Cloud backup
Quick answer
Cloud backup is the practice of keeping a copy of selected files on a remote service so that the original can be restored after loss, damage or encryption. It is the only control in this library that still works after every preventive measure has failed.
Backup answers a question none of the detection entries can answer: what happens once the data is gone. Hardware fails, devices are stolen, files are deleted in error, and ransomware encrypts. In each case the recovery path is identical — a second copy that was not affected by whatever destroyed the first.
The word "cloud" adds one specific property to that idea: the copy is held somewhere physically separate from the device, which addresses fire, flood and theft in a way a drive in the same room does not. It also introduces considerations that a drive in a drawer does not have, concerning who holds the data, where it is held, and who can read it.
Synchronisation is not backup
This is the most consequential distinction on the page. A synchronisation service mirrors a folder between a device and a server so that both match. That is a convenience, and in some failure modes it is the opposite of a backup: a file deleted on the device is deleted on the server, and a file encrypted on the device is uploaded in its encrypted form, overwriting the good copy.
What turns a mirror into a backup is versioning — the service retains previous versions of a file for a defined period, so an earlier state can be recovered. Most major synchronisation services do keep version history and a recovery bin, but the retention window and whether it covers mass changes vary. The question to put to any service is specific: how far back can a file be restored, and can an entire folder be rolled back to a point in time.
The only test that counts
A backup that has never been restored from is an assumption. Restoring one real file to a new location, and opening it, converts the assumption into a fact. This is worth doing when the backup is first set up and once or twice a year afterwards.
What a workable arrangement looks like
- Three copies
- The working file, plus two others. The familiar formulation is three copies, on two different kinds of storage, with one kept off site.
- One copy out of reach
- Offline, in a separate account, or immutable for a fixed period. The purpose is that a compromise of the device cannot propagate to it.
- Automatic operation
- A backup that depends on remembering to run it will, over any long period, not have run recently.
- Defined scope
- Knowing what is covered. Documents and photographs are usually included by default; application data, mail archives, databases and files stored outside the user folder frequently are not.
- Verified restoration
- Evidence from an actual restore rather than from a status indicator.
Deciding what to protect
Backing up everything is usually unnecessary and sometimes counterproductive, because the volume slows both the copying and the restoring. A more workable approach is to sort files into three groups. The first is material that cannot be recreated at any price: photographs, correspondence, original documents, records required for tax or legal purposes. The second is material that could be recreated with effort: configurations, collected reference material, project files for which drafts exist elsewhere. The third is material that can simply be downloaded again, such as installed applications and purchased media.
Only the first group genuinely requires the full arrangement described above. The second benefits from it. The third rarely justifies the space. Making this division once, and writing it down, also makes the periodic restore test quick, because it is clear which file to test with.
Cloud storage compared with local backup
| Consideration | Cloud backup | Local drive |
|---|---|---|
| Fire, flood, theft | Unaffected, held elsewhere | Lost with the device if stored together |
| Restoring a large volume | Limited by the connection | Fast |
| Ransomware reach | Depends on versioning and account separation | Safe only while disconnected |
| Ongoing cost | Recurring subscription in AUD | One purchase, replaced every few years |
| Who else holds the data | The provider, under its own terms | Nobody |
| Effort to maintain | Low once configured | Requires a routine |
Privacy and location of the data
Files placed with a cloud service are held by a company that is subject to the law of the places it operates in, and are frequently stored outside Australia. For most household data this is unremarkable. For records containing other people's personal information — a small practice's client files, for example — it engages obligations under the Privacy Act 1988 (Cth), including the Australian Privacy Principle governing disclosure of personal information overseas. The Office of the Australian Information Commissioner explains the principles at oaic.gov.au.
Where confidentiality matters more than convenience, end-to-end encrypted backup — in which the provider stores only ciphertext and does not hold the key — removes the provider from the list of parties who can read the contents. The trade-off is strict: losing the key or passphrase means losing the data, with no recovery path, because there is no one who can reset it.
Storage included with security software
Several antivirus subscriptions include an amount of cloud storage alongside the scanner. Two questions determine whether such an allocation is useful: how much is included relative to what actually needs protecting, and whether it offers versioning rather than a mirror. A modest allocation may be ample for documents and inadequate for a photograph library, and the two should be costed separately rather than treated as one decision.
Where a specific product's storage terms are concerned, this library does not restate them. The entry on Norton AntiVirus Plus records only what the vendor states and marks everything else as not stated.
Key terms on this page
- Versioning
- Retention of earlier copies of a file so that a previous state can be restored.
- Immutable
- Storage that cannot be altered or deleted for a defined period.
- End-to-end encrypted
- Encrypted before upload with a key the provider does not hold.
- Retention window
- How far back in time a restore can reach.