Cyber resilience in the age of NIS2: Why backup is no longer just an IT function 

A question every business should be asking is: How quickly can we get back to business if something goes wrong? 

Downtime is expensive, and in extreme cases, can even affect the wider economy — with the Jaguar Land Rover cyberattack estimated to have wiped out 0.1% of the UK’s GDP.  

That’s why legislation such as the EU NIS2 Directive places a strong emphasis on recovery capability, not just prevention, for companies deemed “critical” or “important.” Even organizations that are not directly subject to NIS2 may still need to demonstrate appropriate safeguards if they want to do business with customers, partners or suppliers that are. 

But every company should be asking this question, whether they are affected by the legislation or not. Backup is no longer simply about having another copy of your data. It’s a key part of any disaster response and how quickly you can move from recovery to normal business operations. 

That’s why backup and recovery discussions are moving beyond IT departments and becoming board-level priorities. 

How a good backup strategy supports NIS2 

 For many years, the widely accepted backup framework was: 

  • 3 copies of data (to protect against data loss) 
  • 2 different formats (stored on at least two media types) 
  • 1 off-site copy (to protect against physical disasters) 

However, it’s now recommended to add two more measures for true backup efficacy: 

  • 1 immutable copy (ensuring ransomware-proof backups) 
  • 0 doubt you can recover (regular testing guarantees reliability) 

This evolving approach has a key part to play in NIS2 compliance. 

What does NIS2 say about backup strategy? 

At NIS2’s core is a focus on recovery and business continuity. It’s about ensuring disruption is kept to a minimum in the event of an incident. As such, most sections of NIS2 legislation are supported by a good backup strategy. 

Three areas are particularly relevant. 

One of the pillars of NIS2 is “policies to assess effectiveness.” Put simply, this isn’t just about the belief you have effective backup in place — it’s the ability to prove you do.  

A backup is useless if you can’t use it. The “0 doubt you can recover” principle should form part of any recovery strategy,  supported by documented recovery procedures and regular testing. Organizations need confidence that when recovery is required, it will work as expected. 

Meanwhile, the immutable copy addresses the legislation’s need for “business continuity measures” and basic “computer hygiene.” It’s vital to have a copy of data that cannot be altered or deleted and can act as a known and reliable restore point if needed. This is necessary for general disaster recovery and offers a reliable version of data in the event of a cyberattack or ransomware incident. 

Avoid cloud complacency 

 One of the biggest misconceptions in modern IT is the assumption that cloud services automatically provide complete protection, and that providers will handle backup and recovery. The problem is exacerbated by SaaS, where the promise of instant access to a solution is enticing and often achieved without IT involvement. 

Even well-established services like Microsoft 365 can have backup blind spots if organizations do not have an independent protection strategy in place 

The term “cloud blindness” has been coined for this and other areas of cloud complacency. 

While cloud services may bake in a certain amount of resiliency, businesses cannot take a hands-off approach to critical areas such as backup and recovery. 

Businesses need to employ a zero-trust policy when it comes to their data integrity. Regardless of who has stored the data or where, and regardless of the promises given in terms of reliability, the backup strategy must remain consistent across the board.  

Backups are about getting back to business 

In a world where ransomware attacks are increasingly common and SaaS outages are frequently making headlines, backups need to be a key part of any compliance posture. 

Every moment of downtime is potentially lost revenue. The legislation’s approach to making IT part of boardroom governance is good for IT teams, and Datto has long been making the case for backups to be an important part of this discussion. 

Read Datto’s The ultimate guide to BCDR: Why backup and disaster recovery matter 

One Complete Platform for IT & Security Management

Kaseya 365 is the all-in-one solution for managing, securing, and automating IT. With seamless integrations across critical IT functions, it simplifies operations, strengthens security, and boosts efficiency.

One platform. Everything IT.

Kaseya 365 customers experience the benefits of the best IT Management and Security tools in a single solution.

Explore Kaseya 365

Your success is our #1 priority

Partner First is a commitment to flexible terms, shared risk and dedicated support for your business.

Explore Partner First Pledge

2026 Kaseya State of the MSP Report

Kaseya - 2026 State of the MSP Report - Web Graphic - 1200x800-UPDATED

Get 2026 MSP insights from 1,000 plus providers and learn how to grow revenue, adapt to market pressure, and stay competitive.

Download Now

Cloud complacency is putting European Microsoft 365 and Azure date at risk

Microsoft 365 and Azure data is your responsibility. Learn why backup and recovery are essential to protect cloud data from loss, ransomware, and disruption.

Read blog post

Should we start with resilience and work backward from there?

Sponsored by: Kaseya This is a guest blog post by International Data Corporation (IDC), the global market intelligence leader, sharing

Read blog post

Elevating data protection to cyber resilience

Sponsored by: Kaseya This is a guest blog post by International Data Corporation (IDC), the global market intelligence leader, sharing

Read blog post