The most common mistake is confusing the existence of a backup with the ability to restore. The data is there, but nobody checked it actually returns.
That is why our backups always have three parts: a clear policy, a regular restore test, and an owner who is accountable for it.
The result is simple: on the day of an incident we do not start by asking whether it will work - we start a rehearsed plan.