Nano Solutions

Regular backups

Regular backups is the Essential Eight mitigation strategy requiring backups of data, applications and settings to be performed and retained according to business criticality and continuity requirements, synchronised to a common restoration point, tested in disaster recovery exercises, and protected from accounts that could delete them.

Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).

On this page 4 sections
  1. What is required, and where
  2. How protection increases by maturity level
  3. There is no three-month rule
  4. How backups support recovery

Regular backups at a glance

What each maturity level requires

Requirements are cumulative: Level Three means everything in Levels One and Two as well. Each level links to that requirement on the matrix.

  1. ML1 Maturity Level One

    Regular backups, Maturity Level One: Performed and retained in accordance with business criticality and business continuity requirements (ISM-1511)
  2. ML2 Maturity Level Two

    Regular backups, Maturity Level Two: Privileged accounts (excluding backup administrators) cannot access other users' backups, or modify or delete backups
  3. ML3 Maturity Level Three

    Regular backups, Maturity Level Three: Unprivileged and privileged accounts cannot access their own backups
New requirements start here Carries the level below Score yourself with the self-assessment, or look a term up in the glossary.

The regular backups strategy is the only one in the Essential Eight focused on recovery. It protects the data, applications and settings an organisation needs to restore operations.

What is required, and where

Maturity Level One requires:

  • backups of data, applications and settings performed and retained in accordance with business criticality and business continuity requirements
  • backups synchronised to enable restoration to a common point in time
  • backups retained in a secure and resilient manner
  • restoration tested as part of disaster recovery exercises
  • unprivileged accounts prevented from accessing other users' backups or modifying or deleting any backup

Maturity Level Two also prevents privileged accounts other than backup administrators from accessing other users' backups or modifying or deleting backups.

Maturity Level Three prevents unprivileged and privileged accounts from accessing even their own backups. It also prevents backup administrator accounts from modifying or deleting backups during their retention period.

See the requirements matrix for every control at each maturity level.

How protection increases by maturity level

Read together, the three levels protect backups from progressively more privileged accounts.

  • Level One prevents an ordinary user from reaching anyone else's backups or modifying and deleting backups.
  • Level Two applies access and deletion restrictions to privileged users other than backup administrators.
  • Level Three prevents backup administrators from modifying or deleting backups during their retention period.

This progression corresponds to the adversary descriptions in the Essential Eight Maturity Model. At Level One, adversaries "may also destroy data (including backups)". At Level Two, they "may also destroy all data (including backups) accessible to a user account with special privileges".

This is why backup protection and restrict administrative privileges tighten in parallel. Administrative controls limit privileged access, while backup controls preserve recoverability if that access is compromised.

There is no three-month rule

The three-month figure comes from a different ASD publication.

ASD's 2017 Strategies to Mitigate Cyber Security Incidents describes strategy 34 as backups "of important new/changed data, software and configuration settings, stored disconnected, retained for at least three months. Test restoration initially, annually and when IT infrastructure changes."

The November 2023 Essential Eight Maturity Model carries neither the "disconnected" language nor the three-month figure. It requires retention "in accordance with business criticality and business continuity requirements", and retention "in a secure and resilient manner".

Both documents are live ASD publications. The maturity model is what maturity is assessed against, and it sets no number. A documented 30-day retention period may satisfy this Essential Eight control if it meets the organisation's business criticality and continuity requirements; other legal, regulatory or contractual obligations may still require longer retention.

How backups support recovery

Regular backups is the only strategy in ASD's "recover data and system availability" category. The other seven focus on preventing or limiting incidents; backups provide a path to restore operations after one occurs.

It sits mid-table in ASD's Commonwealth Cyber Security Posture in 2025, at 67% of Commonwealth entities at Maturity Level Two or above in 2024–25. That is down from 70% in 2022–23. It is one of three strategies that has not recovered to its 2022–23 result.

A backup job alone does not demonstrate recoverability. That requires restoring data, applications and settings to a common point in time during a disaster recovery exercise.

Sources

All ASD source documents →

Common questions

How long must backups be retained under the Essential Eight?

The maturity model sets no period. The requirement is that backups are "performed and retained in accordance with business criticality and business continuity requirements" — a business test, not a number. The "at least three months" figure comes from the 2017 Strategies to Mitigate Cyber Security Incidents, which also described backups as "stored disconnected". That remains a separate ASD publication, but it is not the current maturity-level requirement.

Do backups have to be offline or air-gapped?

The maturity model does not use those words. It requires backups to be "retained in a secure and resilient manner". Higher maturity levels progressively restrict which accounts can access, modify or delete them. Offline or immutable storage is one way to meet those controls, but it is not itself the requirement.

How often do we have to test restoration?

The maturity model does not state a frequency. It requires restoration to be "tested as part of disaster recovery exercises" at every maturity level, so organisations need a documented exercise cadence based on their continuity requirements. The separate 2017 Strategies publication suggests testing initially, annually and when IT infrastructure changes.

Why does Maturity Level Three restrict backup administrators?

Level Three accounts for compromise of a backup administrator account. It therefore prevents those accounts from modifying or deleting backups during the retention period, preserving a recovery copy even when an account with backup privileges is compromised.

  • Essential Eight requirements matrix

    What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

  • Restrict administrative privileges

    This strategy limits who receives privileged access, what privileged accounts can reach, how administrators use them, and when access expires.

Essential Eight

Need this assessed rather than explained?

We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.