Regular backups
Regular backups protect the data your business runs on — and, crucially, they must be protected from tampering and actually tested. A backup that ransomware can encrypt, or that has never been restored in practice, gives false comfort. This control covers backup cadence, protection, and tested restoration.
It is control 8 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Backups determine whether a ransomware incident is an inconvenience or a catastrophe, so insurers commonly ask how backups are protected from deletion and when restoration was last tested.
Maturity Level 1 — the baseline
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Do you back up your important data, applications and settings regularly, in line with how critical they are to the business?
ACSC requirement: “Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.”
Are backups stored securely and resiliently (for example an offsite or cloud copy that would survive ransomware or fire)?
ACSC requirement: “Backups of data, applications and settings are retained in a secure and resilient manner.”
Have you tested restoring your data from backups (a disaster recovery test)?
ACSC requirement: “Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.”
Are normal (non-admin) staff accounts prevented from changing or deleting backups?
ACSC requirement: “Unprivileged user accounts are prevented from modifying and deleting backups.”
Maturity Level 2 — the common target
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Are admin accounts (other than dedicated backup admins) prevented from accessing other users' backups?
ACSC requirement: “Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.”
Maturity Level 3 — advanced
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Are even backup admin accounts prevented from changing or deleting backups during their retention period?
ACSC requirement: “Backup administrator accounts are prevented from modifying and deleting backups during their retention period.”
These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).