Skip to content

Regular backups

Regular backups protect the data your business runs on — and, crucially, they must be protected from tampering and actually tested. A backup that ransomware can encrypt, or that has never been restored in practice, gives false comfort. This control covers backup cadence, protection, and tested restoration.

It is control 8 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.

Why this Essential 8 control comes up with insurers

Backups determine whether a ransomware incident is an inconvenience or a catastrophe, so insurers commonly ask how backups are protected from deletion and when restoration was last tested.

Maturity Level 1 — the baseline

Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:

  • Do you back up your important data, applications and settings regularly, in line with how critical they are to the business?

    ACSC requirement: “Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

  • Are backups stored securely and resiliently (for example an offsite or cloud copy that would survive ransomware or fire)?

    ACSC requirement: “Backups of data, applications and settings are retained in a secure and resilient manner.

  • Have you tested restoring your data from backups (a disaster recovery test)?

    ACSC requirement: “Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.

  • Are normal (non-admin) staff accounts prevented from changing or deleting backups?

    ACSC requirement: “Unprivileged user accounts are prevented from modifying and deleting backups.

Maturity Level 2 — the common target

Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:

  • Are admin accounts (other than dedicated backup admins) prevented from accessing other users' backups?

    ACSC requirement: “Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.

Maturity Level 3 — advanced

Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:

  • Are even backup admin accounts prevented from changing or deleting backups during their retention period?

    ACSC requirement: “Backup administrator accounts are prevented from modifying and deleting backups during their retention period.

These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).