Should you outsource your backups?
Yes, if the loss of your premises or a compromise of the internal network must still leave at least one restorable copy. Outsourcing does not rule out a local copy: it prevents all copies from sharing the same fate as production.
Updated October 20263 min read5 sources cited
Key points
- Outsource the recovery copy and the history; keep a recent copy on site for small restores.
- Require in writing: the country where copies are held, a non-deletable copy, the measured restoration time, and the contract exit terms.
- The ANSSI, France’s national cybersecurity agency, recommends encrypting before sending and checking where the data is located. In Mauritius, storage outside the country is a transfer governed by section 36 of the Data Protection Act 2017.
- The provider is a processor within the meaning of the Data Protection Act 2017: a written contract must provide for the deletion or return of the data at the end of the service.
- Do not store the encryption key in the same vault as the data.
When outsourcing changes the outcome
- Fire, water damage, theft of equipment: the backup NAS in the same room is lost along with the servers.
- Ransomware that came in through an administrator account: it encrypts mounted shares, including “Backup” on the network.
- Absence of the only employee who swapped the disks: rotation stops without management knowing.
- A requirement to keep data in a specific country or region, without running a second site yourself.
A company that already has two distant buildings, a team, and an immutable copy that is genuinely offline can outsource less. This is rare in an SME.
What to outsource, and what to keep
Outsource the recovery copy and the history. If bandwidth allows, keep a recent copy on site to restore a file without waiting for several terabytes to download. Also outsource cloud email backup to a party other than the email provider: staying in the same tenant means remaining exposed to the same administrator accounts. See Should you back up Microsoft 365?.
Do not outsource the encryption key to the same logical vault as the data, nor leave the only administration password with the provider without a written procedure.
What the ANSSI recommends for an off-site backup
The backup guide of the ANSSI, France’s national cybersecurity agency, devotes a table to off-site backups held by a cloud host or a subcontractor. The points to watch:
| Point to watch | What to check |
|---|---|
| Data sensitivity | Encryption before sending to the provider |
| Location | Storage country known and stated in the contract; outside Mauritius, a transfer governed by section 36 of the Data Protection Act 2017 |
| Restoration time | Compatible with the maximum tolerable downtime, including the restoration priority set out in the contract |
| Resistance to deletion | A WORM (non-modifiable) solution can be considered, with separate administration accounts |
| Offline copy | Still considered more robust; an acceptable compromise combines regular WORM copies with less frequent offline copies |
In Mauritius, the Data Protection Act 2017 (section 31) requires appropriate security measures against the loss or destruction of data: encrypt transmission channels when backups leave the organisation, and protect them to the same level as production servers. CERT-MU also recommends an off-site copy and regular restore tests.
The limits, stated plainly
- Bandwidth. The first backup of a large volume takes time. Subsequent ones only send the changes, if the software is incremental. A connection that is too slow also lengthens a full restore.
- Dependency. On the day of the incident, you depend on the provider’s opening hours, the contract and the provider’s ability to read back its copies. NIST lists accessibility (recovery time and hours) among the criteria for choosing off-site storage. A restore test before a disaster is the only honest test.
- Recurring cost. You pay every month for the volume retained. Five-year retention of an entire server costs as much as poorly targeted archiving.
- Responsibility for the data. The contract must state where the data is, who can access it, and how it is erased at the end of the contract. Under the Data Protection Act 2017, the provider is a processor: it acts on instructions, is bound by the security obligations of section 31 and must be registered with the Data Protection Office. A written contract must provide for the deletion or return of the data at the end of the service. Encryption with a key you hold reduces what the provider can read; it does not remove your obligations.
How to choose
Ask for four things, in writing: the country where copies are held, whether a non-deletable copy is possible, the measured time to restore a volume like yours, and what happens if you leave. Talk of “high security” without these four answers is no basis for a decision.
If the goal is to restart the service, not just recover the data, also read Outsourced DRP: advantages and limits.
At WeDoBack
Off-site backup is the core service: copies leave the client’s network, are encrypted on the machine before they leave, and are replicated across several separate sites, or within the region required by the client’s legislation. The data centres and solutions used are ISO 27001 certified (and HDS, the French certification for hosting health data). SMART leaves operations to the client, with support billed per intervention. INTEGRAL includes two hours of support per month. Support can be reached on +33 9 72 50 78 28 or at [email protected], from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time), i.e. from 11:00 to 15:00 and from 16:00 to 19:30 Mauritius time during the European summer, and from 12:00 to 16:00 and from 17:00 to 20:30 during the European winter. IMMUTABLE, DRP and BCP are options when a restorable copy is not enough to meet the objective (long-term proof, or resumption of service).
Frequently asked questions
Can the provider read my data?
Not if it is encrypted on your machine before it is sent, with a key that only you hold. The provider then stores unreadable blocks. The flip side is that losing the key makes restoration impossible: it must be kept in several secure places.
How long does a restore from an off-site copy take?
It depends on the volume, the bandwidth of your connection and the method. Restoring a file takes a few minutes; restoring several terabytes over the Internet can take days. The ANSSI, France’s national cybersecurity agency, asks you to check that the restoration time is compatible with the maximum tolerable downtime. Hence the value of a local copy or of restarting on a standby instance.
What happens to my backups if I change provider?
The contract must say so. In Mauritius, the provider is a processor within the meaning of the Data Protection Act 2017: specify in writing that, at the end of the service, it deletes or returns the personal data, as the controller chooses. Plan an overlap period: keep the old history until the new one has reached the required retention period.
Sources
Documents consulted in October 2026.
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI, France’s national cybersecurity agency
- Data Protection Act 2017 (sections 31 and 36) — Data Protection Office (Mauritius)
- SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems — NIST
- Guideline on devising a personal backup plan (CMSGu2017-03) — CERT-MU
- Offers and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
