Home›Guides›IT backup

IT backup

Why keep an off-site backup?

An off-site backup exists so that an event that destroys the production site, physically or logically, still leaves a copy elsewhere. Without it, the backup protects against a disk failure, but neither against the loss of the building nor against an attacker already inside the network.

Updated October 20263 min read5 sources cited

Key points

  • Off-site covers fire, flooding, theft and some attacks on the local network.
  • It only protects against ransomware if compromised accounts cannot delete it: offline or immutable.
  • Choose a distance that avoids the same disaster as the main site.
  • It replaces neither monitoring, nor a sufficient history, nor a DRP to restart the service.

The scenarios an off-site backup covers

Physical disaster. Fire, flooding, structural collapse, theft with removal of the machines. Everything in the same premises is lost at once, including the “emergency” external disks in the drawer. CERT-MU, the Mauritian national computer emergency response team, recommends in its backup guideline keeping at least one copy off site: storing backups in the same place as the original data is a mistake to avoid.

Narrow regional disaster. A copy at the neighbour across the landing or on the same electrical transformer can go down with you. The useful distance depends on the risk: a few kilometres are enough for a fire in the premises, not for a flood across an area. The NIST contingency planning guide asks you to consider the likelihood that the storage location is affected by the same disaster as the main site.

Attack on the network. Modern ransomware looks for backups. It uses privileged accounts, mounted shares and consoles left open. Mandiant observed in 2025 that ransomware groups now target backup infrastructure and delete backups stored in the cloud, to make restoration impossible. An off-site copy only protects you if these accounts cannot delete it. Otherwise, “off-site” simply means “another IP address, same credentials”.

Local operating error. A format, a replaced storage array, a clean-up script with too wide a scope. The remote copy, especially if it is immutable for a period, gives you time to notice.

The scenarios an off-site backup does not cover on its own

  • A backup that has been failing for three weeks without anyone reading the reports.
  • A lost decryption key.
  • A history that is too short: last night’s off-site copy is already encrypted, and there is no version from a month ago. See How long should you keep backups?.
  • The need to keep working within the hour. The off-site copy lets you restore. It does not switch on a replacement server. Resuming the service is the job of the DRP or BCP.

Off-site and offline

Two different properties:

  • Off-site: another location.
  • Offline or immutable: the copy cannot be continuously modified from the production network. The ANSSI, France’s national cybersecurity agency, defines an offline backup as a backup on a medium disconnected from any information system.
On site, onlineOff site, onlineOff site, immutableOffline
Fire in the premisesLostProtectedProtectedProtected if stored elsewhere
Stolen administrator accountExposedExposed if same credentialsProtected until expiryProtected
Restoration speedVery highHighHighSlower

A cloud copy reachable with the domain administrator’s password is off site and online. It is already a major improvement against fire. Against ransomware, it must also refuse deletion for a period, or require an identity the attacker does not have. The ANSSI recommends an offline copy, or at least an online off-site copy under certain conditions; for an online copy, it considers a WORM solution acceptable, the offline copy remaining the most robust.

At WeDoBack

Copies are kept outside the production network, on servers dedicated to backup, replicated across several separate sites. The client can require a region imposed by law. The IMMUTABLE offer prevents modification and deletion for the chosen period, up to ten years, which addresses the case where backup credentials are stolen. Encryption takes place on the machine before the data leaves, with a key held by the client. To restart servers on standby instances from a copy, see the DRP offer.

Frequently asked questions

Does my software vendor’s cloud count as an off-site backup?

Only if it keeps a history, under credentials separate from yours, and you can restore an earlier version from it. A sync service or a file-sharing space, even hosted elsewhere, replicates deletions and encryption: it is off-site, but it is not a backup.

Are off-site and offline the same thing?

No. Off-site means another location; offline means a medium disconnected from any information system. The ANSSI, France’s national cybersecurity agency, recommends at least one offline copy or, failing that, an online off-site copy protected against deletion, for example by WORM storage.

Do attackers really target backups?

Yes. Mandiant’s M-Trends 2026 report describes ransomware groups that target backup infrastructure, delete backup objects in cloud storage and attack the directory and virtualisation layers, to prevent any restoration and force payment.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.