What is the difference between backup and replication?
Replication maintains a copy close to the current state, so you can resume quickly after a failure. Backup keeps earlier states, so you can go back to before an error or an attack. The two complement each other: one does not replace the other.
Updated October 20263 min read5 sources cited
Key points
- Replication is an availability tool: it also copies deletions, corruption and encryption.
- Backup is a rollback tool: it keeps several dates, at the cost of a slight time lag (the RPO).
- The ANSSI, France’s national cybersecurity agency, points to replication when you cannot lose more than a few hours, and to backup for returning to a healthy state.
- Microsoft 365 and Google Workspace recycle bins: short-term safety nets within the same tenant, not a backup.
Replication follows the original
A database replica, a virtual machine mirror or file synchronisation sends changes to a second location, often within seconds. If the main server goes down, you can fail over to the second one and lose few transactions. It is an availability tool. NIST’s contingency planning guide (SP 800-34) reserves mirrored systems and disk replication for high-impact systems, combined with a standby site that is already running.
The replica also receives what should not be kept: a deleted file, a corrupted database, a document encrypted by ransomware. Depending on the mode (synchronous, asynchronous, with or without delay), the healthy copy disappears at the same time as the original, or a few minutes later.
Backup keeps the past
A 2 p.m. backup, a 6 p.m. backup and one from the previous evening remain available. If the attack started at 4 p.m., you restore the 2 p.m. version. You lose the afternoon’s work. You get back a usable system. This deliberate lag is the RPO.
A backup is generally less “fresh” than replication. It is the only one of the two that allows a rollback. The ANSSI’s backup guide puts it in its own way: it excludes from its scope data-loss requirements of less than 24 hours, for which it points to synchronous or asynchronous replication.
Comparison
| Replication | Backup | |
|---|---|---|
| Goal | Resume quickly after a failure | Return to an earlier healthy state |
| Freshness of the copy | Seconds to minutes | Hours (depending on frequency) |
| History | None or very short | Several days, weeks or months |
| Deletion, corruption, ransomware | Copied to the replica | Earlier versions intact |
| Outright hardware failure | Rapid failover | Restore, which takes longer |
How to combine them
| Need | Suitable tool |
|---|---|
| Resume within minutes after a hardware failure | Replication or BCP, with a second system already in place |
| Go back to before a deletion or an attack | Backup with history, ideally a copy that the attacker cannot modify |
| Both | Replication for outright failures, immutable backup for errors and ransomware |
A company that does not replicate and backs up every night accepts redoing up to 24 hours of work, and waiting for the restore. A company that only replicates can restart quickly and discover that the replica is already encrypted.
The case of the cloud
A hosting provider’s geo-replication protects against a data centre fire. It copies the state of the volume, including a volume already encrypted by the attacker. It is not a backup history.
The Microsoft 365 and Google Workspace recycle bins are short-term safety nets, within the same administrator account. In Exchange Online, a deleted item remains recoverable for 14 days by default and 30 days at most. In Gmail, an administrator has 25 additional days after the 30-day trash period; after that, neither the administrator nor Google can restore the message. These mechanisms are neither replication to a third party nor a backup outside the tenant. See Does Microsoft 365 really include a backup?.
At WeDoBack
WeDoBack backup keeps versions, at the frequency chosen by the customer. The BCP offer is different: cloud instances run permanently and take over if a server goes down, with no change of IP address, which comes close to service continuity. Replication or synchronisation of data between the BCP instance and the original server is not built in: it relies on a specific process, tailored to your needs, which WeDoBack can set up on quotation. The DRP offer restarts servers on standby instances from a chosen backup version. In both cases, the backup history remains the way to return to a state prior to the incident.
Frequently asked questions
If I replicate my server to a second site, do I still need a backup?
Yes. The second site protects you against a hardware failure or a disaster at the first one. It does not protect you against a deleted file, a corrupted database or ransomware: the replica receives those changes like any others. Only a backup history lets you go back to before the incident.
Is OneDrive or Dropbox synchronisation a backup?
No. Synchronisation copies the current state in both directions: a file deleted or encrypted on the computer is also deleted or encrypted in the cloud. The service’s versions and recycle bin help with an isolated error, for a limited time, but they remain under the same accounts as production.
Does delayed replication protect against ransomware?
Only if the attack is detected before the delay runs out, often a few minutes or a few hours. Yet an intrusion usually goes unnoticed for several days. A replication delay is no substitute for several weeks of history.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- Recoverable Items folder in Exchange Online — Microsoft Learn
- Restore a user’s permanently deleted email — Google Workspace Admin Help
- BCP offer (Business Continuity Plan) — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
