What is an IT backup?
An IT backup is a copy of data made to be restored: on the day the original disappears, is changed by mistake or is encrypted in an attack, it lets you return to an earlier state. Until someone has restored a file and checked that it opens, you have a data transfer, not a proven backup.
Updated October 20264 min read5 sources cited
Key points
- A real backup is separate from the original, keeps several dates and is restored using a known procedure.
- The ANSSI, France’s national cybersecurity agency, recommends the 3-2-1 rule: three copies, two different media, one of them offline.
- RAID, synchronisation and the Microsoft 365 recycle bin are not backups.
- Frequency sets the acceptable data loss (RPO); the restore method sets the downtime (RTO).
- A backup that has never been restored, or whose key has been lost, proves nothing.
What the copy must make possible
Three properties distinguish a backup from a mere duplicate:
- It is separate from the original. A second disk in the same server, or the software’s recycle bin, suffers the same fire, the same power failure and often the same ransomware. CERT-MU recommends keeping an off-site copy, and the Data Protection Act 2017 (section 31) requires appropriate security measures against the loss or destruction of personal data.
- It keeps a history. You must be able to go back to Tuesday at 6 pm, not only to the latest copy, which may already contain the damaged file.
- It can be restored by someone who knows the procedure. The medium, the software, the password and the encryption key must be available on the day of the incident, not only on the day of installation. The ANSSI, France’s national cybersecurity agency, requires backups to be tested regularly and a restore procedure to be written and put into practice.
A backup covers files, databases, mailboxes, or an entire machine (system, applications, accounts, settings). Restoring files alone means reinstalling the server before putting them back. Restoring a system image returns the machine to working order.
The 3-2-1 rule
CERT-MU recommends an off-site copy and regular restore tests; the ANSSI, France’s national cybersecurity agency, formalises these principles in the so-called “3-2-1” rule:
- 3 copies of the data: production and two backups;
- 2 different media;
- 1 offline copy, that is, on a medium disconnected from any information system.
copies of your data
different media
offline copy
Recommendation of the ANSSI (France’s national cybersecurity agency)
The ANSSI considers this offline copy essential, even if it is made less often than the others. The calculation is explained in How many backups should you keep?.
Three things that are often confused
| Operation | Purpose | History |
|---|---|---|
| Backup | Return to an earlier state | Yes, several dates |
| Replication | Have a near-identical copy, immediately | Usually not: the copy follows the original, including its errors |
| Archiving | Keep evidence or a document over the long term | Yes, but the aim is preservation, not resuming operations the next day |
Details are in backup and replication and backup and archiving.
Full, incremental, differential
There are three methods:
- Full: everything is copied. Restoring is simple. It takes time and space.
- Incremental: only the changes since the last backup, of whatever type, are copied. It is lightweight. A restore replays the full backup and then each increment.
- Differential: the changes since the last full backup are copied. It grows over the week. A restore replays the full backup and the latest differential.
A common practice is to combine daily incremental backups with regular full backups.
Frequency sets the RPO (how much work you are prepared to redo). Restore time sets the RTO (how long operations can remain stopped). The ANSSI refers to the maximum tolerable data loss and the maximum tolerable period of disruption. Both targets are chosen business process by business process: Friday evening’s accounting and Saturday lunchtime’s till server do not have the same RPO. See What is an RTO?.
What a backup does not do
It does not replace an antivirus, a firewall or separate administrator accounts. It does not keep the service running during the outage: that is the role of a disaster recovery plan (DRP) or a business continuity plan (BCP). On its own, it does not satisfy a legal retention obligation: an accounting document that must be kept for the statutory period falls under archiving, with its own integrity rules.
Common mistakes
- Believing that RAID is a backup. RAID protects against a failed disk. It also replicates deletions and malicious encryption.
- Backing up to a share that users and administrators can erase.
- Leaving the backup disk permanently connected. It is advisable to disconnect the medium from the computer or network when it is not in use.
- Never restoring. A backup whose key is lost, or whose software no longer exists, gives nothing back.
- Forgetting cloud email. Microsoft 365 and Google Workspace host email, but they do not keep an unlimited independent history of it: in Exchange Online, a deleted item remains recoverable for 14 days by default, 30 days at most.
Checklist: do you have a real backup?
- A copy exists outside the server and outside the building.
- At least one copy cannot be erased by an everyday account.
- Several dates are available, not only last night.
- A failed backup triggers an alert that someone reads.
- A file has been restored and opened in the last three months.
- The encryption key is stored somewhere other than on the backed-up machine.
At WeDoBack
WeDoBack backs up Windows and Linux servers, physical or virtual, Windows and macOS workstations, NAS devices and Microsoft 365 or Google Workspace mailboxes. Data is encrypted on the client’s machine, with a key that only the client holds, then stored on servers dedicated to backup, separate from the client’s production and redundant. Restores can cover files or the entire server, including the system and applications. Frequency and retention period can be set within the limits of the subscribed volume. The SMART and INTEGRAL offers are detailed on the offers and prices page.
Frequently asked questions
Is RAID or a second disk enough as a backup?
No. RAID protects against a disk failure, not against a deletion, a fire or ransomware: it immediately copies the error to every disk. A backup must be on another medium, in another place, with a history.
How often should you back up?
Frequency depends on how much work you are prepared to redo. For most SME servers, one backup a day is a minimum; a database updated continuously needs several. A common practice combines daily incremental backups with full backups at regular intervals.
Do Microsoft 365 or Google Workspace back up my emails?
They host and protect the service, but their recycle bins have limited retention periods. In Exchange Online, deleted items remain recoverable for 14 days by default, 30 days at most. Beyond that, or if an administrator account is compromised, only a copy outside the tenant lets you go back.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI (France’s national cybersecurity agency)
- Guideline on devising a personal backup plan (CMSGu2017-03) — CERT-MU
- Introductory Guide to the Data Protection Act 2017 — Data Protection Office (Mauritius)
- Recoverable Items folder in Exchange Online — Microsoft Learn
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
