Regular backups
Regular backups protect the data your business runs on, but only if the backups themselves are protected from tampering and actually tested. A backup that ransomware can encrypt, or one you have never restored, gives false comfort. This control covers how often you back up, how those backups are protected, and whether restoring them has been tested. The Essential 8 does not set one fixed schedule, such as daily backups, for every business; instead it ties backup frequency to how critical the data is and your business continuity needs, so a daily job for one system and a weekly job for a less critical one can both meet it.
It is control 8 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Backups decide whether a ransomware incident is an inconvenience or a catastrophe. Insurers commonly ask how your backups are protected from deletion, how often they run relative to the data's importance, and when you last tested a restore.
Maturity Level 1: the baseline
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Do you back up your important data, applications and settings regularly, in line with how critical they are to the business?
ACSC requirement: “Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.”
Are backups stored securely and resiliently (for example an offsite or cloud copy that would survive ransomware or fire)?
ACSC requirement: “Backups of data, applications and settings are retained in a secure and resilient manner.”
Have you tested restoring your data from backups (a disaster recovery test)?
ACSC requirement: “Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.”
Are normal (non-admin) staff accounts prevented from changing or deleting backups?
ACSC requirement: “Unprivileged user accounts are prevented from modifying and deleting backups.”
Maturity Level 2: the common target
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Are admin accounts (other than dedicated backup admins) prevented from accessing other users' backups?
ACSC requirement: “Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.”
Maturity Level 3: advanced
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Are even backup admin accounts prevented from changing or deleting backups during their retention period?
ACSC requirement: “Backup administrator accounts are prevented from modifying and deleting backups during their retention period.”
These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).