Are backups tested for malware-free integrity prior to restoration?
Restoring the malware along with the data is a real and frequent way a recovery fails twice.
What the carrier is actually asking
The carrier is asking whether you can establish that a recovery point predates the compromise, and whether restored content is scanned before it rejoins production. Attackers dwell for weeks, so the most recent backup is often the most infected one.
Why it is underwritten
Reinfection extends business interruption, which is the coverage most exposed to a slow recovery. A carrier paying daily indemnity cares a great deal about whether the second restore attempt was necessary. Organisations that can identify a clean recovery point recover once.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is a process and product question that Insurance Posture does not read, so it is attested. Some of the surrounding capability is visible in your endpoint and cloud tooling.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Backup product | Scanning of backup content, or an isolated recovery environment with scanning on restore | Scanning happens somewhere in the path between the recovery point and production |
| Recovery process | A staging or isolated network where restored systems are examined before reconnection | A defined quarantine step rather than a direct restore into production |
| Retention design | Retention depth relative to plausible dwell time | Recovery points old enough to predate a months-long intrusion, since a two-week retention offers no clean point after a six-week dwell |
| Endpoint tooling | Detection telemetry that establishes a compromise date | Enough telemetry to identify when the intrusion began, which is what makes a recovery point selectable |
| Incident response plan | The step that selects and validates a recovery point | Written down, since this decision is made under pressure and badly if improvised |
Scanning helps. Having a recovery point that predates the intrusion helps more. If your retention is shorter than your realistic detection time, no amount of scanning produces a clean restore, because there is no clean point left to choose.
What a defensible yes requires
- Restored systems pass through an isolated stage where they are scanned before rejoining production.
- Retention is deep enough to offer recovery points older than a plausible dwell time.
- The incident response plan names who selects the recovery point and on what evidence.
- Endpoint telemetry is retained long enough to date the compromise.
- The process has been exercised at least once, since improvising isolation during an incident rarely goes well.
How this answer goes wrong
Most organisations answer no honestly, which is fine and common. The overstatement to avoid is answering yes because the backup product performs integrity verification, which checks that the data is intact and says nothing about whether it is infected. The two words look similar on a settings page and mean entirely different things.
Frequently asked
Is antivirus scanning of backup storage the same thing?
It is a partial answer. Scanning stored backups can find known malware in the copies. It does not catch what was undetected at the time, which is why an isolated restore and observation step matters.
How deep should retention be?
Deep enough to cover the time between compromise and detection, which is realistically measured in weeks to months. Thirty days is thin; ninety or more gives you options.
Do carriers expect a yes here?
Less than for immutability or restore testing. A candid no with strong retention and a defined isolation step reads better than a yes that does not survive a follow-up question.
Does an isolated recovery environment help elsewhere?
Yes. It is the same infrastructure that makes restore testing routine, so building it improves two answers at once.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture