Cyber resilience in the age of NIS2: Why backup is no longer just an IT function 

A question every business should be asking is: How quickly can we get back to business if something goes wrong? 

Downtime is expensive, and in extreme cases, can even affect the wider economy — with the Jaguar Land Rover cyberattack estimated to have wiped out 0.1% of the UK’s GDP.  

That’s why legislation such as the EU NIS2 Directive places a strong emphasis on recovery capability, not just prevention, for companies deemed “critical” or “important.” Even organizations that are not directly subject to NIS2 may still need to demonstrate appropriate safeguards if they want to do business with customers, partners or suppliers that are. 

But every company should be asking this question, whether they are affected by the legislation or not. Backup is no longer simply about having another copy of your data. It’s a key part of any disaster response and how quickly you can move from recovery to normal business operations. 

That’s why backup and recovery discussions are moving beyond IT departments and becoming board-level priorities. 

How a good backup strategy supports NIS2 

 For many years, the widely accepted backup framework was: 

  • 3 copies des données (pour se prémunir contre toute perte de données) 
  • 2 formats différents (enregistrés sur au moins deux types de supports) 
  • 1 copie hors site (pour se prémunir contre les catastrophes physiques) 

Cependant, il est désormais recommandé d'ajouter deux mesures supplémentaires pour garantir une véritable efficacité de la sauvegarde : 

  • 1 copie immuable (garantissant des sauvegardes à l'épreuve des ransomwares) 
  • Je ne doute pas que vous puissiez récupérer les données (des tests réguliers garantissent la fiabilité) 

This evolving approach has a key part to play in NIS2 compliance. 

What does NIS2 say about backup strategy? 

At NIS2’s core is a focus on recovery and business continuity. It’s about ensuring disruption is kept to a minimum in the event of an incident. As such, most sections of NIS2 legislation are supported by a good backup strategy. 

Three areas are particularly relevant. 

One of the pillars of NIS2 is “policies to assess effectiveness.” Put simply, this isn’t just about the belief you have effective backup in place — it’s the ability to prove you do.  

A backup is useless if you can’t use it. The “0 doubt you can recover” principle should form part of any recovery strategy,  supported by documented recovery procedures and regular testing. Organizations need confidence that when recovery is required, it will work as expected. 

Meanwhile, the immutable copy addresses the legislation’s need for “business continuity measures” and basic “computer hygiene.” It’s vital to have a copy of data that cannot be altered or deleted and can act as a known and reliable restore point if needed. This is necessary for general disaster recovery and offers a reliable version of data in the event of a cyberattack or ransomware incident. 

Avoid cloud complacency 

 One of the biggest misconceptions in modern IT is the assumption that cloud services automatically provide complete protection, and that providers will handle backup and recovery. The problem is exacerbated by SaaS, where the promise of instant access to a solution is enticing and often achieved without IT involvement. 

Even well-established services like Microsoft 365 can have backup blind spots if organizations do not have an independent protection strategy in place 

The term “cloud blindness” has been coined for this and other areas of cloud complacency. 

While cloud services may bake in a certain amount of resiliency, businesses cannot take a hands-off approach to critical areas such as backup and recovery. 

Businesses need to employ a zero-trust policy when it comes to their data integrity. Regardless of who has stored the data or where, and regardless of the promises given in terms of reliability, the backup strategy must remain consistent across the board.  

Backups are about getting back to business 

In a world where ransomware attacks are increasingly common and SaaS outages are frequently making headlines, backups need to be a key part of any compliance posture. 

Every moment of downtime is potentially lost revenue. The legislation’s approach to making IT part of boardroom governance is good for IT teams, and Datto has long been making the case for backups to be an important part of this discussion. 

Read Datto’s The ultimate guide to BCDR: Why backup and disaster recovery matter 

Une plateforme complète pour la gestion informatique et de la sécurité

Kaseya 365 la solution tout-en-un pour la gestion, la sécurisation et l'automatisation de l'informatique. Grâce à des intégrations transparentes entre les fonctions informatiques essentielles, elle simplifie les opérations, renforce la sécurité et améliore l'efficacité.

Une seule plateforme. Tout l'informatique.

Kaseya 365 bénéficient des avantages des meilleurs outils de gestion informatique et de sécurité, le tout dans une solution unique.

Découvrez Kaseya 365

Votre succès est notre priorité absolue.

Partner First, c'est l'engagement d'offrir des conditions flexibles, un partage des risques et un accompagnement dédié à votre entreprise.

Découvrez Partner First Pledge »

Rapport Kaseya 2026 sur la situation des MSP

Kaseya - Rapport 2026 sur la situation des MSP - Image web - 1200 x 800 - MISE À JOUR

Découvrez les perspectives 2026 sur le MSP, issues des témoignages de plus de 1 000 prestataires, et apprenez comment augmenter votre chiffre d'affaires, vous adapter aux pressions du marché et rester compétitif.

Télécharger maintenant

La négligence en matière de cloud met en danger les données européennes de Microsoft 365 et d'Azure

La gestion des données Microsoft 365 et Azure relève de votre responsabilité. Découvrez pourquoi la sauvegarde et la restauration sont essentielles pour protéger vos données dans le cloud contre la perte, les ransomwares et les perturbations.

Lire l'article de blog

Devrions-nous commencer par la résilience et remonter à partir de là ?

Avec le soutien de : Kaseya Cet article de blog a été rédigé par International Data Corporation (IDC), leader mondial de l'analyse de marché, qui partage

Lire l'article de blog

Faire de la protection des données un pilier de la cyber-résilience

Avec le soutien de : Kaseya Cet article de blog a été rédigé par International Data Corporation (IDC), leader mondial de l'analyse de marché, qui partage

Lire l'article de blog