What is an IT backup?
An IT backup is a copy of data made to be restored: on the day the original disappears, is changed by mistake or is encrypted in an attack, it lets you return to an earlier state. Until someone has restored a file and checked that it opens, what you have is a data transfer, not a proven backup.
Updated October 20264 min read5 sources cited
Key points
- A real backup is separate from the original, keeps several dates and is restored using a known procedure.
- The ANSSI (France’s national cybersecurity agency) and the CNIL (France’s data protection authority) recommend the 3-2-1 rule: three copies, two different media, one of them offline.
- RAID, file synchronisation and the Microsoft 365 recycle bin are not backups.
- Frequency sets the acceptable data loss (RPO); the restore method sets the downtime (RTO).
- A backup that has never been restored, or whose key has been lost, proves nothing.
What the copy must make possible
Three properties distinguish a backup from a mere duplicate:
- It is separate from the original. A second disk in the same server, or the software’s recycle bin, suffers the same fire, the same power failure and often the same ransomware. The CNIL lists storing backups in the same place as the original data among the mistakes to avoid.
- It keeps a history. You must be able to go back to Tuesday at 6 p.m., not just to the latest copy, which may already contain the damaged file.
- It can be restored by someone who knows the procedure. The medium, the software, the password and the encryption key must be available on the day of the incident, not just on the day of installation. The ANSSI requires backups to be tested regularly and a restore procedure to be written and put into practice.
A backup covers files, databases, mailboxes, or an entire machine (system, applications, accounts, settings). Restoring files alone means reinstalling the server before putting them back. Restoring a system image brings the machine back into service.
The 3-2-1 rule
The ANSSI and the CNIL both recommend the so-called “3-2-1” rule:
- 3 copies of the data: production and two backups;
- 2 different media;
- 1 offline copy, that is, on a medium disconnected from any information system.
copies of your data
different media
offline copy
Recommended by the ANSSI and the CNIL
The ANSSI considers this offline copy essential, even if it is made less often than the others. The detailed calculation is in How many backups should you keep?.
Three operations that are often confused
| Operation | Purpose | History |
|---|---|---|
| Backup | Return to an earlier state | Yes, several dates |
| Replication | Have a near-identical copy, immediately | Usually not: the copy follows the original, errors included |
| Archiving | Keep evidence or a document over the long term | Yes, but the goal is preservation, not getting the business running again the next day |
Details are in backup and replication and backup and archiving.
Full, incremental, differential
Cybermalveillance.gouv.fr, the French government’s cybercrime assistance platform, distinguishes three methods:
- Full: everything is copied. Restoring is simple. It takes time and space.
- Incremental: only the changes since the last backup, whatever its type, are copied. It is lightweight. A restore replays the full backup and then each increment.
- Differential: the changes since the last full backup are copied. It grows over the week. A restore replays the full backup and the latest differential.
The CNIL recommends combining daily incremental backups with regular full backups.
Frequency sets the RPO (how much work you are prepared to redo). Restore time sets the RTO (how long the business can remain at a standstill). The ANSSI refers to the maximum tolerable data loss and the maximum tolerable period of disruption. Both targets are chosen activity by activity: Friday evening’s accounting and the Saturday lunchtime till server do not have the same RPO. See What is an RTO?.
What a backup does not do
It does not replace antivirus software, a firewall or separate administrator accounts. It does not keep the service running during the outage: that is the role of a disaster recovery plan (DRP) or a business continuity plan (BCP). On its own, it does not satisfy a legal retention obligation: an accounting document that must be kept for ten years falls under archiving, with its own integrity rules.
Common mistakes
- Believing RAID is a backup. RAID protects against a failed disk. It also replicates deletions and malicious encryption.
- Backing up to a share that users and administrators can erase.
- Leaving the backup disk permanently connected. Cybermalveillance.gouv.fr advises disconnecting the medium from the computer or network when it is not in use.
- Never restoring. A backup whose key has been lost, or whose software no longer exists, gives nothing back.
- Forgetting cloud email. Microsoft 365 and Google Workspace host your email, but they do not keep an unlimited independent history of it: in Exchange Online, a deleted item remains recoverable for 14 days by default and 30 days at most.
Checklist: do you have a real backup?
- A copy exists outside the server and outside the building.
- At least one copy cannot be erased by an everyday account.
- Several dates are available, not just last night’s.
- A failed backup triggers an alert that someone reads.
- A file has been restored and opened within the last three months.
- The encryption key is kept somewhere other than on the machine being backed up.
At WeDoBack
WeDoBack backs up Windows and Linux servers, physical or virtual, Windows and macOS workstations, NAS devices, and Microsoft 365 or Google Workspace mailboxes. Data is encrypted on the customer’s machine, with a key that only the customer holds, and then stored on redundant servers dedicated to backup and separate from the customer’s production. Restores can cover individual files or the entire server, including the system and applications. Backup frequency and retention period can be set within the limits of the subscribed volume. The SMART and INTEGRAL offers are described on the offers and prices page.
Frequently asked questions
Is RAID or a second disk enough as a backup?
No. RAID protects against a disk failure, not against deletion, fire or ransomware: it immediately copies the error to every disk. A backup must be on another medium, in another location, with a history.
How often should you back up?
Frequency depends on how much work you are prepared to redo. For most SME servers, one backup a day is a minimum; a database updated continuously needs several. The CNIL recommends daily incremental backups and full backups at regular intervals.
Do Microsoft 365 or Google Workspace back up my emails?
They host and protect the service, but their recycle bins have limited retention periods. In Exchange Online, deleted items remain recoverable for 14 days by default and 30 days at most. Beyond that, or if an administrator account is compromised, only a copy outside the tenant lets you go back.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI
- Why and how to manage your backups properly — Cybermalveillance.gouv.fr
- Security: back up your data — CNIL
- Recoverable Items folder in Exchange Online — Microsoft Learn
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
