Privacy notice This website only uses technically necessary cookies. Statistics, marketing and external services are not loaded without JavaScript. Learn more in our Privacy Policy.
Back to the blog
Nexthosting Guide

Storing Backups Offsite: Strategies Against Ransomware and Outages

Learn how to store your backups offsite and protect against ransomware and outages effectively. Protect your data now!

Aug 24, 2026 87 views
Storing Backups Offsite: Strategies Against Ransomware and Outages

Store backups offsite following the 3-2-1-1-0 principle: a local copy for fast restores, replication to an external target, and at least one immutable copy that no attacker with stolen credentials can delete. There are three things you should still do this week:

  • Separate backup access from the production system, with separate credentials for the offsite target
  • Automate daily verification of backup integrity, not just of the job itself
  • Store encryption keys separately from the backup system, otherwise the copy is useless

This structure protects at the same time against ransomware that moves laterally through the network, and against fire, theft or a complete outage of the hosting data center.

Key takeaways

A resilient offsite strategy combines a local copy, an external replica and an immutable backup, with automated, regularly tested verification.

Topic Details
3-2-1-1-0 as the foundation Three copies, two media types, one offsite, one immutable, aim for zero verification errors.
Access separation Separate credentials and API tokens for backup systems prevent deletion through compromised production accounts.
Use Object Lock with care With PBS 4.2, a two-bucket workaround prevents inconsistencies during garbage collection.
Plan restore drills Full restore tests every quarter, rather than just checking backups, provide reliable RTO/RPO figures.
Choose your hosting foundation Nexthosting offers VPS and dedicated servers in Germany as the basis for local copies in a hybrid backup architecture.

Table of contents

Definition: What is an offsite backup and which variants exist?

An offsite backup is kept physically or logically separate from the production system: at another location, in another data center or with another provider. This differs from a plain off-cluster or off-host backup, which sits on another machine but remains reachable in the same network segment and is therefore also at risk during an attack.

Common variants are cloud object storage such as S3-compatible services, a second Proxmox Backup Server at another location, a NAS operated by the operator themselves, or physical media such as tape and external hard drives. Offsite becomes necessary whenever a single location counts as a single point of failure, which is the case for every production game server, VPS or dedicated server.

Benefits and risks: What offsite protects, and where the pitfalls are

Offsite copies protect against three specific scenarios: fire or water damage in the data center, theft of hardware, and a complete outage of the hosting provider. Without a physically separate copy, a server is completely lost in any of these events, no matter how well the local backups are organized.

The real risk lies elsewhere, though: ransomware often moves laterally through the network and deliberately searches for backup systems before encryption begins. If the attacker has gained admin rights on the backup server, even offsite copies are worthless if they can be deleted with the same credentials.

Pro tip: Regularly check that your backup account can really only write, but not delete. A delete permission that nobody needs becomes the entry point in an emergency.

This is exactly where the BSI ransomware catalog of measures comes in: it explicitly recommends separate backup copies, offline or immutable variants and regular recovery drills as core measures against precisely this pattern.

Onsite vs. offsite: Which data belongs where?

Not every server needs the same backup depth. The decision depends on four criteria:

  • Criticality: A production FiveM or Minecraft server with a paying community cannot tolerate data loss, a test server can.
  • Compliance: Customer data or payment information often require demonstrable external backups.
  • RTO/RPO: How quickly does the server need to be running again, and how much data loss is acceptable?
  • Data volume: Large worlds or databases need different transport routes than small configuration files.

In practice, a hybrid solution works well: game server sessions and current save games are kept locally for fast restores, while long-term archives and daily full backups go offsite with a longer retention period. Short-term local, long-term offsite: that is the rule of thumb that prevails in most hosting environments.

Best practices: How do you implement a secure offsite strategy?

The modern extension of the classic 3-2-1 rule is called 3-2-1-1-0: three copies, two media types, one of them offsite, one immutable, zero errors in verification. Here is how to put it into practice:

  1. Local copy for fast restores. Keep a current backup on the same or a neighboring system so you can fix small errors without download time.
  2. Replication to an external target. Automated jobs copy the data to a second location, ideally with a different provider.
  3. Plan for an immutable copy. Object Lock in S3-compatible storage, physical tape or an offline-stored bundle of hard drives prevent an attacker from overwriting the copy.
  4. Separate encryption and key management. The encryption key must never be stored in the same system as the backup itself, otherwise the encryption is ineffective.
  5. Build an access structure. Separate credentials and API tokens for backup systems, with no reuse of admin access from the production system.
  6. Automation with oversight. Schedules, verification jobs, prune rules for old versions and alerting on failures belong in the same workflow.

Each of these steps builds on the others. An immutable copy without separate credentials achieves little, and automation without alerting only notices an outage when it is too late.

Technical options: S3, Proxmox PBS, NAS and tape compared

For S3-compatible cloud storage, four points matter: the region, the provider's endpoint format, enabled versioning and the limits of Object Lock. Field reports show that Hetzner Object Storage is a common choice for cost-efficient offsite object storage in German-speaking setups because of its locations in Nuremberg, Falkenstein and Helsinki.

Proxmox Backup Server (PBS) 4.2 comes with native S3 datastores, but requires a local cache of several gigabytes for this. More importantly: anyone who enables Object Lock directly on the PBS bucket risks inconsistencies during garbage collection. The recommended approach is a two-bucket workaround, in which a second, immutable bucket is kept in sync via rclone or the AWS CLI.

For sync jobs between two PBS instances, a pull model is recommended: the offsite server fetches the data itself via an API token, instead of the production system being allowed to write actively. This way, group filters and asymmetric retention can be configured, with longer retention at the offsite target than locally.

With a pull model, a compromised source system cannot delete the offsite copy, because it has no write permissions on the target system. This is the decisive difference from classic push backups.

NAS systems and external hard drives remain practical for smaller setups, especially with a rotation rule: several drives used in turn, with one always stored offline. This offline copy is the simplest ransomware protection there is, because a medium that is not connected cannot technically be attacked. For very large initial transfers, such as the initial seeding of several terabytes, physical transport by tape or hard drive is often still faster than any internet connection.

Testing & recovery: How often should you run restore drills?

A backup without a test is a claim, not proof. Verification jobs with SHA-256 checksums should ideally run after every backup run, and at least weekly for critical systems.

  1. Set up verification jobs. Automated checksum comparisons detect corrupt chunks before you depend on them in an emergency.
  2. Run restore drills quarterly. Simulate a complete server failure and actually rebuild a game server or VPS, not just individual files.
  3. Document runbooks. Key access, failover steps and contacts belong in writing, not just in one person's head.
  4. Record metrics. You need to back up RTO (recovery time) and RPO (maximum acceptable data loss) with real figures from the drills, not estimate them.

The BSI catalog of measures explicitly names regular recovery drills as one of the most effective measures against ransomware, precisely because many failures only become visible during an actual restore attempt.

Publisher and compliance signals: Why these recommendations are reliable

The measures described here are based on publicly available, verifiable sources: the BSI ransomware catalog of measures as an official government reference, and ISO 27001 as an internationally recognized standard for information security management systems. The technical details on PBS 4.2 and Hetzner Object Storage come from documented real-world implementations, not from theoretical assumptions.

For companies that run their own backup infrastructure, Nexthosting offers VPS and dedicated server solutions located in Germany that fit into such an architecture as a building block, without presenting any particular product here as a cure-all.

Author's perspective: Practical focus for game server and hosting environments

Most operators overinvest in performance and underinvest in restore capability. A fast server is useless if the offsite copy fails at the first real test. My recommendation: a VPS or dedicated server for operation, an external PBS or S3 target for backups, and tests that you don't put off. Anyone who drops restore drills because they are tedious only finds out when it is too late.

— Erik

Quick introduction: Nexthosting as a building block for your offsite strategy

If you run game servers, VPS or dedicated servers in Germany, you benefit from short latencies to the data center and personal support when something goes wrong during a restore test, instead of waiting days for a ticket at a mass hoster. Nexthosting offers VPS and dedicated server solutions with automatic backups as a starting point for a hybrid architecture: local snapshots on the VPS Standard for fast restores, combined with an external target for the immutable offsite copy. For beginners who want to test a smaller setup first, the VPS Einfach is a low-cost starting point. If you have specific questions about implementing a backup strategy for your own FiveM server or Minecraft server, you can contact support directly and discuss your architecture.

Sources

FAQ

Where can you store backups?

Backups can be stored locally, on a NAS, with a cloud provider that offers S3-compatible object storage, or on physical media such as external hard drives and tape. For real resilience, at least one target should be physically separate from the production system, for example a VPS at Nexthosting as the local target combined with external object storage.

How can I store my backup on an external hard drive?

Copy the backup to an external hard drive regularly and physically disconnect the drive from the system afterward, so it stays offline and therefore protected from ransomware. Rotating several drives adds further security.

What are the three types of backups?

The three classic types are full, differential and incremental backups, which differ in scope and speed. Offsite strategies usually combine them: a full backup as the base, supplemented by incremental runs.

How can I back up my NAS to an external hard drive?

Most NAS systems offer built-in backup functions that can copy data to a connected external hard drive on a schedule. For additional protection, this copy should be disconnected and stored offline after the backup run.

What does the 3-2-1-1-0 rule mean in practice?

The rule calls for three copies of the data on two different media types, one of them offsite and one immutable, with zero errors in regular verification. It extends the classic 3-2-1 rule with immutability and verification.