Does Cloud Backup meet Cyber Security Insurance requirements?
Am I using Cloud Backup?
To find out if you are using Cloud Backup please login to my.sixfive.io > My Products & Services. If you are not and you want to be, visit our Cloud Backup page to get started.
What is Cyber Insurance?
Many businesses are taking critical steps to protect their technology assets (data, email, websites etc.). Protection can include cyber insurance, also known as cyber liability insurance, a type of business insurance that protects against financial losses resulting from cyber security incidents, such as data breaches, ransomware attacks, and malicious destruction of data. When applying for cyber insurance (like all policies) you will be required to answer a range of questions about "how secure, fail safe" your technology business operations are. These audits are good as they force you to look hard at your business tech and lead to the implementation of important security settings such as multi-factor authentication (MFA), password management tools and backups. But they can also be confusing as they are often written for older technologies like on-premise environments that are not so common in todays cloud based world.
Surely Google Workspace has backups?
Being "in the cloud" doesn't necessarily mean you are protected. While Google protects itself and it's data via replication across the globe (ie. it has it's own backups) it isn't specifically looking out for your business. If Google Workspace "went down" they wouldn't be prioritising your business as part of it's recovery. Also Google Workspace is of no help if you have a security breach, ransomware attack, internal malicious actor compromising your data or you just realised 30 days too late that something that was deleted (ie. a user or data in the trash) is now gone for good.
How does Cloud Backup help me obtain cyber insurance?
Most cyber insurance applications contain the following questions (or like thereof). If you are utilising SixFive's Cloud Backup solution, you already have the answers and more to these questions:
- Do you take regular backups ?
- Yes, as a standard backups are taken 3 times a day and retained for 1 year for those users and data selected for protection.
- Do you routinely test your backups?
- SixFive regularly tests the restoration of backups on a monthly basis.
- Are backups made to a location remote from your current data location?
- Yes, cloud backups are stored completely separately from your Google Workspace. Backups can also optionally be downloaded if your Google Workspace is compromised for an extended period.
- Are backups subject to strict access protection including multi-factor authentication.
- Yes, access to backups requires access via Google single sign on (SSO) which has multi-factor authentication enforced.
- Are backups stored using immutable technology (ie. they can never be changed)?
- Yes, cloud backups are stored using immutable technology to ensure that the data remains in its original state, allowing for reliable data recovery and disaster recovery scenarios.
- Are backups encrypted?
- Cloud backups are encrypted both in transit and at rest, with additional "bring your own key" options available.
- Do you have a business continuity or disaster recovery plan (spoiler alert, they both require backups are in place).
- If you have cloud backup, you have automatically provided the source data for any business continuity or disaster recovery related requirements regarding Google Workspace.
- Do you have any ransomware protection for your data?
- Yes, cloud backups have AI-driven ransomware detection, preemptive backups, and timely alerts to administrators in the event it detects suspicious activity in your backups.
How else can SixFive assist me with obtaining cyber insurance?
Whilst all insurers are different, premiums paid often depend on "how secure" they deem your business. For example, do you know who you are sharing your data with, are you regularly reviewing who your administrators are, are you enforcing multi-factor authentication in your Google Workspace? Six Five's Google Workspace Care Plans are designed to provide you with crucial security and brand protection solutions including monthly reports, email brand protection and recommendations for security settings in Google Workspace. Visit our Care Plan page to get started.
DISCLAIMER: We are not lawyers and every cyber security application is different, this article does not constitute legal advice, it assists you with auditing your business requirements with solutions that may prove pertinent to applying for cyber security.