Guide · 7 min · For Owners

The short answer: offsite backup vs. cloud backup is a false choice — cloud backup is a form of offsite backup, and the property that actually decides whether you survive ransomware is immutability plus a tested restore, not where the copy sits. The modern target is 3-2-1-1-0: three copies, two media, one offsite, one immutable or offline, zero restore-test errors. Everything below unpacks that.

The terms, untangled

Three words get used loosely. They're not the same thing:

The question "offsite vs cloud" is slightly the wrong question. Cloud is a way to do offsite. The real questions are: do you have a local copy for speed, do you have an offsite copy for disaster survival, and is at least one copy immutable so ransomware can't delete it?

The 3-2-1 rule (and the modern update)

The long-standing rule:

The modern update, 3-2-1-1-0, adds two elements that ransomware made necessary:

Why immutability beats location

Here's the failure mode that catches small businesses: they have a cloud backup, they feel safe, and then ransomware encrypts everything anyway — including the cloud backup.

Modern ransomware doesn't just encrypt the primary data. It hunts for the backup first. It deletes Windows shadow copies, terminates the backup service, and — critically — if it can authenticate to your cloud backup (because the credentials are stored on the compromised machine), it deletes that too. A cloud backup that the attacker can log into and delete is not protected just because it's "in the cloud."

Immutability is the defense. An immutable backup cannot be modified or deleted for a defined retention window — not by the attacker, not by a rogue admin, not by anyone, until the retention expires. That's the property that makes the backup survive the attack. Location (local vs. cloud) is secondary to immutability.

The recommended small-business architecture

For most small businesses, the right backup is a hybrid:

  1. Local appliance — a backup appliance on-site that takes image-level backups of servers and critical workstations on a frequent schedule (every 1–4 hours for servers). This is your fast-restore copy.
  2. Immutable cloud copy — the local appliance replicates to immutable cloud storage on a daily (or more frequent) cadence. This is your disaster-survival and ransomware-proof copy.
  3. SaaS backup — a separate backup of Microsoft 365 or Google Workspace (mail, OneDrive/Drive, SharePoint, Teams). The cloud productivity suite is not backed up for you in the way owners assume.

This gives you: minutes-to-hours restore for routine failures (from the local appliance), survival of a site disaster (the cloud copy), and survival of ransomware (the immutable cloud copy plus immutable local snapshots).

Restore speed: the number that actually matters

Backups are measured by two numbers nobody talks about until they need them:

Set both targets deliberately. A medical clinic that can't see patients without the EHR has a tighter RTO than a back-office that can wait a day. The backup design follows from the targets, not the other way around.

The Microsoft 365 blind spot

The single most common backup gap we find: businesses assume Microsoft backs up their 365 data. Microsoft does not, in the sense owners mean. Microsoft operates a shared-responsibility model — they keep the service available and protect against their own infrastructure failures, but recovering your data from accidental deletion, malicious deletion (a departing employee), or ransomware is your responsibility. Native retention is short.

A separate SaaS backup of Microsoft 365 (and Google Workspace) — mail, OneDrive/Drive, SharePoint, Teams — is a baseline control. The same is true for any cloud LOB application that holds data you can't afford to lose.

How a Micro-IT plan handles backup

Every Micro-IT environment gets image-level backup on servers and critical endpoints to a local appliance, replicated to immutable Datto cloud storage, with retention set per the client's regulatory and operational needs. Restores are tested on a documented cadence (not just scheduled). SaaS backup of Microsoft 365 mailboxes is included in Managed Inbox. RPO and RTO targets are set with the client at onboarding and reviewed quarterly. See backup is the answer; restore is the test for the testing discipline, or the security page for the full stack.

Why store backups offsite at all?

A backup that sits in the same building as the data it protects shares the data's fate. The reason backup media should be stored offsite is simple: anything that destroys the original can destroy a local-only copy in the same event. A fire takes the server and the backup appliance next to it. A flood ruins both. A burglar walks out with the workstation and the external drive in the same bag.

The threat that makes offsite mandatory today is ransomware. Modern attacks don't stop at the production data — they hunt for the backup, delete shadow copies, kill the backup service, and encrypt any backup the compromised network can reach. A local backup on the same network is often reachable, which means it gets encrypted too. An offsite copy that the attacker can't touch — especially an immutable one — is the copy that survives and lets you recover without paying.

So backup media should be stored offsite because offsite is the one copy that outlives a site-wide disaster or a network-wide attack. It is the difference between an inconvenience and a closed business.

How safe are offsite backups?

An offsite backup is only as safe as how it's configured. Location alone is not protection — a cloud copy the attacker can log into and delete is no safer than a local drive. Safety comes from a stack of controls:

Configured this way, an offsite backup is very safe — safer than the production environment it protects. Configured carelessly, it offers false comfort.

What offsite backup costs (and what drives it)

There's no single price for offsite backup, because the cost is driven by three things:

At Micro-IT, restore-tested backup is part of the managed stack rather than a line item you assemble yourself — image-level local backup replicated to immutable cloud storage, with retention set to your regulatory and operational needs. The right number depends on your data and targets, so we scope it during onboarding. See our plans or call 270.816.5726 for a figure tied to your environment.

Does HIPAA or cyber insurance require offsite backup?

HIPAA does not use the word "offsite," but its Security Rule effectively requires it. The Contingency Plan standard at 45 CFR 164.308(a)(7) requires covered entities to establish a data backup plan — "procedures to create and maintain retrievable exact copies of electronic protected health information" — and a disaster recovery plan to "restore any loss of data." A backup that can't survive a fire or flood at the same site can't satisfy a disaster recovery plan, so a recoverable offsite copy is what meets the standard in practice. (Source: 45 CFR 164.308, Cornell Legal Information Institute.)

Cyber insurance is now more explicit. To bind or renew a policy, carriers increasingly require offsite, immutable, and regularly tested backups as a condition of coverage — alongside MFA and endpoint detection. Carriers have learned that recoverable offsite backups are what let a business decline a ransom, so they underwrite for it. If your backup isn't offsite and tested, you may be answering "no" on the application without realizing it.

Frequently asked questions

What's the difference between offsite backup and cloud backup?
Offsite backup means a copy of your data stored at a different physical location than the original — historically a tape or drive taken to another building. Cloud backup is a specific kind of offsite backup where the copy lives in a cloud provider's data center. All cloud backup is offsite; not all offsite backup is cloud. The modern answer is usually a hybrid: a local copy for fast restores plus a cloud copy for disaster survival.
What is the 3-2-1 backup rule?
3 copies of your data, on 2 different types of media, with 1 copy offsite. A modern update adds a fourth and fifth element — 3-2-1-1-0: one of the offsite copies is immutable or air-gapped, and there are zero errors on the last restore test. The immutability is what makes the backup survive ransomware.
Why does immutability matter more than location?
Ransomware now targets the backup before encrypting the primary data — it deletes shadow copies, kills the backup service, and encrypts any backup it can reach. A cloud backup that the ransomware can authenticate to and delete is not safe just because it's in the cloud. An immutable backup cannot be altered or deleted for a defined retention period, even with admin credentials — which is exactly what defeats the attack.
Is cloud backup enough on its own?
It can be, but a local copy plus cloud is usually better for a small business. The local copy gives fast restores (restoring a 2TB server over the internet takes a long time; restoring from a local appliance takes minutes to hours). The cloud copy gives disaster survival (fire, flood, theft of the local appliance). The combination — local appliance plus immutable cloud — is the standard for business-grade backup.
Does Microsoft 365 back itself up?
No — not in the way most owners assume. Microsoft operates under a shared-responsibility model: they keep the service running and protect against their own infrastructure failures, but recovering your data from accidental deletion, malicious deletion, or ransomware is your responsibility. The default retention is short. A separate SaaS backup of Microsoft 365 (and Google Workspace) is a baseline control, not an optional extra.
Why should backups be stored offsite?
Because a backup in the same building as the data shares the data's fate. A fire, flood, or theft that destroys the original can destroy a local-only copy in the same event. The bigger reason today is ransomware: modern attacks hunt for the backup and encrypt any copy the network can reach, so a local backup often gets encrypted too. An offsite copy — especially an immutable one the attacker can't touch — is the one that survives and lets you recover without paying.
How safe are offsite backups?
As safe as how they're configured, not the location alone. Safety comes from encryption in transit and at rest, access controls and MFA on the backup console and storage, immutability or object lock so the copy can't be deleted within its retention window, and tested restores that prove the data comes back. Configured that way, an offsite backup is safer than the environment it protects. A cloud copy an attacker can log into and delete is not safe just because it's offsite.
How much does offsite backup cost?
There's no single price — cost is driven by data volume, retention length, and how fast you need to restore. A few hundred gigabytes with short retention costs less than several terabytes kept for years, and a tight recovery-time target adds a local appliance for speed. At Micro-IT, restore-tested backup is part of the managed stack rather than a separate line item. See our plans or call 270.816.5726 for a figure tied to your environment.
Does HIPAA require offsite backup?
HIPAA doesn't use the word "offsite," but its Security Rule effectively requires it. The Contingency Plan standard at 45 CFR 164.308(a)(7) requires a data backup plan to create and maintain retrievable exact copies of electronic protected health information, plus a disaster recovery plan to restore any loss of data. A backup that can't survive a site disaster can't satisfy a disaster recovery plan, so a recoverable offsite copy is what meets the standard in practice. Cyber insurers now commonly require offsite, immutable, tested backups as a condition of coverage.

Related reading