Network Bridge Solutions

Are the backups encrypted, tested, and NIS2-aligned?

Short answer

Encryption is the easy part, and reputable services do it as standard. What fails is a restore nobody has ever tried, and a copy that sits within reach of the admin account an attacker has just taken over. NIS2 lists backup management and disaster recovery among its required measures, so the honest test is whether you can show your backups work, not whether you assume they do.

Three tests your backups have to pass: encrypted, tested, and out of reach of the account that just got compromised.

Part of Microsoft 365 x NIS2
A works van with a flat rear tyre and a flat spare wheel propped against its rear bumper.

The sentence that costs the most

Ask a roomful of business owners who backs up their Microsoft 365 and many will say, with real confidence, "Microsoft does". It is the most expensive sentence in cloud computing, because it is a quarter true, and the missing three quarters only becomes visible on the worst day of the year.

Here is the honest division of labour. Microsoft protects the platform: the data centres, the hardware, the replication between them, the service coming back after their failure. That side of the deal is kept well. What the platform does not do by default is protect your data from the things that actually delete data: your people, your processes, and your attackers. The recycle bins and retention settings buy you a window; anything beyond it is something you have to configure or buy.

A leaver's account is closed and the retention window quietly expires with their files in it. A member of staff deletes a folder in March and the absence is noticed in September. Ransomware encrypts the files on a laptop and the sync engine faithfully copies the encrypted versions to the cloud, as designed. An attacker inside an admin account deletes what he touched on the way out. In every case the platform did exactly what it promises. And in every case the question is the same: do you hold a copy that does not live inside the thing that just went wrong?

What NIS2 actually asks

The directive is blunt about this in a way that many compliance topics are not. Article 21's list of mandatory measures includes, in as many words, business continuity: backup management, disaster recovery, and crisis management. It also requires policies on the use of cryptography and, where appropriate, encryption, and, like every measure on that list, it has to be something you can show rather than assume.

Notice what that means for the question this article answers. "Are the backups encrypted, tested, and NIS2-aligned?" is a question your business should be able to answer, in writing, about its own arrangements. It is not a feature you buy. It is a discipline you can evidence, and a customer's questionnaire will probe it with exactly those words: what do you back up, how often, is it encrypted, when did you last restore something, how long could you be down?

The three tests

Encrypted is the easiest, and the least sufficient. Data should be encrypted in transit and at rest, wherever the copy lives, and the keys should not be lying next to the safe. Modern platforms and reputable backup services do this as standard. Encryption is necessary. It has also become the checkbox that lets people stop reading, and the next two tests are where the real failures live.

Tested is where good intentions die. An untested backup is a hope, not a control. The test that counts is a restore: pick a mailbox, a folder, a site, and actually bring it back, on a schedule, with the time it took written down. Businesses that do this discover things while they are cheap to discover: the licence lapsed, the coverage missed a whole workload, the restore takes four days when the business can survive one. The final report NIS2 requires after a significant incident sets out the mitigation you applied, which is your recovery told after the fact; a rehearsed restore is the difference between a paragraph you are proud of and one you are not.

Independent is the test a default Microsoft 365 setup fails outright. A copy that the same admin accounts can reach and delete, protected by the same credentials, is not a backup against the scenarios that matter. It is the same basket with extra eggs. Real independence means the account an attacker owns on Tuesday cannot destroy your recovery on Wednesday: either a copy held separately under separate credentials, or one that is locked against deletion and that you have checked is locked. Retention features inside the platform are valuable and worth configuring, but they answer a different question.

The implication

Under NIS2, continuity stops being an IT preference and becomes an evidenced obligation. The practical consequence is pleasant, though: this is among the most answerable topics in the whole directive. Backups are concrete. Either the copy exists or it does not; either the restore was tested in June or it was not. A business that can produce a one-page backup statement, a restore log and a retention decision reads, to any auditor or customer, like a business that runs itself deliberately.

Where to start

First, write down what you actually have. Which workloads are covered, mail, files, sites, the lot; where the copies live; who holds the credentials. Expect to find at least one workload nobody is backing up.

Second, decide two numbers in plain words. How much work can we afford to lose, a day, an hour? And how long can we afford to be down? These two management decisions, not any product, define what your backups must be. Write them down; they are the "NIS2-aligned" part.

Third, make one copy independent. Held separately under separate credentials, or locked against deletion and checked.

Fourth, restore something this month. Small is fine. Time it, log it, diarise the next one. The log is the evidence, and the habit is the control.

The platform's half of the deal is kept in data centres you will never see. Your half is four decisions and a habit. NIS2 simply asks you to make your half real, and to be able to show it, before the day that tests it arrives on its own schedule.

Related questions

What are the most common mistakes small businesses make with Microsoft 365 security?3 min read
Doesn't antivirus and MFA mean we're covered?4 min read
Why do default Microsoft 365 settings fail a NIS2 audit?5 min read
Previous question
Can you help us with our incident response plan?
Next question
Will this help us meet the 24-hour incident reporting requirement under NIS2?

Prefer the conversation to the reading?

Thirty minutes on the alignment between your strategy and your technology. Not a sales pitch.

Book a discovery call →