That verified if their backups were end to end encrypted though right?
It's also interesting what was out of scope:
Limitations
The following components were not in scope; NCC Group was therefore unable to evaluate and identify issues with
them:
• Third-party and proprietary HSM vendor implementation.
• Backup encryption implementation.
• Side-channels in the access, creation, modification and deletion of backup data on third-party cloud storage.