Home›Guides›IT backup

IT backup

Where should you store your backups?

The right location is the one that survives the disaster you fear. A fire in the server room wipes out the server and the disk plugged in next to it; ransomware wipes out everything the compromised account can modify, including a “backup” NAS left on the same network. The location is therefore chosen scenario by scenario, not according to the price of the disk.

Updated October 20263 min read5 sources cited

Key points

  • Combine a local copy for fast restores with an offsite copy for disasters.
  • At least one copy must be offline or immutable: this is recommended by the CNIL (France’s data protection authority) and the ANSSI (France’s national cybersecurity agency).
  • Choose a distance suited to the risk: NIST requires a location that will not be hit by the same disaster as the main site.
  • Encrypt before sending and keep the key somewhere other than on the machine being backed up.
  • Require the storage country in writing; for an outsourced backup, the ANSSI expects data to be located within the European Union.

Four locations, and what they protect against

LocationProtects againstDoes not protect against
Second disk or RAID in the same serverA failed diskFire, theft, deletion, ransomware
NAS in the same buildingA server failureFire, flood, an attack that reaches the NAS
Disk or tape taken offsiteA disaster affecting the buildingMissed rotation, loss, slowness, a stolen bag
Outsourced, encrypted copy, separate from internal accountsLocal disasters and many attacks from inside the networkLoss of the key, unreachable provider, copy too old

The combination that works: a fast local copy to restore a file within the hour, and an offsite copy for the day the building or the network can no longer be trusted. At least one of the two must be immutable or offline. The CNIL lists keeping backups in the same place as the original data, or on the same systems without isolation, among the mistakes to avoid. Cybermalveillance.gouv.fr, the French government’s cybercrime assistance platform, advises disconnecting the backup medium from the network when it is not in use.

Geography matters as much as the building

“Offsite” can still mean the same neighbourhood, the same electricity supplier, the same valley flood. For a regional disaster, copies are better kept in distant locations. NIST’s contingency planning guide (SP 800-34) makes distance, and the likelihood that the storage location will suffer the same disaster as the main site, the first selection criterion.

Where there is a data residency obligation (healthcare, public sector, contractual clause, law of the customer’s country), the location must be chosen, not imposed on you. For an outsourced backup, the ANSSI calls for checking that the data is located within the European Union. “Somewhere in the cloud” is no answer for an auditor who asks for the country.

Encryption before sending changes how much trust you need to place in the location: the provider stores data it cannot read if the key stays with the customer. The ANSSI recommends looking closely at key management (storage, backup, offline copy). That key must therefore be kept somewhere other than on the machine being backed up.

What to require from the location

NIST lists five criteria for an offsite storage location: geographic area, accessibility (time needed to retrieve the data, opening hours), security, environment (temperature, fire, power supply) and cost. Translated for an SME:

  • Authenticated and logged access.
  • Redundancy: the backup copy itself does not rely on a single disk.
  • Monitoring: a write failure is reported.
  • A known restore time for the actual volume, not just the theoretical throughput of a link.
  • Hours during which someone can help you restore.
  • An exit route: getting your data back if you change provider, in a format you know how to read.

At WeDoBack

Backups are stored on servers dedicated to this purpose, separate from the customer’s production, and made redundant across several European countries. If the law of the country or sector requires a specific zone, storage can be deployed there. Data is encrypted on the customer’s machine before it is sent; the key stays with the customer. The hosting centres and solutions used are certified ISO 27001 and HDS (the French certification for hosting health data). For a copy that no one can delete, the IMMUTABLE offer can be added to the backup. This is not collaborative file storage: the space is used for restoring, not for day-to-day work on documents.

Frequently asked questions

Is a NAS in the same office a good backup location?

It is a good first level, for quickly restoring a file or a server. It is not enough on its own: it shares the premises, the power supply and often the credentials of the production network. You need a second offsite copy, and one of the two must be offline or non-erasable.

How far away should the offsite copy be stored?

Far enough not to be affected by the same disaster. A few kilometres are enough for a fire on the premises; a valley flood or a regional power outage calls for a different area. NIST cites distance and the likelihood of a shared disaster as the first selection criterion.

Can you take a backup disk home?

Yes, it is a form of offsite and offline copy, provided the disk is encrypted, the rotation is actually carried out and someone else knows where it is. The risks are forgetting, losing or having the disk stolen, and a slower restore.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.