The question is not whether managed backup appears more modern than a self-operated backup environment. What matters is which operating model a company can truly sustain in day-to-day practice. That is what determines whether backup merely exists on paper or whether recovery will actually work when it matters.
In practice, we often see the discussion move too quickly to tools, licences or hosting models. The more useful perspective is usually different: Who monitors the jobs? Who responds to failures? Who tests restores on a regular basis? Who documents the setup in a way that stands up in audits, internal governance and crisis situations? Only when those questions are answered does a backup solution become a viable recovery strategy.
Direct control speaks in favour of running backup in-house
A self-operated backup solution has one clear advantage: maximum control. Architecture, policies, retention periods, role and access models, and recovery procedures remain fully in your hands. That is a genuine benefit when sufficient in-house expertise already exists and backup is treated as an operating discipline in its own right rather than something handled on the side.
In more complex environments, that can make all the difference. Organisations running multiple platforms, specific compliance requirements or historically grown structures do not always fit neatly into a standardised managed model. In those cases, an in-house solution can often be aligned more precisely with the actual operating environment.
The operational cost of in-house ownership is often underestimated
The difficulty usually does not sit in the software itself, but in the ongoing operation. CISA and NIST are very clear that backups must be protected, documented and tested regularly if they are expected to help in a crisis.[1][2][3] That is exactly where many environments become vulnerable — not because backups are missing, but because the operational foundation beneath them is not stable enough.
Setting up backup jobs is only the starting point. Monitoring, escalation, immutable or offline concepts, error tracking, restore testing, recovery documentation and clear ownership all matter. If an organisation can sustain that internally over time, it has strong arguments for self-operation. If it cannot, it should not downplay the issue.
Managed backup can relieve pressure — but it does not replace responsibility
That is where a managed approach has real strengths. If internal resources are limited or backup operations do not get the attention they require, an external operating model can provide substantially more reliability. This applies not only to job monitoring, but also to error handling, capacity management, escalation and defined recovery procedures.
This matters for another reason as well: staffing shortages are real. The ISC2 Workforce Study 2025 once again points to a substantial gap in the cybersecurity labour market.[4] Backup is not the same as security, but in practice the disciplines overlap far more than they used to — especially around recovery, access protection and cyber resilience.
The threat landscape also argues against treating backup as a routine task. ENISA continues to list ransomware among the central cyber threats in Europe.[5] At the same time, CISA and MS-ISAC recommend, among other things, offline backups, protected backup data and regular restore testing.[1] A managed service can help embed exactly these disciplines more reliably into day-to-day operations. What it does not do is remove the company’s obligation to define requirements, priorities and control points clearly.
Shared responsibility remains in place
This is, in our view, one of the most important points in the debate: outsourcing backup does not automatically outsource responsibility. The shared-responsibility models of AWS and Microsoft make that very clear.[6][7] A service provider can take on clearly defined operational tasks. Responsibility for protection requirements, prioritisation, governance, data classification and many compliance questions still remains with the company.
If that distinction is not properly understood internally, false expectations emerge. A managed service can then quickly turn into the expectation that “someone else will take care of everything.” That is exactly what companies should separate clearly before making a decision: opperational relief, while responsibility remains with the company.
Compliance makes the issue binding
This distinction becomes unavoidable in regulated environments. The GDPR requires the ability to restore the availability of and access to personal data, as well as processes for regularly testing and evaluating security measures.[8] NIS2 explicitly refers to backup management, disaster recovery and crisis management as elements of risk management.[9] DORA requires, among other things, backup policies, recovery procedures and ICT business continuity arrangements for financial entities.[10]
That means backup is not just a technical issue. It is a governance issue. Even where operations are outsourced, the organisation must still steer, review and demonstrate control.
In-House Operations or Managed Services: What Is Your Operational Threshold?
An in-house model makes sense when sufficient internal depth exists to design and operate backup and recovery in a disciplined way. That includes monitoring, testing practice, documentation and clear ownership.
Managed backup is a better fit where that operating discipline is necessary but cannot be delivered with the required consistency through internal resources alone. This is especially true where teams are overloaded, response times matter or backup needs to work reliably without being reprioritised internally every single day.
Conclusion: A sound decision depends on factors within the company
Managed backup is not automatically the better option. But a self-operated backup solution does not automatically mean more control either. The more durable decision is the one that matches the organisation’s staffing reality, operational maturity and recovery requirements. If the internal setup is strong enough, self-operation can be highly targeted and controlled. If the operational foundation is not stable enough in day-to-day practice, managed backup should be assessed as an operating model — not as a marketing promise.
Therefore never base the decision on the tool alone. The decisive question is which model your organisation can operate, test and defend reliably over time.
Health Check
If you want to understand how resilient your current backup and recovery organisation really is, we would be glad to support you with a health check of your existing environment. And if you want to assess whether a managed approach or an individual service concept is the better fit for your resources and requirements, we would be happy to discuss that with you in a structured way — without standard answers, and with a clear view of your actual operating reality.
Sources
[1] CISA; MS-ISAC: “Ransomware Guide,” 2023. Available at: https://www.cisa.gov/stopransomware/ransomware-guide
[2] NIST: “Contingency Planning Guide for Federal Information Systems (SP 800-34 Rev. 1),” 2010. Available at: https://csrc.nist.gov/pubs/sp/800/34/r1/final
[3] NIST: “Guide for Cybersecurity Event Recovery (SP 800-184),” 2016. Available at: https://csrc.nist.gov/pubs/sp/800/184/final
[4] ISC2: “2025 Cybersecurity Workforce Study,” 2025. Available at: https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
[5] ENISA: “ENISA Threat Landscape 2024,” 2024. Available at: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024
[6] Amazon Web Services: “Shared Responsibility Model.”: https://aws.amazon.com/compliance/shared-responsibility-model/
[7] Microsoft Learn: “Shared responsibility in the cloud.”: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility
[8] European Union: Regulation (EU) 2016/679 (GDPR), Article 32, 2016. Available at: https://eur-lex.europa.eu/eli/reg/2016/679/oj
[9] European Union: Directive (EU) 2022/2555 (NIS2), Article 21, 2022. Available at: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
[10] European Union: Regulation (EU) 2022/2554 (DORA), 2022. Available at: https://eur-lex.europa.eu/eli/reg/2022/2554/oj