The question of cloud backup or local disk usually comes up not in advance, but at the worst possible moment: when the database won’t open, when a ransom note is on the screen, or when the one external drive holding “everything important” simply won’t mount. That’s when the real point becomes clear — a backup matters not because it exists, but because it’s available and intact precisely when the original is already gone.

Let’s look honestly at where copies actually survive disaster, and where they only create a feeling of safety. This isn’t about “modern” versus “old-fashioned.” It’s about which scenarios you’re protecting against.

What a backup actually saves you from

Before choosing a location, name the threats out loud. A backup isn’t needed “just in case” in the abstract — it’s needed against specific events:

  • hardware failure — a disk, server, or phone dies without warning;
  • human error — someone deletes a folder, overwrites a file, “cleans up” the wrong thing;
  • ransomware — malicious software encrypts everything it can reach and demands payment;
  • theft or fire — physical loss of the device along with the data;
  • silent corruption — a file slowly “rots,” and you notice only six months later.

The key is that these threats differ in nature. A copy on a disk sitting next to the server is great against the first one, but helpless against fire and ransomware. So “cloud or disk” isn’t really an either/or — it’s about which gaps you’re closing.

Local disk: fast, under your control, but exposed

A copy on your own disk — an external HDD, a NAS, a separate server — has real advantages. It’s fast: restoring a large database from a disk on the same network takes minutes, not hours of downloading. It’s under your physical control: the data never leaves the premises, which is sometimes critical for sensitive information. And it doesn’t depend on the internet or a monthly bill.

But that very locality is its weak point. A disk that stays permanently connected to the working machine or network gets encrypted by ransomware along with everything else — to malware it’s just another accessible folder. Fire, flooding, a power surge, or theft take the original and the copy at once, because they sit in the same room. And a single external drive that “just works” for years is a deferred disaster: mechanics and memory degrade, and you’ll learn the moment of failure only when you actually need it.

A local backup is a strong first line of defense. But as the only line, it becomes a single point of failure disguised as reliability.

Cloud: survives physical disaster, but comes with conditions

A copy in the cloud closes exactly what the local disk can’t handle. It’s physically elsewhere, so a fire or theft at your office doesn’t touch it. It’s harder for ransomware to destroy — if access is configured properly, and not as an ordinary synced folder. And it scales without buying new hardware.

But “cloud” doesn’t automatically mean “safe.” It has its own pitfalls.

First — sync is not backup. If a folder is simply mirrored to the cloud in real time, then a deleted or encrypted file gets instantly “updated” in the cloud too. You’ve duplicated the problem, not insured against it. A real backup keeps versions and history you can roll back to a point before the disaster.

Second — access and keys. If the cloud account is breached through a weak password with no two-factor authentication, the attacker gets both the data and the copy. The cloud is exactly as safe as the login that guards it.

Third — recovery and verification. Downloading terabytes back over the internet can take far longer than you expect in a moment of stress. And a copy you’ve never tried to restore is an assumption, not a guarantee.

Cloud backup or local disk: the right answer is “both”

When the question is put bluntly — cloud backup or local disk — the practical conclusion is almost always the same: don’t pick one, combine them into a system. The local copy gives speed and independence from the network. The cloud copy survives a physical catastrophe and better resists ransomware. Together they cover the scenarios that each one alone cannot.

An industry benchmark that works well in practice is the “3-2-1” principle: three copies of the data, on two different types of media, with at least one kept off-site. It isn’t dogma, just a simple self-check: if all your copies die from a single event — fire, ransomware, theft — you have no real protection, no matter how many copies you keep.

Another principle that saves the day most often: at least one copy should be “out of reach” of the everyday system — offline, or behind separate access rights that ransomware can’t touch even from infected machines. That copy is what separates an unpleasant incident from a business shutdown.

What makes a backup real rather than nominal

The storage location is only half the job. For a copy to work when it’s needed, a few more things matter — the ones people remember too late:

  • Regularity and automation. A backup made by hand “when I remember” doesn’t get made. It has to run on a schedule, without a human in the loop.
  • Versioning. You need to roll back not to “yesterday,” but to a point before the problem started — otherwise encrypted or corrupted files simply overwrite the healthy ones.
  • Recovery testing. A copy should be periodically deployed for real to confirm it’s intact and readable. An untested backup is hope, not a system.
  • Access control. Who can erase or overwrite the copies, and with what, is a separate question. A copy that can be destroyed by the same account as the original protects you poorly.

This is where “cloud backup or local disk” stops being a choice of media and becomes a question of architecture: how the schedule, versions, permissions, and checks are set up.

Where to start

We’ve been working as a studio since 2018, we run our own infrastructure and support, and in practice we see the same thing again and again: the ones who lose data aren’t those who “had no backup,” but those whose backup was wrong — sync instead of copies, one disk instead of two layers, a recovery that was never tested.

The place to start isn’t buying a disk or a cloud plan, but a simple conversation: which data is critical for you, what its loss costs per day of downtime, and which threats exactly you’re defending against. From there you build a system where the copies truly survive disaster. If you’d like, let’s start with a short brief and look together at where the weak spot in your current backup really is.