Home | Cyber insurance questionnaire | Backup
Cyber insurance backup questions: how to answer them
Australian cyber insurance proposal forms ask four separate questions about backup, and passing all four takes more than a working nightly job. Insurers want daily backups, a copy that is offline and unreachable from your network, an environment that is encrypted, multi-factor protected and immutable, and a dated record of a full restore test. That last one is the single most commonly missing piece of evidence on the entire form.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner

Key facts
- Insurers ask four backup questions: frequency, whether an offline copy exists, the security of the backup environment, and how often a full restore is tested.
- Daily is the minimum acceptable backup frequency on Australian proposal forms. Weekly and monthly are both offered as answers and both invite follow-up questions.
- The offline copy question is worded as “segregated from and inaccessible to your network”, which rules out a device sitting on the same network with the same credentials, even when the backup job succeeds every night.
- Proposal forms define immutable technology as data that cannot be altered or modified once created, so a retention setting an administrator can shorten does not qualify.
- An immutability window needs to outlast attacker dwell time. Fourteen days is a floor and 30 days is the safer answer.
- Backup consoles are asked about twice on longer forms, once under identity and again here, because ransomware operators target the backup platform before encrypting anything.
Why insurers ask about this in so much detail
Backup is what determines whether a ransomware incident is an expensive week or an existential event, and it is therefore the control that most directly affects the size of a claim. An insurer facing a business interruption claim wants to know how quickly systems came back, and the answer to that was decided long before the incident, by whether the backups were reachable from the network the attacker had already compromised.
The questions became more specific because the general one stopped working. Nearly every business had backups. A large share of those businesses discovered during an incident that the backup target was domain joined, that the backup credentials were the same domain administrator credentials the attacker had taken, or that nobody had ever restored a full system and the process took four days instead of four hours.
The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named, and where forms differ the stricter wording is used. The full set of 45 technical questions is on the cyber insurance questionnaire guide.
The backup questions insurers ask
How frequently do you take regular backups of critical data and systems?
Australian cyber insurance proposal forms offer four answers to this question: daily, weekly, monthly, or greater than monthly. Daily is the minimum an underwriter treats as normal for a business of any size, and anything less prompts questions about what recovery point the business is willing to accept.
What needs to be in place is a daily job covering everything that matters, which in practice means servers, line-of-business application data, file storage and cloud platform data. Cloud data is the gap worth naming: many businesses assume their productivity platform backs itself up, and while the vendor protects its own infrastructure, it is not keeping a restorable copy of your mailboxes and files for you in the way a backup product does.
The evidence is not the schedule. It is a job success report covering the period, showing the jobs ran and completed. A daily job that has been failing quietly for three weeks is a worse position than a weekly job that works, and an insurer assessing a claim will look at the report rather than the configuration.
Do you keep a copy of critical backups offline, segregated from and inaccessible to your network?
This is the question that decides how a ransomware incident ends, and the wording does the work. “Inaccessible to your network” means the copy must survive the compromise of your production environment, which is a higher bar than simply existing somewhere else.
To answer yes you need a copy on a target that production credentials cannot authenticate to and production malware cannot traverse to. In practice that is immutable object storage with its own credential set, a cloud copy protected by a separate identity, or removable media rotated offsite. What fails the question is the common arrangement: a storage device on the same network, joined to the same directory, reachable with the same administrator account. That is a second copy, not an offline copy.
Hold an architecture diagram showing where the credential boundary and the network boundary sit, together with the immutability or object lock settings on the target. When you sketch that boundary honestly, it becomes obvious very quickly whether the answer is yes.
Is your backup environment encrypted, multi-factor protected and using immutable technology?
Proposal forms ask this as a list, covering whether the backup environment is in the cloud, on premises, at a secondary data centre, encrypted, multi-factor protected, and using immutable technology. The last three are the ones that carry weight.
What you need is encryption at rest on the backup data, multi-factor authentication on the backup console, and an immutability window long enough to outlast the time an attacker spends inside a network before triggering encryption. Intruders commonly sit quietly for days or weeks, deliberately long enough for short-retention backups to age out, so a seven day window can be defeated by patience alone. Fourteen days is the floor and 30 days is the answer that holds up. Immutability also has to be real: proposal forms define immutable technology as data that cannot be altered or modified once it is created, so a retention lock a compromised administrator account can shorten does not meet the definition.
The evidence is the object lock or immutability configuration showing the retention window, the encryption setting, and the console administrator list showing the authentication state. Keep backup administrator credentials separate from production administrator credentials, because shared credentials undermine every other control in this list.
How frequently do you test system restoration capabilities by performing a full restoration from backup?
Australian proposal forms offer annually, quarterly, monthly or not tested. This question is where the largest number of otherwise well-run businesses answer honestly and answer badly, because backup software reporting success is not a restore test and never has been.
What satisfies the question is a scheduled restore of a sample set to isolated infrastructure, performed end to end, with two things recorded: whether the restored system came up working, and how long it took. The time matters as much as the outcome, because a business continuity plan that assumes a four hour recovery and a restore process that takes three days are two different plans, and only one of them is real.
The evidence is a dated restore test report. This is the artefact most often missing when an underwriter asks, and it is also the cheapest one on this page to produce. A quarterly test with a one page record puts a business ahead of most of the market on the question insurers care about most.
The evidence to assemble before the form arrives
Five artefacts answer all four questions, and holding them makes the next renewal and any competing quote a much shorter exercise:
- A backup job success report covering the last full month, not just the schedule.
- An architecture diagram showing where the credential and network boundary sits between production and the offline copy.
- The immutability or object lock configuration, showing the retention window in days.
- The backup console administrator list with the authentication method for each account.
- Dated full restore test reports, with the time taken recorded.
These controls map onto the regular backups strategy in the Australian Signals Directorate Essential Eight, so a business working toward Maturity Level 1 is building what the underwriter is asking about. The Essential Eight guide for Australian SMEs covers how the eight strategies fit together, and the framework itself is published by the Australian Cyber Security Centre at cyber.gov.au.
One thing not to do
Do not answer yes to the offline copy question because a copy exists somewhere other than the primary server. The question asks whether the copy is inaccessible to your network, and that is a specific technical claim about credentials and routing. It is the answer most likely to be tested by events rather than by an underwriter, and finding out it was wrong happens at the worst possible moment, with the encrypted backup target sitting on the same network as everything else.
If a cyber insurance questionnaire has landed and the backup section is the part holding it up, 4iT works through the whole form against your actual environment, closes the gaps that turn a yes into a no, and produces the evidence pack the underwriter will ask for. Request a callback and we will work out what it takes in your case.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







