How can you tell whether a business is really protected against data loss?
A business is really protected if, for the systems that keep it running, it can show a recent successful restore, a copy that does not share the fate of the server, and a person able to do it again without improvising. The volume purchased, the software logo or the phrase “we are backed up” are not enough to conclude.
Updated October 20263 min read6 sources cited
Key points
- Protection is assessed on a defined scope: the short list of systems without which the business stops.
- Nine questions are enough; a vague answer counts as a no.
- If an everyday administrator account can erase a copy, so can ransomware.
- More than twelve months without a restore test: protection is just an assumption.
- Insurers and auditors mainly ask for the report of the last test, not the product name.
The questions that settle it
Ask them of management and of the person who administers the systems. Vague answers count as a no.
- Which systems, if lost tonight, would stop the business tomorrow? Without a short list, protection has no scope. Good-practice guides start with exactly this: identifying the devices and data to back up.
- When was the last successful backup of each one? “Normally last night” is not a date. A screen or an alert email is.
- Where is the copy if the building burns down? Same room, same administration network, or another location. The CNIL, France’s data protection authority, recommends at least one backup at a geographically separate site.
- Can an everyday administrator account erase this copy? If so, ransomware can too. The ANSSI, France’s national cybersecurity agency, calls for dedicated backup accounts and at least one offline copy.
- When did you last carry out a real restore, of what, and how long did it take? More than twelve months without a test: protection is just an assumption.
- Who has the encryption key and the instructions if that person is on leave? A single key in one employee’s head is a point of failure. The ANSSI recommends defining who holds the keys, where they are stored and how they are backed up.
- What downtime does management accept, and did the last restore fit within it? Otherwise the RTO is just a wish.
- Is cloud email within scope? Many businesses protect the file server and forget Microsoft 365 or Google Workspace, where the real work is done.
- What happens at the weekend? An alert that is only read on Monday delays the discovery of a failure accordingly.
A simple score
| Answer | Interpretation |
|---|---|
| List of systems, off-site copy, immutable or offline, test less than twelve months old, two capable people | Real protection on the listed scope |
| Software in place, green logs, no tests, copy on the local NAS | Protection against a minor disk failure only |
| “The provider takes care of it”, with no contractual response time or test | Protection not verified |
| No copy of cloud email | A gap in the main work tool |
Protection always applies to a defined scope. An SME can be very well protected for its ERP and completely exposed on two sales reps’ laptops. Saying so is more useful than an overall percentage.
What an external audit also looks at
Cyber insurers and auditors generally ask for the same evidence: architecture of the copies, retention period, result of the last test, management of access to the console, and the incident procedure. They rarely ask for the product name. They ask for the report of the last test.
The incident procedure must also cover the formalities: a complaint to the police in your country, online where possible, and a claim to your insurer. Check your cyber insurance policy for the deadlines for reporting and filing a complaint: they vary by country and insurer.
For businesses within the scope of the European NIS 2 Directive, transposed into the law of each Member State, this is no longer just a matter of good practice: Article 21 lists business continuity, backup management and business recovery among the risk management measures to be put in place.
At WeDoBack
The service provides the encrypted off-site copy, on servers dedicated to backup and replicated in several European countries (or in the zone required by law), and 24/7 backup monitoring with an alert in the event of failure. If subscribed, it adds immutability, restart on standby instances (DRP) or takeover by continuously running instances (BCP). It does not replace answers 1, 5 and 6: the scope, the test and safekeeping of the key remain the customer’s responsibility. INTEGRAL includes two hours of support per month to help with these tasks. SMART leaves operations to the customer and bills support per intervention. Support can be reached on +33 9 72 50 78 28 from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time). In any case, a business that has never carried out a restore is not “protected by WeDoBack”. It has a subscription.
Frequently asked questions
Is having an IT service provider enough to be protected?
No, not in itself. Check what the contract actually provides for: scope backed up, location of copies, retention period, restore tests, response time. Ask for the report of the last test. Without these elements, protection has not been verified.
Is my business covered by NIS 2?
The European NIS 2 Directive targets essential and important entities in many sectors, depending on their size and activity. For those concerned, it explicitly lists backup management and business recovery among the mandatory security measures. Even if you fall outside its scope, its list is a good benchmark.
Where should you start if the answers are poor?
With the list of critical systems, then a test restore of the most important one. This first test almost always reveals the real gaps: missing copy, key that cannot be found, time that is too long. You then fix them in that order.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI (French agency)
- Security: Backing up — CNIL (French authority)
- Cybersecurity guide for SMEs – 12 steps to securing your business (June 2021) — ENISA, the European Union Agency for Cybersecurity
- Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2), Article 21 — EUR-Lex
- Report cybercrime online (online reporting services by country) — Europol
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
