Home›Guides›IT backup

IT backup

Should you outsource your backups?

Yes, if losing your premises or a compromise of your internal network must still leave at least one restorable copy. Outsourcing does not rule out a local copy: it prevents all copies from sharing the same fate as production.

Updated October 20263 min read5 sources cited

Key points

  • Outsource the backup copy and the history; keep a recent copy on site for small restores.
  • Require in writing: the country where copies are held, a copy that cannot be deleted, the measured restore time, and the contract exit terms.
  • The ANSSI, France’s national cybersecurity agency, recommends encrypting before sending and checking that the data is located in the European Union.
  • Under the GDPR, the provider is a processor: the contract must provide for the deletion or return of data at the end of the service.
  • Never store the encryption key in the same vault as the data.

When outsourcing changes the outcome

  • Fire, water damage, theft of equipment: the backup NAS in the same room is lost along with the servers.
  • Ransomware that got in through an administrator account: it encrypts mounted shares, including the “Backup” share on the network.
  • The only employee who swapped the disks is away: the rotation stops without management knowing.
  • A requirement to keep data in a specific country or region, without running a second site yourself.

A company that already has two distant buildings, a dedicated team and an immutable copy that is genuinely offline can outsource less. That is rare in an SME.

What to outsource, and what to keep

Outsource the backup copy and the history. Keep on site, if bandwidth allows, a recent copy so that you can restore a file without waiting for several terabytes to download. Also outsource cloud email backups to a party other than the email provider: staying in the same tenant means remaining exposed to the same administrator accounts. See Should you back up Microsoft 365?.

Do not outsource the encryption key to the same logical vault as the data, and do not leave the only administration password with the provider without a written procedure.

What the ANSSI recommends for an outsourced backup

The ANSSI backup guide devotes a table to offsite backups held with a cloud host or a subcontractor. The points to watch:

Point to watchWhat to check
Data sensitivityEncryption before data is sent to the provider
LocationStorage within the European Union
Restore timeCompatible with the maximum tolerable downtime, including the restore priority set out in the contract
Resistance to deletionA WORM (non-modifiable) solution can be considered, with separate administration accounts
Offline copyStill considered more robust; an acceptable compromise combines regular WORM copies with less frequent offline copies

The CNIL, France’s data protection authority, adds that transmission channels must be encrypted when backups leave the organisation, and that backups deserve the same level of security as production servers.

The limitations, stated plainly

  • Bandwidth. The first backup of a large volume takes time. Subsequent backups send only the changes, provided the software is incremental. A connection that is too slow also lengthens a full restore.
  • Dependence. On the day of the incident, you depend on the provider’s opening hours, the contract and the provider’s ability to read back its copies. NIST lists accessibility (recovery time and hours) among the criteria for choosing offsite storage. A restore test before a disaster is the only honest test.
  • The recurring cost. You pay for the volume retained each month. A five-year retention on an entire server costs as much as poorly targeted archiving.
  • Responsibility for the data. The contract must state where the data is, who can access it and how it is erased at the end of the contract. The GDPR (Article 28) only allows the use of a processor that provides sufficient guarantees, and requires it to delete or return the data at the end of the service. Encryption with a key you hold reduces what the provider can read; it does not remove your obligations.

How to choose

Ask for four things in writing: the country where copies are held, the option of a copy that cannot be deleted, the measured time to restore a volume like yours, and what happens if you leave. Talk of “high security” without these four answers does not allow you to decide.

If the goal is to restart the service, not just to recover the data, also read Outsourced DRP: benefits and limitations.

At WeDoBack

Outsourcing is the core service: copies leave the client’s network, are encrypted on the machine before they are sent, and are replicated across several European countries, or in the region required by the client’s legislation. The data centres and solutions used are ISO 27001 and HDS (French health data hosting) certified, and processing complies with the GDPR. SMART leaves operations to the client, with support billed per intervention. INTEGRAL includes two hours of support per month. Support can be reached on +33 9 72 50 78 28 or at [email protected], from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time). The IMMUTABLE, DRP and BCP offers are options for when a restorable copy is not enough to meet the objective (long-term proof, or resuming service).

Frequently asked questions

Can the provider read my data?

Not if it is encrypted on your machine before it is sent, with a key that only you hold. The provider then stores unreadable blocks. The flip side is that losing the key makes restoring impossible: it must be kept in several secure places.

How long does a restore from an offsite copy take?

It depends on the volume, the bandwidth of your connection and the method. Restoring a file takes a few minutes; restoring several terabytes over the Internet can take days. The ANSSI, France’s national cybersecurity agency, asks you to check that the restore time is compatible with the maximum tolerable downtime. Hence the value of a local copy or of restarting on a standby instance.

What happens to my backups if I change provider?

The contract must say so. The GDPR requires that, at the end of the service, the processor deletes or returns the personal data, as the controller chooses. Plan an overlap period: keep the old history until the new one has reached the required retention.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.