Information checked: 21 July 2026.
Cloud and local backups describe storage locations, not automatically their resilience. A cloud copy controlled by the same compromised administrator account may be less independent than an encrypted local copy held under separate control.
In brief: Choose copies with genuinely separate failure and security boundaries rather than relying on the storage label.
Compare the failure boundaries
| Factor | Cloud storage | Local or offline storage |
|---|---|---|
| Automation | Usually easy to schedule and monitor | May require disciplined connection and rotation |
| Geographic separation | Often built in | Depends on where media is stored |
| Account compromise | Risk if identity and deletion controls are shared | Risk if keys or devices are accessible |
| Ransomware isolation | Requires immutability or separate controls | Offline media can remain unaffected |
| Restoration speed | Depends on bandwidth and provider | Can be fast when media and hardware are available |
A resilient mixed approach
- Use an operational automated backup for quick recovery.
- Keep versioned copies protected from routine administrator deletion.
- Maintain at least one copy outside the live hosting security boundary.
- Store encryption keys and recovery instructions separately.
- Test both access and restoration before relying on the design.
Do not ignore supplier exit
Document export formats, retrieval time, cost and what happens when the subscription or account is closed. A backup that cannot be retrieved after a supplier dispute is not independent.
Acceptance check
Test the scenario in which the hosting and primary cloud account are both unavailable. Confirm who can retrieve the remaining copy and what equipment or credentials are required.
Account separation matters
A local drive permanently connected to an infected workstation is not an offline backup. A cloud bucket protected by a separate identity, immutable retention and restricted deletion may provide stronger isolation. Evaluate control boundaries, not physical labels.
Records to keep
- Identity and deletion-control map.
- Encryption-key ownership.
- Supplier retrieval and exit terms.
- Offline or immutable-copy test.
Owner test: Assume the primary administrator account is compromised and demonstrate which backup copy remains protected and accessible to an authorised responder.
Sources and date checked
This practical guidance was checked against the following primary sources. Date checked: 21 July 2026.
Keep the decision under your control
Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.