Backups of important data, software and configuration settings are performed and retained in accordance with business criticality and continuity requirements. Backups are performed and retained in a coordinated and resilient manner. Restoration from backups is tested.
Regular backups
Keeping copies of your important data somewhere safe, and regularly testing that you can actually restore them.
The case for it
What you lose without regular backups.
Ransomware exists. Hardware fails. People make mistakes. A tested backup is your last line of defence. Most businesses find out theirs doesn't work on the day they need it, so the testing is what decides whether you get your data back.
Where you need to be
What each maturity level asks of regular backups.
The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.
Unprivileged accounts can't access backups belonging to other accounts. Unprivileged accounts are prevented from modifying or deleting backups.
Privileged accounts (other than backup administrators) cannot modify or delete backups. Backup administrator accounts are prevented from accessing backups they administer without the involvement of another privileged account.
Not sure which level you should aim for?
Three questions about your regulatory position and the data you keep will point you at the right target.
Take the maturity pickerThe rollout
Setting up regular backups in your environment.
Backups cover your Microsoft 365 data (mailboxes, SharePoint, OneDrive, Teams), file servers or network storage, and line-of-business applications. Retention is tiered daily, weekly and monthly by how critical the data is. Restores are tested every quarter, not once a year. We pick a real file, restore it to a separate target, confirm it opens, and document the result. Backups are kept isolated from the account that administers them, so a compromised admin can't destroy them while encrypting everything else.
Free self-assessment
No email required.
Score yourself on all eight controls.
Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.
Take the self-assessmentAsked on client calls
Questions we get about regular backups.
- Doesn't Microsoft 365 already back up everything?
- No. Microsoft gives you retention, which is not the same thing. Delete a file and retention holds it for a set number of days, then it is gone. If ransomware encrypts a OneDrive, version history may or may not save you. A real backup is a separate copy in a separate system, with its own restore process and no reliance on your tenant being healthy.
- How often should we test restores?
- Quarterly, at the least. Annually isn't enough, because by the time you find the backup is broken, eleven months of changes have gone with it. Our Technology Success Program includes a documented restore test every quarter. You get the evidence, and so does your auditor.
- What's the ransomware angle on backups?
- Ransomware now targets backups specifically. If the attacker reaches an account that can delete or encrypt them, the whole strategy fails at the worst possible moment. Maturity levels 2 and 3 require backups to be isolated from privileged accounts, which is an architecture decision rather than a setting. We build them that way by default.
- How long would it actually take to restore our environment?
- A single mailbox or OneDrive takes minutes to hours. A full server takes hours to a working day, depending on how much data there is. Rebuilding a whole tenant after a catastrophic compromise takes days, sometimes a week. We document recovery time and recovery point targets for each class of data, so the numbers you give your board are real ones.
Where to go next
Essential Eight controls that work with regular backups.
Control 01
Application control
Only letting approved programs run on your computers. Everything else is blocked by default.
Read the controlControl 05
Restrict administrative privileges
Making sure only the people who need admin rights have them, and only when they need them.
Read the controlControl 07
Multi-factor authentication
Requiring something more than a password to log in: a code, a key, or an app.
Read the controlThe maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .
The qualifier
Let's see if we're a fit.
Seven questions, one moment of your time. We'd rather tell you now than three months in.