Data Centers

Five challenges for moving backup to the cloud

As cloud-based services continue to gain in popularity, traditional network-based infrastructure services are making their way out of the data center. Find out what to consider for cloud-based backup services.

A few years ago, cloud-based backups were a pipe dream; there were no economics that supported such an effort, and Internet connections were relatively slow. Today, even bandwidth-intensive services can often be supported. If your organization is deciding whether to move to cloud backups, here are five things to consider.

1: Cost

There are a variety of ways to charge for backup services. Several options include:

  • Many providers will charge for storage and bandwidth use but base it on tiers of service -- so the more you use, the less you pay per increment.
  • Some providers will charge you a flat fee based on unlimited use or how much data you plan to store; others will charge you based on your storage use and bandwidth used to transfer the data.
  • Some providers may charge more for additional backup services, such as offloading to tape.

The bottom line is make sure you understand your backup patterns and needs and how your selected vendor's pricing fits so that you don't get any nasty surprises.

2: Bandwidth

In general, Internet bandwidth tends to scale based on the size of the company or the office. A small company with a couple of employees might do just fine with a DSL connection to the Internet, while that 5,000 corporate behemoth down the street might enjoy a multi-gigabit redundant Internet connection. In either case, if backup services are to be outsourced to the cloud, both upstream and downstream bandwidth needs require careful scrutiny. Remember, for many Internet connections, there is a huge difference between upstream and downstream connection speeds, with upstream speeds often capped at very low rates when compared to the downstream side of the pipe. A cloud based backup service could easily saturate that upstream connection.

My hunch is that smaller companies would be more interested in cloud-based backup services than larger companies; smaller organizations often have residential-style connections to the Internet that feature very good download speeds, but very poor upload speeds. Larger organizations are likely to have a more balanced upload/download ratio; however, a large organization will probably have much more data to back up, too.

Regardless of company size or downstream Internet connection capability, before embarking on a cloud-based backup venture, be sure to evaluate existing infrastructure to make sure that the network is up to the task.

Bandwidth may not be an issue after the initial data load takes place; that is, once that first full backup is complete, many cloud providers send only changed blocks of information over the network to the service provider location.

3: Security

Even as the choice of cloud-based service providers explodes, many people are wary about taking the plunge into the unknown. After all, even if a cloud vendor promises top-notch security, it can be a comfort to keep data under one's own roof and not allow it to traverse the Internet and be stored on some stranger's servers.

All that said, some cloud-based services are too tempting to ignore, so it becomes important to assess the provider's security offerings to make sure that your data is protected and that you aren't accidentally breaking any laws.


Regardless of which cloud backup provider you choose or what you're backing up, end-to-end encryption is absolutely critical. Data should be encrypted while in transit between your source systems and the provider's systems and should remain encrypted while at rest in the provider's data center. Further, if the provider takes additional backup steps beyond that initial disk-based system, ask them for full details about how they protect your data from unauthorized access.

Compliance issues

More and more entities are forcing new requirements on many organizations. From PCI compliance to Sarbanes-Oxley to HIPAA, there are specific steps that need to be taken in some cases to stay on the right side of the compliance issue. You need to pay special attention to your backup provider's contractual language to make sure that you don't unintentionally leave your organization open to legal or compliance issues due to a failure on the part of your backup provider.

Geographic diversity

The purpose of backup is to protect your organization in the event of a disaster -- or at least to make sure that you can recover an accidentally deleted email message. If you're serious about the use of a cloud-based backup provider, don't let a failure on their end (power, data loss, etc.) create a problem for you. Find out if the provider offers geographical redundancy in their service.

Termination agreements

Your arrangement with a cloud-based service provider might end before you originally plan. Before signing a service contract, make sure you create conditions for a successful termination of the relationship by insisting that, upon cancellation or termination of the contract, all of your information is fully purged from the provider's systems. Don't wait until it's time to end the service to make termination arrangements.

4: Recovery

When your backup system sits in your own data center, recovery processes and procedures are a pretty simple matter. If a user needs a file recovered, you just do it. If the data center burns down, you have at your fingertips what you need to rebuild your systems -- procedures and backups. You don't need to worry about bandwidth -- after all, the data center often enjoys massive bandwidth between systems. Once you outsource your backups to the cloud, however, that all-important connection speed raises its ugly head again, particularly in the event of a disaster that requires a major restoration process.

If you run across a particularly substantial challenge, you might even need to go so far as to get a physical dump if your data from the backup provider.  It's possible that having your data shipped to you on physical devices would be faster than performing a full reload of your systems over the Internet.

Before signing your service contract, work with your provider to assess their ability and willingness to help you quickly recover from disaster.

5: Vendor reliability

I believe that we're seeing a huge cloud bubble today, much like the Internet bubble of the 90s. I distinctly remember walking into a Staples and seeing an "Internet compatible computer desk" advertised for sale; today, the word cloud is associated with everything, increasing the possibility that unsustainable companies will rise and then fall or be acquired. Even if a company goes under, the safety of your data is of prime importance.

Although you hope that the provider you choose is in business for the long haul, make sure you plan for the possibility that it will be there one day and gone the next. You should negotiate up front about what happens to your data if a company goes out of business or is acquired and make sure your contract can't be unilaterally changed in the event of an acquisition.

In addition, customer references remain a powerful tool in your analysis arsenal but use them liberally. For particularly large projects, you might even go so far as to visit the vendor's facilities to gain a first-hand look at its operations. Is it run from someone's basement, or do they really have all the bells and whistles (i.e., backup generators, redundant storage services and power) that they promise?

Keep up with Scott Lowe's posts on TechRepublic


Since 1994, Scott Lowe has been providing technology solutions to a variety of organizations. After spending 10 years in multiple CIO roles, Scott is now an independent consultant, blogger, author, owner of The 1610 Group, and a Senior IT Executive w...


Very good article. I totally agree with vendor reliability and compliance issues. Its very important to find a good host and encrypt your data. Chris Armer VP of Operations


Encryption is a must but you forgot to remind people to keep a copy of the encryption key off-site. No point in having cloud backup if your data centre is gone and the encryption key gone with it.


I see that you work at a college. I hope you are not entrusted with young peoples futures there. There is no cloud, only ISP's. There is no fool proof encryption, only a mechanism to delay the detection of data. There is no reason to give any third party possession of your most valuable assets, your information and the information on others that you currently have on your systems. Risking your own future is bad enough, but risking the future, the data, the information and the personal information of others is not just irresponsible, it is criminal. There are NO CONTROLS, and any that do exist will disintegrate when the corporate entities dissolve for one reason or another. Where will your children's future be? If you are reasonably mature, you do not risk your fortunes on others over whom you have no control. Why would you do this to the people who have placed their trust in you? Regards, Les H


We're at the peak of inflated expectations, to use Gartner's Hype Cycle term. It's cloud everything these days. I keep waiting for a cloud iPod. But seriously. When you back up off site, you also want to keep a copy onsite to make the restores go quicker. That takes more space, but if you have the resources then why not. One approach is to backup from the prime source directly to offsite, and then copy back to a local location. This reduces the amount of time that your data is unavailable due to backup, but it puts even higher demands on your data pipe. Backing up over the net will take longer, so don't forget the impact to the availability of your data for the purpose that it's actually intended for.


not me... who wants to upload and download gigs or terabytes of data through the internet... not me. Doesnt make a difference if everything was fiber, huge security issue. what good is your data "in the cloud" when the internet is down or having network problems?

Scott Lowe
Scott Lowe

I don't remember indicating anywhere in the article that I am moving or planning to move any college data in any way, shape or form to the cloud. Although I do not personally believe that it would be in the college's best interests to move data out of the data center, there are organizations considering this very migration and they need to understand what pitfalls are present when doing so. Believe it or not, I don't buy into the cloud hype, but I do understand why it is appealing to many people, which is why I write these kinds of articles - to help people take a step back and really think about what is going on. Scott


If I want to keep my data in a cloud I want that cloud to be on computers I own, not a subscription to someone's service. I don't want to be in the position of suddenly having my data held hostage by a provider that has suddenly doubled the cost of renting that cloud, or has gone out of the cloud business and deleted the data.


Here, more than anywhere, don't be taken aback at having to drop your pants, bend over, and spread them.


Les H didnt manage to make it through his first sentence without making a personal attack. More of a statement on him/her rather than your article. Always enjoy reading up on emerging technologies. Unfortunately, Cloud Technologies (particularly backups) are going to be impractical in countries like Australia where bandwidth quotas and costs are ridiculously out of line with the rest of the world.

Scott Lowe
Scott Lowe

This happens a lot - a personal attack based on something I've written... I'm used to it. I felt that this one needed a response and, after re-reading, don't like my own wording!

Editor's Picks