A lost laptop is inconvenient. A stolen backup containing years of client files, finance records or charity beneficiary information can be far more serious. So, are cloud backups encrypted? Usually, yes – but that short answer can create a false sense of security. Encryption varies between providers, products and settings, and it is only one part of keeping recoverable copies of your data safe.
For organisations in Bradford, Leeds and Halifax, the useful question is not simply whether a backup supplier uses encryption. It is: what is encrypted, when, who can access it, and could we restore our files after a cyber attack?
Are cloud backups encrypted by default?
Most reputable cloud backup services encrypt data while it travels from your computers or servers to their data centre, and while it is stored there. These are commonly called encryption in transit and encryption at rest.
Encryption in transit protects information as it moves across the internet. Without it, someone intercepting the connection could potentially read or alter the data. Encryption at rest protects the stored backup files on the provider’s systems, so that a hard drive or storage system cannot simply be read by anyone who gets hold of it.
That is good news, but it does not mean every backup is protected in the same way. Some services encrypt only certain data types or plans. Others enable stronger options only when an administrator turns them on. A backup may also be encrypted on the provider’s storage but remain visible to anyone who has gained access to an administrator account.
The sensible approach is to ask for clear, plain-English confirmation of the protections included with the service you are buying. If the answer is buried in vague wording or technical sales material, keep asking.
Encryption is not one single feature
When a provider says it uses encryption, there are several layers worth understanding. You do not need to become an encryption specialist, but your IT partner should be able to explain these without baffling you.
Data travelling to the backup service
A secure connection, typically using TLS, protects data while it is uploaded and downloaded. This matters especially for remote staff, home workers and teams using public Wi-Fi. It should also apply when you need to restore files, not only when the backup runs.
Data stored in the cloud
Stored backup data should be encrypted using recognised, current standards such as AES-256. This makes the raw stored information unintelligible without the correct encryption key. It helps reduce the impact of physical theft, unauthorised access to storage hardware and certain provider-side failures.
The encryption keys
The key is as important as the lock. In many managed cloud backup services, the provider controls the encryption keys. This can be practical: the service can automate recovery and support requests without putting complicated key management on your office team.
The trade-off is that the provider may be technically able to decrypt the data under tightly controlled circumstances. Some services offer customer-managed keys or private encryption keys, where only your organisation holds the key. This can provide stronger control, but it also creates a serious responsibility. If the only copy of the key is lost, your backup may be permanently unrecoverable.
For many small businesses and charities, provider-managed encryption combined with strong account security and a trusted support arrangement is the more workable choice. For organisations handling particularly sensitive information or operating under stricter contractual requirements, customer-managed keys may be worth considering.
What encryption does not protect you from
Encryption is valuable, but it is not a cure for every backup risk. If a criminal signs in using a compromised Microsoft 365 or backup administrator account, encryption does not stop them accessing data through that legitimate route. The same applies if too many people have powerful permissions, or if a former employee’s account has not been removed.
Ransomware is another example. If infected or encrypted files are copied into your backups for long enough, you may need an older clean version to recover from. A good backup setup keeps multiple versions for a defined period, rather than continually overwriting yesterday’s usable copy with today’s damaged one.
You should also consider accidental deletion, retention rules and restore testing. A backup that is encrypted but only retained for seven days may not help when someone spots a missing folder a month later. A backup that has never been tested may look fine in a dashboard but fail when it is needed most.
The controls that make encrypted backups genuinely safer
Encryption works best alongside a few sensible safeguards. These are the questions worth putting to your provider or IT support team:
- Is multi-factor authentication required for all backup administrator accounts?
- Can access be limited so that staff only see the systems and data they need?
- Are backup copies protected from deletion or alteration for a set period, sometimes called immutable storage?
- How many versions are kept, and for how long?
- Are backups monitored daily, with a human response when one fails?
- When was the last full restore test, and how long did it take?
These points matter because recovery is the real purpose of a backup. A small community group may only need to restore a handful of Microsoft 365 files. A growing business may need to recover a full server, line-of-business software and shared drives quickly enough to keep trading. The right plan depends on the disruption your organisation can tolerate.
Cloud backup versus cloud storage
This distinction catches many organisations out. Files held in OneDrive, SharePoint, Google Drive or Dropbox are stored in the cloud and are normally encrypted by the supplier. That does not automatically mean you have an independent backup.
Cloud storage is designed primarily for access, collaboration and synchronisation. If a file is deleted, corrupted or encrypted by ransomware, that change can synchronise across users and devices. Version history and recycle bins are helpful, but they have limits and retention periods.
A dedicated backup provides a separate recovery point, usually with its own retention policy and management controls. For Microsoft 365 in particular, a separate backup can protect mailboxes, Teams content, SharePoint sites and OneDrive files beyond the everyday collaboration features. Whether you need this depends on the data you hold, your retention obligations and how damaging a loss would be.
Questions to ask before choosing a cloud backup service
Do not settle for a tick-box assurance that data is “secure”. Ask whether data is encrypted both in transit and at rest, and whether that applies to every part of the service you will use. Ask who controls the keys, where the data is stored, how access is logged and how quickly suspicious activity is investigated.
Then move beyond encryption. Find out how often backups run, what is included, how long copies are retained and whether immutable backups are available. Ask for a realistic restore plan: if your main server failed at 10am on a Tuesday, what would be restored first, who would do it, and when could your team work again?
It is also worth checking the less glamorous details. Can a departing staff member’s data be retained where appropriate? Are failed backups reported to someone who will act? Is there a clear process for restoring a single email as well as an entire system? Practical answers are more reassuring than impressive terminology.
A proportionate approach for small organisations
Not every organisation needs the most complex or expensive backup platform. A two-person consultancy and a charity supporting vulnerable people may have very different risks, budgets and recovery needs. The aim is not to buy security for security’s sake. It is to make sure an incident does not stop you serving customers, supporting beneficiaries or paying staff.
Start by identifying the data you could not reasonably recreate: financial records, client documents, case notes, email, databases and key shared folders. Decide how much data loss is acceptable and how quickly each system needs to return. From there, a suitable backup service can be designed with encryption, retention, access controls and tested recovery in mind.
A good IT partner will explain the choices clearly, flag the compromises and keep checking that the backup is actually working. Bees Knees IT can help West Yorkshire organisations take the sting out of those decisions, without turning a straightforward safety measure into a technical headache.
The best time to ask whether your backups are encrypted is before you need them. The next best step is to make sure they can be restored.
Leave A Comment