Cloud services are highly durable, which leads many teams to assume their data is safe. But durability protects against hardware failure, not against an engineer running the wrong script, a compromised account deleting resources, or ransomware encrypting everything it can reach.
This guide explains how to build a cloud backup strategy that works when you need it.
Cloud services are highly durable, which leads many teams to assume their data is safe.
Why do you need backups in the cloud?
Under the shared responsibility model, cloud providers secure and operate the infrastructure, while customers are responsible for their data, configuration and access. Common causes of cloud data loss include:
- Accidental deletion or overwriting
- Faulty automation or infrastructure-as-code changes
- Ransomware and malicious insiders
- Compromised credentials
- Application bugs corrupting data
- SaaS data loss, such as Microsoft 365 mailboxes or files
What is the 3-2-1 backup rule in the cloud?
The classic rule is three copies of data, on two different media, with one copy offsite. In the cloud, adapt it as:
- 3 copies: production data plus at least two backups
- 2 separations: different storage services or accounts
- 1 isolated copy: in a separate account and/or region, ideally immutable
Many organisations extend this to 3-2-1-1-0: one immutable or air-gapped copy and zero errors in restore tests.
Cloud backup best practices
Immutable cross-account cloud backups
Illustration in progress
- Centralise backup management with AWS Backup, Azure Backup or Google Cloud Backup and DR, using policies rather than manual jobs.
- Tag resources for backup so new resources are protected automatically.
- Copy backups to a separate account with restricted access and separate credentials.
- Copy to another region for regional resilience.
- Make backups immutable using features such as AWS Backup Vault Lock, Azure immutable vaults or object lock.
- Align frequency to RPO: critical databases may need continuous or point-in-time recovery; others daily.
- Define retention based on business, legal and compliance needs, with lifecycle rules to control cost.
- Encrypt backups with managed keys and restrict key access.
- Monitor backup jobs and alert on failures.
- Test restores regularly and record results.
How much backup retention do you need?
| Data type | Typical frequency | Typical retention |
|---|---|---|
| Production databases | Continuous / hourly | 7–35 days point-in-time, plus monthly long-term |
| Application servers | Daily | 7–30 days |
| File storage | Daily | 30–90 days |
| Compliance records | Per policy | As required by regulation |
| Non-production | Weekly or none | Short |
These are starting points; set retention with business, legal and compliance teams.
How do backups fit with disaster recovery?
Backups are one building block of disaster recovery. DR also covers rebuilding infrastructure, networking, identity and applications within RTO targets. Backup-and-restore is the simplest DR strategy, suitable for less critical systems.
How do you control backup costs?
- Use lifecycle rules to move older backups to cold storage tiers
- Avoid backing up data that can be easily regenerated
- Delete orphaned snapshots (a common AWS cost leak)
- Review retention policies annually
How Crozaint approaches backup
Storage and backup and disaster recovery and business continuity are two of the eight disciplines in Crozaint's 24/7 managed services. We design policy-based backup across AWS, Azure and Google Cloud, set up cross-account and cross-region copies with immutability, monitor every job and run regular restore tests as part of ongoing operations.
Because backup costs are also cloud costs, our FinOps practice keeps retention and storage tiers efficient.
Common mistakes to avoid
- Relying on replication as backup
- Storing backups in the same account as production
- No immutability, leaving backups exposed to ransomware
- Never testing restores
- Unlimited retention driving up storage costs
Conclusion
Backups are your last line of defence. Isolate them, make them immutable, align them with RPO and retention needs, and prove them with regular restores.
Confident your backups would restore today? Book a 30-minute call with Crozaint.
