0%

Preparing the page

Cloud Backup Strategy: Best Practices for AWS, Azure and Google Cloud

Build a cloud backup strategy that survives ransomware and mistakes: the 3-2-1 rule, immutable backups, cross-account copies, retention and restore testing.

Nidhish Joy

Nidhish Joy · Co-founder & CEO

· 4 min read

Share
Placeholder illustration

Cloud services are highly durable, which leads many teams to assume their data is safe. But durability protects against hardware failure, not against an engineer running the wrong script, a compromised account deleting resources, or ransomware encrypting everything it can reach.

This guide explains how to build a cloud backup strategy that works when you need it.

Cloud services are highly durable, which leads many teams to assume their data is safe.

Why do you need backups in the cloud?

Under the shared responsibility model, cloud providers secure and operate the infrastructure, while customers are responsible for their data, configuration and access. Common causes of cloud data loss include:

  • Accidental deletion or overwriting
  • Faulty automation or infrastructure-as-code changes
  • Ransomware and malicious insiders
  • Compromised credentials
  • Application bugs corrupting data
  • SaaS data loss, such as Microsoft 365 mailboxes or files

What is the 3-2-1 backup rule in the cloud?

The classic rule is three copies of data, on two different media, with one copy offsite. In the cloud, adapt it as:

  • 3 copies: production data plus at least two backups
  • 2 separations: different storage services or accounts
  • 1 isolated copy: in a separate account and/or region, ideally immutable

Many organisations extend this to 3-2-1-1-0: one immutable or air-gapped copy and zero errors in restore tests.

Cloud backup best practices

Cross-account immutable backup vault
  1. Centralise backup management with AWS Backup, Azure Backup or Google Cloud Backup and DR, using policies rather than manual jobs.
  2. Tag resources for backup so new resources are protected automatically.
  3. Copy backups to a separate account with restricted access and separate credentials.
  4. Copy to another region for regional resilience.
  5. Make backups immutable using features such as AWS Backup Vault Lock, Azure immutable vaults or object lock.
  6. Align frequency to RPO: critical databases may need continuous or point-in-time recovery; others daily.
  7. Define retention based on business, legal and compliance needs, with lifecycle rules to control cost.
  8. Encrypt backups with managed keys and restrict key access.
  9. Monitor backup jobs and alert on failures.
  10. Test restores regularly and record results.

How much backup retention do you need?

Data typeTypical frequencyTypical retention
Production databasesContinuous / hourly7–35 days point-in-time, plus monthly long-term
Application serversDaily7–30 days
File storageDaily30–90 days
Compliance recordsPer policyAs required by regulation
Non-productionWeekly or noneShort

These are starting points; set retention with business, legal and compliance teams.

How do backups fit with disaster recovery?

Backups are one building block of disaster recovery. DR also covers rebuilding infrastructure, networking, identity and applications within RTO targets. Backup-and-restore is the simplest DR strategy, suitable for less critical systems.

How do you control backup costs?

  • Use lifecycle rules to move older backups to cold storage tiers
  • Avoid backing up data that can be easily regenerated
  • Delete orphaned snapshots (a common AWS cost leak)
  • Review retention policies annually

How Crozaint approaches backup

Storage and backup and disaster recovery and business continuity are two of the eight disciplines in Crozaint's 24/7 managed services. We design policy-based backup across AWS, Azure and Google Cloud, set up cross-account and cross-region copies with immutability, monitor every job and run regular restore tests as part of ongoing operations.

Because backup costs are also cloud costs, our FinOps practice keeps retention and storage tiers efficient.

Common mistakes to avoid

  • Relying on replication as backup
  • Storing backups in the same account as production
  • No immutability, leaving backups exposed to ransomware
  • Never testing restores
  • Unlimited retention driving up storage costs

Conclusion

Backups are your last line of defence. Isolate them, make them immutable, align them with RPO and retention needs, and prove them with regular restores.

Confident your backups would restore today? Book a 30-minute call with Crozaint.

Frequently Asked Questions

Do I need to back up data in AWS or Azure?

Yes. Cloud providers ensure infrastructure durability, but under the shared responsibility model, protecting your data from deletion, corruption, ransomware and misconfiguration is your responsibility. Use native backup services or third-party tools with policies, isolation and regular restore tests.

What is an immutable backup?

An immutable backup cannot be modified or deleted for a defined retention period, even by administrators. Features such as AWS Backup Vault Lock, Azure immutable vaults and object lock provide immutability, protecting backups against ransomware, malicious insiders and accidental deletion.

What is the 3-2-1 backup rule?

The 3-2-1 rule recommends keeping three copies of data, on two different types of storage, with one copy offsite. In the cloud, this means production plus two backups, stored across separate services or accounts, with at least one isolated, ideally immutable, copy in another account or region.

How often should we test backup restores?

Test restores of critical systems at least quarterly and other systems at least annually. Automated restore testing can run more often. Record restore time and data integrity results, and compare them with RTO and RPO targets to confirm backups meet business needs.

Should Microsoft 365 data be backed up?

Many organisations back up Microsoft 365 mailboxes, OneDrive, SharePoint and Teams data, because native retention features are not designed as full backup and restore solutions for every scenario. Evaluate your recovery needs, retention requirements and ransomware risk to decide.

Nidhish Joy

Written by

Nidhish Joy

Co-founder & CEO · 10 articles

Nidhish co-founded Crozaint in 2018 and leads it as CEO — 250+ cloud engagements, a 35-strong team running 24/7 operations for 100+ critical applications, and AWS Advanced and Microsoft Gold partner status along the way. He works where technology, strategy and investment meet: AI-first businesses, FinOps and technology economics, and the partnerships that make them real. He is also the first call on any new engagement.

JosephReviewed for technical accuracy by Joseph, Cloud Consulting.

After the reading

Reading About Managed Services Is the Easy Part.Doing It in Your Estate Is Ours.

Thirty minutes with the people who wrote this. We look at your setup, say what we would fix first and leave you with a plan, whether or not you go further with us.

  • A look at your estate, not a demo
  • What we would fix first, and why
  • A plan you keep, whether or not you hire us
Nidhish Joy

Talk to Nidhish

Wrote this article · Co-founder & CEO

Thirty minutes on your estate. Nidhish looks at what you have and tells you what we would do first.

Book 30 Minutes

No deck, no pitch, no commitment.