Home›Guides›IT backup

IT backup

Where should you store your backups?

The right location is the one that survives the disaster you fear. A fire in the server room wipes out the server and the disk plugged in next to it; ransomware wipes out everything the compromised account can modify, including a “backup” NAS left on the same network. The location is therefore chosen scenario by scenario, not according to the price of the disk.

Updated October 20263 min read5 sources cited

Key points

  • Combine a local copy for fast restores with an off-site copy for disasters.
  • At least one copy must be offline or immutable: the ANSSI, France’s national cybersecurity agency, recommends it.
  • Choose a distance suited to the risk: NIST calls for a location that would not be hit by the same disaster as the main site.
  • Encrypt before sending and keep the key somewhere other than on the backed-up machine.
  • Require the storage country in writing: outside Mauritius, it is a transfer governed by section 36 of the Data Protection Act 2017.

Four locations, and what they protect against

LocationProtects againstDoes not protect against
Second disk or RAID in the same serverA failed diskFire, theft, deletion, ransomware
NAS in the same buildingA server failureFire, flood, an attack that reaches the NAS
Disk or tape taken off siteA disaster affecting the buildingForgotten rotation, loss, slowness, theft of the bag
Outsourced, encrypted copy, separate from internal accountsLocal disasters and many attacks from inside the networkLoss of the key, unreachable provider, copy too old

The combination that holds up: a fast local copy to restore a file within the hour, and an off-site copy for the day the building or the network can no longer be trusted. At least one of the two must be immutable or offline. CERT-MU recommends keeping an off-site copy, separate from the original data. Also disconnect the backup medium from the network when it is not in use.

Geography matters as much as the building

“Off-site” can still mean the same neighbourhood, the same electricity supplier, the same valley flood. For a regional disaster, copies are better kept in distant locations. The NIST contingency planning guide (SP 800-34) makes distance, and the likelihood that the storage location will suffer the same disaster as the main site, the first selection criterion.

Where there is a data residency obligation (health, public sector, contractual clause, law of the client’s country), the location must be chosen, not simply accepted. In Mauritius, storage outside the country is a transfer governed by section 36 of the Data Protection Act 2017 (appropriate safeguards): check where the data is. “Somewhere in the cloud” is no answer for an auditor who asks for the country.

Encryption before sending changes how much trust you need to place in the location: the provider stores data it cannot read if the key stays with the client. The ANSSI, France’s national cybersecurity agency, recommends examining key management (storage, backup, offline copy). This key must therefore be kept somewhere other than on the backed-up machine alone.

What to require from the location

NIST sets out five criteria for an off-site storage location: geographic area, accessibility (time needed to retrieve the data, opening hours), security, environment (temperature, fire, power supply) and cost. Translated for an SME:

  • Authenticated, logged access.
  • Redundancy: the backup copy itself does not rely on a single disk.
  • Monitoring: a write failure is reported.
  • A known restore time for the actual volume, not just the theoretical throughput of a link.
  • Hours during which someone can help you restore.
  • An exit path: recovering the data if you change provider, in a format you know how to read.

At WeDoBack

Backups are stored on servers dedicated to this purpose, separate from the client’s production, and replicated across several distinct sites, or within the area required by the client’s legislation. The storage location is agreed with the client; outside Mauritius, it is a transfer governed by section 36 of the Data Protection Act 2017. Data is encrypted on the client’s machine before it is sent; the key stays with the client. The data centres and solutions used are ISO 27001 and HDS (French health data hosting) certified. For a copy that no one can delete, the IMMUTABLE offer can be added to the backup. It is not collaborative file storage: the space is used for restoring, not for working on documents day to day.

Frequently asked questions

Is a NAS in the same office a good backup location?

It is a good first level, for quickly restoring a file or a server. On its own it is not enough: it shares the room, the power supply and often the credentials of the production network. You need a second, off-site copy, and one of the two must be offline or non-erasable.

How far away should the off-site copy be stored?

Far enough not to suffer the same disaster. A few kilometres are enough for a fire on the premises; a valley flood or a regional power outage calls for a different area. NIST cites distance and the likelihood of a shared disaster as the first selection criterion.

Can you take a backup disk home?

Yes, it is a form of off-site and offline copy, provided the disk is encrypted, the rotation is actually carried out and someone else knows where it is. The risks are forgetting it, losing it or having it stolen, and a slower restore.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.