, on a pre-announced date, following a written step-by-step scenario. Each step should be timed and compared against the RTO target. The gaps that emerge become an action list to close before the next drill.
Several sector regulations already mandate regular drills and reporting. But the real reason is not the auditor: an untested disaster recovery plan is insurance that exists on paper and fails when you need it.