Storing Backups Offsite: Strategies Against Ransomware and Outages
Learn how to store your backups offsite and protect against ransomware and outages effectively. Protect your data now!
Learn how to store your backups offsite and protect against ransomware and outages effectively. Protect your data now!
Store backups offsite following the 3-2-1-1-0 principle: a local copy for fast restores, replication to an external target, and at least one immutable copy that no attacker with stolen credentials can delete. There are three things you should still do this week:
This structure protects at the same time against ransomware that moves laterally through the network, and against fire, theft or a complete outage of the hosting data center.
A resilient offsite strategy combines a local copy, an external replica and an immutable backup, with automated, regularly tested verification.
| Topic | Details |
|---|---|
| 3-2-1-1-0 as the foundation | Three copies, two media types, one offsite, one immutable, aim for zero verification errors. |
| Access separation | Separate credentials and API tokens for backup systems prevent deletion through compromised production accounts. |
| Use Object Lock with care | With PBS 4.2, a two-bucket workaround prevents inconsistencies during garbage collection. |
| Plan restore drills | Full restore tests every quarter, rather than just checking backups, provide reliable RTO/RPO figures. |
| Choose your hosting foundation | Nexthosting offers VPS and dedicated servers in Germany as the basis for local copies in a hybrid backup architecture. |
An offsite backup is kept physically or logically separate from the production system: at another location, in another data center or with another provider. This differs from a plain off-cluster or off-host backup, which sits on another machine but remains reachable in the same network segment and is therefore also at risk during an attack.
Common variants are cloud object storage such as S3-compatible services, a second Proxmox Backup Server at another location, a NAS operated by the operator themselves, or physical media such as tape and external hard drives. Offsite becomes necessary whenever a single location counts as a single point of failure, which is the case for every production game server, VPS or dedicated server.
Offsite copies protect against three specific scenarios: fire or water damage in the data center, theft of hardware, and a complete outage of the hosting provider. Without a physically separate copy, a server is completely lost in any of these events, no matter how well the local backups are organized.
The real risk lies elsewhere, though: ransomware often moves laterally through the network and deliberately searches for backup systems before encryption begins. If the attacker has gained admin rights on the backup server, even offsite copies are worthless if they can be deleted with the same credentials.
Pro tip: Regularly check that your backup account can really only write, but not delete. A delete permission that nobody needs becomes the entry point in an emergency.
This is exactly where the BSI ransomware catalog of measures comes in: it explicitly recommends separate backup copies, offline or immutable variants and regular recovery drills as core measures against precisely this pattern.
Not every server needs the same backup depth. The decision depends on four criteria:
In practice, a hybrid solution works well: game server sessions and current save games are kept locally for fast restores, while long-term archives and daily full backups go offsite with a longer retention period. Short-term local, long-term offsite: that is the rule of thumb that prevails in most hosting environments.
The modern extension of the classic 3-2-1 rule is called 3-2-1-1-0: three copies, two media types, one of them offsite, one immutable, zero errors in verification. Here is how to put it into practice:
Each of these steps builds on the others. An immutable copy without separate credentials achieves little, and automation without alerting only notices an outage when it is too late.
For S3-compatible cloud storage, four points matter: the region, the provider's endpoint format, enabled versioning and the limits of Object Lock. Field reports show that Hetzner Object Storage is a common choice for cost-efficient offsite object storage in German-speaking setups because of its locations in Nuremberg, Falkenstein and Helsinki.
Proxmox Backup Server (PBS) 4.2 comes with native S3 datastores, but requires a local cache of several gigabytes for this. More importantly: anyone who enables Object Lock directly on the PBS bucket risks inconsistencies during garbage collection. The recommended approach is a two-bucket workaround, in which a second, immutable bucket is kept in sync via rclone or the AWS CLI.
For sync jobs between two PBS instances, a pull model is recommended: the offsite server fetches the data itself via an API token, instead of the production system being allowed to write actively. This way, group filters and asymmetric retention can be configured, with longer retention at the offsite target than locally.
With a pull model, a compromised source system cannot delete the offsite copy, because it has no write permissions on the target system. This is the decisive difference from classic push backups.
NAS systems and external hard drives remain practical for smaller setups, especially with a rotation rule: several drives used in turn, with one always stored offline. This offline copy is the simplest ransomware protection there is, because a medium that is not connected cannot technically be attacked. For very large initial transfers, such as the initial seeding of several terabytes, physical transport by tape or hard drive is often still faster than any internet connection.
A backup without a test is a claim, not proof. Verification jobs with SHA-256 checksums should ideally run after every backup run, and at least weekly for critical systems.
The BSI catalog of measures explicitly names regular recovery drills as one of the most effective measures against ransomware, precisely because many failures only become visible during an actual restore attempt.
The measures described here are based on publicly available, verifiable sources: the BSI ransomware catalog of measures as an official government reference, and ISO 27001 as an internationally recognized standard for information security management systems. The technical details on PBS 4.2 and Hetzner Object Storage come from documented real-world implementations, not from theoretical assumptions.
For companies that run their own backup infrastructure, Nexthosting offers VPS and dedicated server solutions located in Germany that fit into such an architecture as a building block, without presenting any particular product here as a cure-all.
Most operators overinvest in performance and underinvest in restore capability. A fast server is useless if the offsite copy fails at the first real test. My recommendation: a VPS or dedicated server for operation, an external PBS or S3 target for backups, and tests that you don't put off. Anyone who drops restore drills because they are tedious only finds out when it is too late.
— Erik
If you run game servers, VPS or dedicated servers in Germany, you benefit from short latencies to the data center and personal support when something goes wrong during a restore test, instead of waiting days for a ticket at a mass hoster. Nexthosting offers VPS and dedicated server solutions with automatic backups as a starting point for a hybrid architecture: local snapshots on the VPS Standard for fast restores, combined with an external target for the immutable offsite copy. For beginners who want to test a smaller setup first, the VPS Einfach is a low-cost starting point. If you have specific questions about implementing a backup strategy for your own FiveM server or Minecraft server, you can contact support directly and discuss your architecture.
Backups can be stored locally, on a NAS, with a cloud provider that offers S3-compatible object storage, or on physical media such as external hard drives and tape. For real resilience, at least one target should be physically separate from the production system, for example a VPS at Nexthosting as the local target combined with external object storage.
Copy the backup to an external hard drive regularly and physically disconnect the drive from the system afterward, so it stays offline and therefore protected from ransomware. Rotating several drives adds further security.
The three classic types are full, differential and incremental backups, which differ in scope and speed. Offsite strategies usually combine them: a full backup as the base, supplemented by incremental runs.
Most NAS systems offer built-in backup functions that can copy data to a connected external hard drive on a schedule. For additional protection, this copy should be disconnected and stored offline after the backup run.
The rule calls for three copies of the data on two different media types, one of them offsite and one immutable, with zero errors in regular verification. It extends the classic 3-2-1 rule with immutability and verification.