Home/Questions/Backup and recovery/Backup procedures and tools
Backup and recovery

Are there procedures and tools to back up sensitive data and critical systems?

This is the gateway question for the whole backup block. Answering it yes commits you to the six or seven harder questions that follow.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking two things at once: whether backups happen, and whether they happen by design. A scheduled job with defined scope, retention, and ownership is a procedure. A colleague who copies the file server to a drive most Fridays is not, even when the copies exist.

Scope is where this question quietly gets harder. Critical systems now include cloud workloads, software-as-a-service data, and the identity platform itself, and many organisations answer this from the perspective of an estate they no longer run.

Why it is underwritten

Backup quality is the single largest determinant of ransomware loss severity. Recovery from clean, tested backups turns a catastrophic claim into an expensive week. Everything else in this block exists because carriers learned that a yes to this question alone does not predict recovery, so they now interrogate the details.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Insurance Posture reads Microsoft 365, Entra ID, Azure, and AWS configuration. It does not read backup products, so the substance of this answer is attested. What the cloud can show is the retention and recoverability posture of the data that lives there natively.

PlatformWhere the setting livesWhat has to be true
Backup productJob configuration, scope, schedule, retention, and success reportingNamed systems in scope, a schedule matched to your tolerance for loss, and alerting on failure. This is attested
Microsoft 365Retention policies in Purview, and SharePoint version historyRetention covering mail, sites, and OneDrive. Retention is not backup, and stating the distinction rather than blurring it is what makes the answer credible
AzureStorage account soft delete for blobs and containers, and blob versioningSoft delete enabled with a defined window, versioning on for data you cannot recreate
AzureGeo-redundant storage on accounts holding critical dataReplication that survives the loss of a region, which is a different property from surviving a deletion
AzureKey Vault soft delete and purge protectionRecoverable vaults, because losing key material makes an otherwise intact backup unreadable
Retention is not backup

Microsoft 365 retention policies preserve content against deletion inside the same tenant. They do not protect against a tenant-level compromise, and they are not a restore path for a corrupted mailbox at a point in time. Many organisations answer this question on the strength of retention alone, which is a materially different control from what the carrier is imagining.

What a defensible yes requires

  • Backup scope is written down and includes cloud workloads and software-as-a-service data, not only servers.
  • Schedules are matched to a stated recovery point objective rather than to whatever the tool defaulted to.
  • Job failures alert to someone, because silent failure is the normal way backups stop working.
  • Someone owns the backup estate by name.
  • The identity platform and key material are covered, since data you cannot decrypt or a tenant you cannot sign into is not recovered.

How this answer goes wrong

The scope gap dominates. An organisation with excellent server backups answers yes, and its Microsoft 365 data, its cloud databases, and its software-as-a-service platforms are covered by nothing but the vendor's own retention. If ransomware or a malicious insider reaches the tenant, those datasets have no independent copy.

The second failure is silent breakage. Backups configured three years ago now skip a volume added last year, and nobody reads the success report because it always says success for the parts it still covers.

Frequently asked

Does Microsoft 365 back itself up?

It replicates and it retains, which protects against hardware failure and accidental deletion inside the retention window. It does not give you an independent, point-in-time copy outside the tenant, which is what carriers mean by backup.

What scope do carriers expect?

Whatever you would need to operate. In practice that means file data, databases, the mail and collaboration estate, configuration, and increasingly identity. If losing it stops the business, it belongs in scope.

Can Insurance Posture verify our backups?

It verifies the cloud-native retention and recoverability settings it can read and labels the rest as attested. Backup product configuration comes from the product.

Is a cloud-to-cloud backup product worth it for underwriting?

It closes the most common scope gap on modern applications and gives you a concrete artefact to point at, which tends to make the whole block easier to answer.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture