←All insights

essential eight

Essential Eight Backups: What "Regular and Tested" Actually Means

Regular backups of important data is the eighth Essential Eight control. The details — how often, stored where, retained for how long, and tested how — determine whether the control actually provides resilience in a ransomware incident.

Ryan BallootBy Ryan Balloot, Managing Director22 April 20242 min read
ByRyan Balloot22 April 20242 min read

Backups are the last line of defence against . They are also the control where the gap between "we have backups" and "we have effective backups" is most significant. Many businesses discover the quality of their backup program only when they try to recover from an incident.

What the Essential Eight Requires

At Maturity Level One: backups of data, applications and settings are performed and retained in line with business criticality, synchronised to restore to a common point in time, retained securely, and tested as part of disaster recovery exercises; unprivileged accounts cannot access other accounts' backups or modify or delete backups. At Two: privileged accounts other than backup administrators also cannot access other accounts' backups or modify or delete backups. At Maturity Level Three: no account other than a backup administrator can access even its own backups, and backup administrators cannot modify or delete backups during the retention period. Restoration is tested as part of disaster recovery exercises at every level; the model sets no calendar.

The Offline or Immutable Requirement

Ransomware attacks specifically target backups. If backup storage is accessible from the same network as production systems, it will be encrypted or deleted along with everything else. Effective backup resilience requires at least one copy stored in a location the production environment cannot write to: offline media, immutable cloud storage, or an isolated vault with no direct network path from production.

The 3-2-1 Rule

Three copies of data. On two different media types. With one copy stored offsite. For most Australian SMBs this translates to: local backup to NAS or external drive, cloud backup to immutable storage, and periodic offline media for critical data. Microsoft 365 backup is separate — Microsoft retains data for limited periods and is not a substitute for a business-controlled backup.

Does Microsoft 365 back up our data?

Microsoft operates a highly resilient infrastructure but this is not the same as a business backup. Accidental deletion, malicious deletion by a compromised account, and ransomware can all result in data loss that Microsoft's infrastructure does not protect against. A third-party backup solution — Veeam, Acronis, or similar — that creates a separate, business-controlled copy of Exchange, , and Teams data is required for comprehensive backup coverage.

Keep reading

More from the IronSights team.