How can you tell whether a business is really protected against data loss?
A business is really protected if, for the systems that run its operations, it can show a recent successful restore, a copy that does not share the fate of the server, and a person able to do it again without improvising. The volume purchased, the software logo or the phrase “we are backed up” are not enough to conclude.
Updated October 20263 min read6 sources cited
Key points
- Protection is judged within a defined scope: the short list of systems without which operations stop.
- Nine questions are enough; a vague answer counts as a no.
- If an everyday administrator account can erase a copy, ransomware will be able to erase it too.
- More than twelve months without a restore test: protection is an assumption.
- Insurers and auditors mainly ask for the report of the last test, not the product name.
The decisive questions
Ask them of management and of the person who administers the systems. Vague answers count as a no.
- Which systems, if lost tonight, would stop operations tomorrow? Without a short list, protection has no scope. Every backup plan starts there: identifying the devices and data to be backed up.
- When was the last successful backup of each one? “Normally last night” is not a date. A screen or an alert email is.
- Where is the copy if the building burns down? Same room, same administration network, or another location. CERT-MU recommends keeping a copy off site.
- Can an everyday administrator account erase that copy? If so, ransomware will be able to as well. The ANSSI, France’s national cybersecurity agency, calls for dedicated backup accounts and at least one offline copy.
- When did you last carry out a real restore, of what, and how long did it take? More than twelve months without a test: protection is an assumption.
- Who has the encryption key and the instructions if that person is on leave? A single key in one employee’s head is a single point of failure. The ANSSI recommends defining who holds the keys, where they are stored and how they are backed up.
- What downtime does management accept, and did the last restore fit within it? If not, the RTO is a wish.
- Is cloud email within the scope? Many businesses protect the file server and forget Microsoft 365 or Google Workspace, where the real work happens.
- What happens at weekends? An alert that is only read on Monday delays the discovery of a failure by the same amount.
A simple score
| Answer | Interpretation |
|---|---|
| List of systems, off-site copy, immutability or offline copy, test less than twelve months old, two capable people | Real protection within the listed scope |
| Software in place, green logs, no tests, copy on the local NAS | Protection against a minor disk failure only |
| “The provider takes care of it”, with no contractual response time and no test | Unverified protection |
| No copy of cloud email | Gap in the main working tool |
Protection always applies within a scope. An SME may be very well protected on its ERP and completely exposed on the computers of two sales staff. Saying so is more useful than an overall percentage.
What an external audit also looks at
Cyber insurers and auditors generally ask for the same evidence: backup architecture, retention period, result of the last test, management of console access, and incident procedure. They rarely ask for the product name. They ask for the report of the last test.
The incident procedure must also cover the formalities: reporting on MAUCORS+, the national platform run by CERT-MU (hotline 800 2378), filing a complaint with the Cybercrime Unit of the Mauritius Police Force before reinstalling the machines, and, if you have cyber insurance, declaring the claim within the time limit and with the supporting documents set out in your policy.
For critical information infrastructure, this is no longer just a matter of good practice: in Mauritius, the Cybersecurity and Cybercrime Act 2021 (sections 33 to 37) requires disaster recovery measures, data archiving, annual audits and reporting of serious incidents.
At WeDoBack
The service provides the encrypted off-site copy, on servers dedicated to backup and replicated in several European countries (transfer outside Mauritius governed by section 36 of the Data Protection Act 2017), and 24/7 backup monitoring with an alert in the event of failure. If subscribed, it adds immutability, restart on standby instances (DRP) or takeover by continuously running instances (BCP). It does not replace answers 1, 5 and 6: the scope, the test and the safekeeping of the key remain the customer’s responsibility. INTEGRAL includes two hours of support per month to help with these tasks. SMART leaves operations to the customer and bills support per intervention. Support can be reached on +33 9 72 50 78 28 from 9 am to 1 pm and from 2 pm to 5:30 pm (Paris time), i.e. from 11 am to 3 pm and from 4 pm to 7:30 pm Mauritius time during European summer time, one hour later during European winter time. In any case, a business that has never restored is not “protected by WeDoBack”. It has a subscription.
Frequently asked questions
Is having an IT service provider enough to be protected?
No, not in itself. Check what the contract actually provides: scope of the backup, location of the copies, retention period, restore tests, response time. Ask for the report of the last test. Without these elements, the protection has not been verified.
Is my business covered by the Cybersecurity and Cybercrime Act 2021?
In Mauritius, this law (Act No. 16 of 2021) requires critical information infrastructure to have disaster recovery measures, data archiving, annual audits and reporting of serious incidents (sections 33 to 37). A business operating in the European Union may also fall under the NIS 2 Directive. Even outside their scope, these requirements are a good benchmark.
Where should you start if the answers are poor?
With the list of critical systems, then a test restore of the most important one. This first test almost always reveals the real gaps: missing copy, key that cannot be found, time too long. Then fix them in that order.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025, in French) — ANSSI, France’s national cybersecurity agency
- Guideline on devising a personal backup plan (CMSGu2017-03) — CERT-MU
- MAUCORS+: report a cybersecurity incident — CERT-MU
- Cybersecurity and Cybercrime Act 2021 (Act No. 16 of 2021) — ICT Authority (Mauritius)
- Cybercrime Prevention in Mauritius — Mauritius Police Force
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
