Home›Guides›IT backup

IT backup

How can you tell whether a business is really protected against data loss?

A business is really protected if, for the systems that keep it running, it can show a recent successful restore, a copy that does not share the fate of the server, and a person able to do it again without improvising. The volume purchased, the software logo or the phrase “we are backed up” are not enough to conclude.

Updated October 20263 min read6 sources cited

Key points

  • Protection is assessed on a defined scope: the short list of systems without which the business stops.
  • Nine questions are enough; a vague answer counts as a no.
  • If an everyday administrator account can erase a copy, so can ransomware.
  • More than twelve months without a restore test: protection is just an assumption.
  • Insurers and auditors mainly ask for the report of the last test, not the product name.

The questions that settle it

Ask them of management and of the person who administers the systems. Vague answers count as a no.

  1. Which systems, if lost tonight, would stop the business tomorrow? Without a short list, protection has no scope. Good-practice guides start with exactly this: identifying the devices and data to back up.
  2. When was the last successful backup of each one? “Normally last night” is not a date. A screen or an alert email is.
  3. Where is the copy if the building burns down? Same room, same administration network, or another location. The CNIL, France’s data protection authority, recommends at least one backup at a geographically separate site.
  4. Can an everyday administrator account erase this copy? If so, ransomware can too. The ANSSI, France’s national cybersecurity agency, calls for dedicated backup accounts and at least one offline copy.
  5. When did you last carry out a real restore, of what, and how long did it take? More than twelve months without a test: protection is just an assumption.
  6. Who has the encryption key and the instructions if that person is on leave? A single key in one employee’s head is a point of failure. The ANSSI recommends defining who holds the keys, where they are stored and how they are backed up.
  7. What downtime does management accept, and did the last restore fit within it? Otherwise the RTO is just a wish.
  8. Is cloud email within scope? Many businesses protect the file server and forget Microsoft 365 or Google Workspace, where the real work is done.
  9. What happens at the weekend? An alert that is only read on Monday delays the discovery of a failure accordingly.

A simple score

AnswerInterpretation
List of systems, off-site copy, immutable or offline, test less than twelve months old, two capable peopleReal protection on the listed scope
Software in place, green logs, no tests, copy on the local NASProtection against a minor disk failure only
“The provider takes care of it”, with no contractual response time or testProtection not verified
No copy of cloud emailA gap in the main work tool

Protection always applies to a defined scope. An SME can be very well protected for its ERP and completely exposed on two sales reps’ laptops. Saying so is more useful than an overall percentage.

What an external audit also looks at

Cyber insurers and auditors generally ask for the same evidence: architecture of the copies, retention period, result of the last test, management of access to the console, and the incident procedure. They rarely ask for the product name. They ask for the report of the last test.

The incident procedure must also cover the formalities: a complaint to the police in your country, online where possible, and a claim to your insurer. Check your cyber insurance policy for the deadlines for reporting and filing a complaint: they vary by country and insurer.

For businesses within the scope of the European NIS 2 Directive, transposed into the law of each Member State, this is no longer just a matter of good practice: Article 21 lists business continuity, backup management and business recovery among the risk management measures to be put in place.

At WeDoBack

The service provides the encrypted off-site copy, on servers dedicated to backup and replicated in several European countries (or in the zone required by law), and 24/7 backup monitoring with an alert in the event of failure. If subscribed, it adds immutability, restart on standby instances (DRP) or takeover by continuously running instances (BCP). It does not replace answers 1, 5 and 6: the scope, the test and safekeeping of the key remain the customer’s responsibility. INTEGRAL includes two hours of support per month to help with these tasks. SMART leaves operations to the customer and bills support per intervention. Support can be reached on +33 9 72 50 78 28 from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time). In any case, a business that has never carried out a restore is not “protected by WeDoBack”. It has a subscription.

Frequently asked questions

Is having an IT service provider enough to be protected?

No, not in itself. Check what the contract actually provides for: scope backed up, location of copies, retention period, restore tests, response time. Ask for the report of the last test. Without these elements, protection has not been verified.

Is my business covered by NIS 2?

The European NIS 2 Directive targets essential and important entities in many sectors, depending on their size and activity. For those concerned, it explicitly lists backup management and business recovery among the mandatory security measures. Even if you fall outside its scope, its list is a good benchmark.

Where should you start if the answers are poor?

With the list of critical systems, then a test restore of the most important one. This first test almost always reveals the real gaps: missing copy, key that cannot be found, time that is too long. You then fix them in that order.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.