Back to glossary

Backup site

4 min read

A backup site is the secondary facility an organisation can move its critical systems and data to when the primary one is unavailable, whether because of a disaster, a hardware failure or an attack.

July 30, 2026
Compartir:

A backup site is the part of an organisation’s infrastructure kept ready to take over so that the business can keep running when something adverse happens to the primary site.

Those events include natural disasters, hardware failures, cyberattacks and anything else that makes systems and data unavailable where they normally live.

What makes one useful

Copies of what matters. Its first job is holding copies of critical data and system state so that they are available when the originals are lost, damaged or corrupted.

Redundant infrastructure. Servers, storage and networking duplicated so there is no single point of failure, and enough capacity to actually carry the load rather than to demonstrate that it exists.

A rehearsed recovery process. The measure of a backup site is how quickly essential services and data actually come back, which depends on documented, automated and practised procedures rather than on the equipment.

Why it matters

Continuity. After a disaster or a serious incident, continuing to operate is what decides how much the incident costs.

Protection against permanent loss. Regular copies held away from the primary environment are what stand between an incident and data that is simply gone.

Regulatory expectation. Several sectors are required to have recovery arrangements and to be able to evidence them, so the site is also part of a compliance answer.

A worked example

A financial services company is hit by ransomware that reaches its critical systems and leaves the data needed for daily operations inaccessible.

A properly implemented backup site would have been holding regular copies of that data, kept out of reach of the attack.

In response, the team activates the disaster recovery plan. The backup site is what makes restoration possible, bringing the affected systems back with as little downtime as the plan allows.

Note the condition in that sentence, because it is the one that fails in practice: out of reach of the attack. A secondary site reachable with the same credentials, from the same network, is a copy of the problem rather than a way out of it, which is the argument for immutable backups.

Hot, warm and cold, and why the choice is not technical

Backup sites are usually described in three degrees, and the difference is time against cost.

A hot site is running, synchronised and able to take the load in minutes. A warm site has the infrastructure but needs data restored and services started, which is hours. A cold site is space and connectivity, and everything else has to be built, which is days.

Which one is right is not an infrastructure decision. It comes from two numbers, the recovery time objective and the recovery point objective, and those come from a business impact analysis: how long the organisation can be down, and how much recent work it can afford to lose. Choosing the tier before answering those questions is how organisations end up paying for a hot site to protect a process that could have waited two days, or discovering the opposite during an incident.

And a backup site is not the same thing as high availability. High availability keeps a service running through a component failure; a backup site is what you use when the whole site is gone.

Where to read more

CISA, Business continuity and disaster recovery planning: guidance on planning, including the role of backups and redundant infrastructure.

SANS Institute, The disaster recovery plan: an introduction to business continuity and what a plan has to contain to be usable under pressure.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.