Home›Guides›IT backup

IT backup

How long should you keep your backups?

To resume operations after a failure, an error or ransomware, thirty days of daily restore points are enough for most SMEs. Retention obligations spanning several years concern specific documents: they are handled through archiving, not by extending each night’s backup indefinitely.

Updated October 20263 min read5 sources cited

Key points

  • 30 days of daily restore points: a useful minimum, because an intrusion often remains hidden for two weeks or more.
  • Beyond three months, keep spaced-out restore points (weekly, monthly), not every night.
  • Legal retention periods (accounting, tax) apply to documents, not to server images.
  • The Data Protection Act 2017 limits the retention of personal data: “just in case” is not a retention period.
  • Write down the period you choose and monitor how full the storage is.

Why thirty days is a useful minimum

Ransomware is not always spotted on the day it strikes. In its M-Trends 2026 report, Mandiant measured a median of 14 days between compromise and detection in 2025, compared with 11 days the year before. A median means that half of all intrusions remain hidden for longer. The same report notes that ransomware groups now target backup infrastructure to prevent restoration.

A seven-day history may therefore contain only copies that are already affected. Thirty days leave a margin to find a healthy version. Fourteen days is a minimum if backups and accounts are genuinely monitored every day.

Beyond three months, the volume becomes expensive and contains a lot of personal data you no longer need for operations. You then keep more widely spaced restore points (one a month) rather than every night.

A practical schedule

HorizonContentUse
24 hoursSeveral restore points if data changes constantlyData entry error during the day
30 daysOne restore point per dayFailure, deletion, recent ransomware
3 to 12 monthsOne restore point per week or per monthLate discovery, short dispute
Several yearsSelected, immutable documentsAccounting, contracts, regulated records

The ANSSI, France’s national cybersecurity agency, gives a similar example breakdown: fifteen days of daily backups, one year of monthly backups and five years of annual backups. Above all, it asks for these retention periods to be defined in a written strategy.

Example for a file server with 1 TB of usable data. With moderate changes, a thirty-day history often weighs between two and four times the usable volume, not thirty times, because incremental backups copy only the changed blocks. The rule of thumb “current volume × 3” is a reasonable starting point, to be adjusted after a week of real measurements.

Do not confuse this with the legal retention period

Keeping years of daily backups does not, on its own, satisfy the obligation to retain accounting books. An inspector expects the documents, readable, not a 2016 system disk. Conversely, deleting a forty-day-old backup does not breach this obligation if the invoices are archived elsewhere.

DocumentLegal period in Mauritius
Accounting books and supporting documentsUnder the Companies Act: to be confirmed with your accountant
Tax documentsUnder the Income Tax Act 1995 (section 153): to be confirmed with your accountant
Payslips (employer’s copy)Under Mauritian labour law: to be checked
Contracts and business correspondenceAccording to limitation periods: to be checked with your adviser

The Data Protection Act 2017 pushes in the other direction: section 27 requires personal data to be destroyed as soon as the purpose has been fulfilled. It therefore cannot be kept indefinitely, and a distinction is made between the active database and intermediate archiving, with restricted access. A mailbox backed up for five years “just in case” may be excessive if no business rule requires it. Details are in What is the difference between backup and archiving?.

What makes the chosen period fail

  • The disk is full: the software deletes old restore points without anyone noticing, or stops backing up.
  • The encryption key has been changed and the old copies have become unreadable.
  • The format or software no longer exists when you want to read an eight-year-old archive.
  • No one has written down the period. Everyone assumes “it is kept for a long time”.
  • The period is short but no restore has been tested: see How do you test that a backup works?.

At WeDoBack

The retention period of the SMART and INTEGRAL offers is set according to the subscribed storage. The client increases or reduces it. To size this storage, the published rule of thumb is the current volume multiplied by three, adjusted after a week of use. For retention without modification, the IMMUTABLE offer sets a period during which no one can modify or delete the data, up to ten years, at €20 excl. VAT per 100 GB block per month, plus one agent.

Frequently asked questions

Is seven days of history enough?

Rarely. In 2025, Mandiant measured a median of 14 days between intrusion and detection: in half of all cases, the attacker was present for longer. With seven days of history, every copy may postdate the intrusion.

Should backups be kept for years for accounting purposes?

No. The legal retention obligation, whose duration should be confirmed with your accountant, covers accounting books and records. Archive these documents separately, in a readable and unmodifiable format, and keep a short history for everything else. It is cheaper and easier to present during an inspection.

What happens when backup storage is full?

Depending on the software, either the oldest restore points are deleted or new backups fail. In both cases, the actual retention period becomes shorter than the written one. An alert on the fill rate and a monthly check avoid unpleasant surprises.

Sources

Documents consulted in October 2026.

  1. Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI (France’s national cybersecurity agency)
  2. M-Trends 2026: Data, Insights, and Strategies From the Frontlines — Mandiant (Google Cloud)
  3. Income Tax Act 1995 (consolidated version) — Mauritius Revenue Authority
  4. Data Protection Act 2017 — Data Protection Office (Mauritius)
  5. IMMUTABLE offer: WORM storage and prices — WeDoBack

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.