IronSights
←All insights

technical

Ransomware-proof backups for Australian businesses: immutability, 3-2-1-1-0 and the restore test

A backup the attacker can reach is a second copy of the problem. The 3-2-1-1-0 design, what immutable really means, what the Essential Eight requires at each level, why Microsoft 365 needs its own backup, and the one restore test that answers everything.

Ryan BallootBy Ryan Balloot, Managing Director29 September 20267 min read
ByRyan Balloot29 September 20267 min read

Attackers go for the backups before they trigger the , because intact backups are the main reason a victim refuses to pay. Connected backup drives are encrypted with everything else. Cloud backup consoles are wiped with a stolen administrator login. Volume shadow copies are deleted as a routine step by most strains. A backup that the attacker can reach is not a backup. It is a second copy of the problem.

This guide is the design that survives that: what a -proof backup looks like in 2026, what 's requires of it at each , and the one test that tells you whether yours would hold. It is written for an Australian business with an IT provider rather than a security team, and it assumes nothing has gone wrong yet.

The rule, and the two additions that matter now

The old rule was 3-2-1: three copies of your data, on two different types of storage, with one copy somewhere else. It was written for fires and floods, and it still works for those. Ransomware needs two more numbers, and practitioners now write the rule as 3-2-1-1-0.

NumberWhat it meansWhy ransomware makes it necessary
3Three copies: production plus two backups.One backup is a single point of failure. Two gives you a fallback if the first generation turns out to be infected.
2Two different storage types.A flaw or a credential that reaches one type should not reach the other.
1One copy off-site.A fire, a flood or a seized server room does not take the backup with it.
1One copy offline or immutable.The copy the attacker cannot reach, because there is no network path to it or because the storage refuses to alter or delete it during the retention period.
0Zero errors on a tested restore.A backup nobody has restored from is a hope, not a plan. The zero is the test result.

What immutable actually means

Immutable storage is a copy that cannot be changed or deleted until a set period has passed, by anyone, including the administrator who created it. Cloud object storage offers it as a lock on the bucket or container; backup appliances and some backup software offer it as a retention lock; tape and disconnected drives are immutable in the oldest way, by not being plugged in.

The question to ask of any immutable copy is who cannot get at it. A domain administrator is exactly what a ransomware operator becomes before they encrypt, so if a domain administrator can delete the backups, so can the attacker. ASD's Essential Eight makes this explicit: at Maturity Level 2, privileged accounts other than backup administrators cannot access other accounts' backups or modify or delete backups, and at Level 3 even backup administrators cannot modify or delete backups during the retention period.

Three design rules follow. The backup system has its own accounts, not domain accounts, with on the console. The immutable copy is written by the backup system, not by a share that production servers can browse to. And the retention period on the immutable copy is longer than the time an attacker typically spends inside a network before encrypting, which is days to weeks, so that at least one clean generation exists when you need it.

What the Essential Eight requires

Regular backups is the eighth of ASD's Essential Eight. The requirements below are condensed from the current maturity model at cyber.gov.au; the wording that matters is that restoration is tested as part of disaster recovery exercises, at every level.

LevelRequirement
Maturity Level 1Backups of data, applications and settings are performed and retained in line with business criticality and continuity requirements, synchronised so everything restores to a common point in time, and retained in a secure and resilient manner. Restoration to a common point in time is tested as part of disaster recovery exercises. Unprivileged accounts cannot access other accounts' backups and cannot modify or delete backups.
Maturity Level 2Everything at Level 1, and privileged accounts other than backup administrators also cannot access other accounts' backups or modify or delete backups.
Maturity Level 3Everything at Level 2, and no unprivileged or privileged account other than a backup administrator can access even its own backups. Backup administrators cannot modify or delete backups during the retention period.

Two things in that table catch businesses that believe they are covered. Applications and settings are in scope, not just data, so a backup of the file server that leaves out the identity system, the firewall configuration and the line-of-business application is a Level 0 backup. And the common point in time matters: restoring the database from Tuesday and the application from Thursday gives you a system that does not work. The other seven controls are in our Essential Eight controls list.

Microsoft 365 is not backed up unless you back it up

Microsoft runs resilient infrastructure. That is not the same thing as a backup you control. Accidental deletion, deliberate deletion by a compromised account, and ransomware that reaches synchronised and libraries can all destroy data that Microsoft's own retention will not bring back once the retention window passes. A third-party backup that keeps a separate, business-controlled copy of Exchange, SharePoint, OneDrive and Teams is part of the three copies, not an optional extra.

Decide the three numbers before the incident

APRA's CPS 230 asks regulated entities to set three tolerance levels for every critical operation: the maximum time they would tolerate a disruption, the maximum data loss they would accept, and the minimum service they would maintain while running on alternative arrangements. Every business should answer the same three questions, because the answers set the backup schedule, the retention period and the restore priority. A practice that can lose a day of appointments but not the patient record sets a different schedule from a distributor that cannot lose an hour of orders.

Write the answers down per system. Then check the backup schedule against them. It is common to find one system that is backed up nightly when the answer to the data-loss question was an hour.

The test that answers everything

Pick one important system. Restore it from backup into an isolated environment that cannot reach production. Time it. Check that the application starts, that the data is complete to the point in time you expected, and that nobody needed a password that only exists in the compromised environment.

That one exercise tells you whether the backups are complete, whether the immutable copy is really separate, how long a real recovery would take, and whether the people who would do it under pressure can do it at all. Do it before the incident, on a schedule, and record the result. On the bad day the result is the difference between restoring and negotiating.

If the bad day is today

Do not restore yet. Attackers spend days or weeks inside a network before they encrypt, so backups taken in that window can carry their tools and accounts back in with the data, and restoring over the compromised machines destroys evidence and any partially encrypted files that were still recoverable. Take whatever backups survived offline immediately, then work through the three questions in are my backups safe to restore after ransomware. If the backups are gone, the encrypted files are often partially intact; our ransomware data recovery page covers what can be rebuilt without a key.

Frequently asked questions

What is the 3-2-1-1-0 backup rule?

Three copies of your data, on two different storage types, one of them off-site, one of them offline or immutable, and zero errors on a tested restore. The last two numbers are the ransomware additions to the older 3-2-1 rule.

Are cloud backups safe from ransomware?

Only if the copy is immutable and the console is protected by its own credentials and multi-factor authentication. A cloud backup that a domain administrator can log into and delete is reachable by an attacker who has become a domain administrator, which is the usual position by the time encryption starts.

How often should backups be tested?

The Essential Eight requires restoration to be tested as part of disaster recovery exercises at every maturity level and does not set a calendar. A practical answer is a full restore test of at least one critical system on a fixed schedule, with the result recorded, plus a restore of anything whose backup configuration has changed.

Does the Essential Eight require offline backups?

Not in those words. It requires backups to be retained in a secure and resilient manner and, from Level 2, protected from privileged accounts. An offline or immutable copy is the usual way to satisfy both, and it is what ASD's own advice to back up important data regularly is pointing at.

Should we keep paying for tape?

If tape is your offline copy and someone rotates it, it is doing a job that a lot of expensive software fails to do. The weakness is usually not the tape but the untested restore.

Where to start

An Essential Eight assessment rates your backups against the requirements above, with evidence, alongside the other seven controls; it is one of the fixed-price options on our assessment service. If you would rather have someone run the restore test and fix what it finds, that is the Fortify managed security plan doing its ordinary work.

Incident response

If this happens to you, the first hour decides the rest.

Our incident response team is available 24/7 on 1300 004 766. We contain the incident, work out what was taken, and handle the reporting clocks you are now on.