Why make an offsite backup?
An offsite backup exists so that an event that destroys the production site, physically or logically, still leaves a copy elsewhere. Without it, your backup protects you from a disk failure, but neither from the loss of the building nor from an attacker already inside the network.
Updated October 20263 min read5 sources cited
Key points
- An offsite copy covers fire, flooding, theft and some attacks on the local network.
- It only protects against ransomware if compromised accounts cannot delete it: offline or immutable.
- Choose a distance that avoids the same disaster as the main site.
- It replaces neither monitoring, nor a sufficient history, nor a DRP to restart the service.
The scenarios an offsite copy covers
Physical disaster. Fire, flooding, structural collapse, theft with removal of equipment. Everything in the same premises is lost at once, including the “emergency” external disks in the drawer. The CNIL, France’s data protection authority, lists storing backups in the same place as the original data among the mistakes to avoid, and recommends at least one copy in a geographically separate location.
Narrow regional disaster. A copy held by the office next door or on the same electricity substation can go down with you. The useful distance depends on the risk: a few kilometres are enough for a fire in your premises, but not for area-wide flooding. The NIST contingency planning guide asks you to take into account the likelihood that the storage site is hit by the same disaster as the main site.
An attack on the network. Modern ransomware looks for backups. It uses privileged accounts, mounted shares and consoles left open. In 2025 Mandiant observed that ransomware groups now target backup infrastructure and delete backups stored in the cloud to make restoring impossible. An offsite copy only protects you if these accounts cannot delete it. Otherwise, “offsite” simply means “a different IP address, the same credentials”.
A local operating error. A format, a replaced storage array, a clean-up script with too broad a scope. The remote copy, especially if it is immutable for a set period, gives you time to notice.
The scenarios an offsite copy does not cover on its own
- A backup that has been failing for three weeks without anyone reading the reports.
- A lost decryption key.
- A history that is too short: last night’s offsite copy is already encrypted, and there is no version from a month ago. See How long should you keep your backups?.
- The need to keep working within the hour. The offsite copy lets you restore. It does not start a replacement server. Resuming the service is the job of the DRP or the BCP.
Offsite and offline
Two different properties:
- Offsite: another location.
- Offline or immutable: the copy cannot be continuously modified from the production network. The ANSSI, France’s national cybersecurity agency, defines an offline backup as a backup on a medium disconnected from any information system.
| On site, online | Offsite, online | Offsite, immutable | Offline | |
|---|---|---|---|---|
| Fire in the premises | Lost | Protected | Protected | Protected if stored elsewhere |
| Stolen administrator account | Exposed | Exposed if same credentials | Protected until expiry | Protected |
| Restore speed | Very high | High | High | Slower |
A cloud copy reachable with the domain administrator’s password is offsite and online. Against fire, it is already a major improvement. Against ransomware, it must also refuse deletion for a set period, or require an identity the attacker does not have. The ANSSI recommends an offline copy, or at least an online offsite copy under certain conditions; for an online copy, it considers a WORM solution an option, while the offline copy remains the most robust.
At WeDoBack
Copies are kept outside the production network, on servers dedicated to backup, replicated across several European countries. The client can require a region imposed by law. The IMMUTABLE offer prevents modification and deletion for the chosen period, up to ten years, which addresses the case where backup credentials are stolen. Encryption takes place on the machine before the data leaves, with a key held by the client. To restart servers on standby instances from a copy, see the DRP offer.
Frequently asked questions
Does my software vendor’s cloud count as an offsite backup?
Only if it keeps a history, under credentials separate from yours, and you can restore an earlier version from it. A synchronisation or file-sharing space, even hosted elsewhere, replicates deletions and encryption: it is offsite, but it is not a backup.
Are offsite and offline the same thing?
No. Offsite means another location; offline means a medium disconnected from any information system. The ANSSI, France’s national cybersecurity agency, recommends at least one offline copy or, failing that, an online offsite copy protected against deletion, for example by WORM storage.
Do attackers really target backups?
Yes. Mandiant’s M-Trends 2026 report describes ransomware groups that target backup infrastructure, delete backup objects in cloud storage and attack the directory and virtualisation layers, in order to prevent any restore and force payment.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- M-Trends 2026: Data, Insights, and Strategies From the Frontlines — Mandiant (Google Cloud)
- Security: back up your data — CNIL
- IMMUTABLE offer: WORM storage and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
