Alvaro Soriano, leader in cloud platforms and infrastructure, specializing in CSP and PaaS strategy across North America, Australia, and Europe
TL;DR: Moving backup and disaster recovery to the cloud trades server-room maintenance for a new set of questions: where the data legally lives, how fast it restores, and what a real recovery will cost. The average Canadian data breach cost CA$6.98 million in 2025, up 10.4% year-over-year (IBM Cost of a Data Breach Report 2025), yet most providers advertising “Canadian backup” can’t actually back that claim up. Before you sign, a provider should guarantee four things: Canadian data residency and jurisdiction, defined and tested RTO/RPO targets, immutable backups that ransomware can’t alter, and no egress fees on restores. ThinkOn delivers all four on its own Canadian-owned, Canadian-operated infrastructure.
Every Canadian organization running backup or DR out of an on-premises server room eventually asks the same question: should this move to the cloud? The honest answer is usually yes — but “moving backup to the cloud” means something different depending on which provider you ask.
The gap shows up in the fine print, not the sales page. Two providers can both claim “Canadian cloud backup” while one resells hyperscaler capacity subject to foreign law, quotes a recovery time objective it has never tested, stores backups that ransomware can still encrypt, and bills per gigabyte the moment a real restore happens. None of that is visible until an audit, an incident, or a legal request tests it.
ThinkOn delivers offsite backup and disaster recovery on infrastructure it owns and operates in Canada, with defined RTO/RPO commitments, ransomware-resistant immutable repositories, and a no-egress, fixed-cost restore model. The rest of this page answers the specific questions IT and operations teams ask before choosing where their backups actually live.
Glossary
CLOUD Act: U.S. legislation that lets US authorities compel a US-headquartered company to produce data it controls, regardless of where that data is physically stored.
Offsite backup: A copy of data stored at a location separate from the primary system, so a local disaster, ransomware attack, or hardware failure can’t destroy both copies at once.
Disaster Recovery as a Service (DRaaS): A service that replicates workloads to a provider’s infrastructure so they can be failed over and run there if the primary site goes down.
Recovery Time Objective (RTO): The maximum acceptable time between a disruption and full system restoration.
Recovery Point Objective (RPO): The maximum acceptable amount of data loss, measured in time, between the last backup and a disruption.
Immutable backup: A backup copy that cannot be altered, encrypted, or deleted for a set retention period, used to protect recovery points from ransomware.
Data residency: Where data is physically stored, independent of which laws apply to it.
Data sovereignty: The principle that data is subject exclusively to the laws of the country in which it is held — which requires Canadian ownership and operation, not just a Canadian mailing address.
Egress fees: Charges a cloud or backup provider applies when data is moved out of its environment, most commonly during a restore or a provider migration.
What should you consider when moving backups and DR to the cloud in Canada?
Plan for Canadian data residency and law, RTO/RPO targets, immutability against ransomware, and no egress fees, so restores stay fast, compliant, and affordable.
Moving backup and disaster recovery to the cloud trades hardware headaches for a new set of questions: where does the data legally live, how fast can you restore, and what will retrieval cost. Choosing a Canadian, no-egress provider with immutable copies answers all three at once.
What is offsite cloud backup in Canada?
Offsite cloud backup stores a copy of your data with a provider outside your own site, protecting it if your primary location fails, floods, or gets encrypted by ransomware.
For most Canadian organizations, offsite backup now means a cloud repository rather than a second physical site or a box of tapes shipped off-site weekly. The difference between providers isn’t whether they can store the copy — nearly all can — it’s whether the infrastructure it sits on is actually owned and operated in Canada, whether the copy can be altered once written, and what it costs to get the data back during a real restore.
How does offsite backup with Canadian data sovereignty work?
A sovereign offsite backup keeps both the data and its legal jurisdiction Canadian, so no foreign law can compel access regardless of who owns the software layer on top.
Data sovereignty is a stricter standard than data residency. A backup can be physically stored in a Canadian data centre while still being subject to a foreign parent company’s legal obligations — the CLOUD Act is the clearest example, letting US authorities compel a US-headquartered provider to produce data it controls no matter where that data sits. ThinkOn is not subject to any foreign data access or privacy regulations outside of Canada. Only Canadian laws apply to the data we host within Canadian borders. This ensures complete sovereignty and protection for your information.
Why do Canadian businesses need offsite backup?
Local backups fail alongside the systems they’re meant to protect during fire, flood, hardware failure, or ransomware, which is why a geographically separate copy is non-negotiable.
Ransomware incidents in Canada rose an average of 26% year-over-year between 2021 and 2024, a trend the Canadian Centre for Cyber Security expects to continue, and the average Canadian data breach now costs CA$6.98 million, up 10.4% year-over-year (IBM Cost of a Data Breach Report 2025). A local backup sitting on the same network as the system it protects is often the first thing ransomware encrypts. An offsite, immutable copy — one that can’t be altered even if an attacker has admin credentials — is what separates a contained incident from a full data-loss event.
What to check before choosing an offsite backup provider
Globally, 69% of organizations were hit by ransomware in the past year, yet only 10% recovered more than 90% of their data (Veeam 2025 Ransomware Trends Report) — and closer to home, 74% of Canadian ransomware victims paid the ransom demand in 2025, typically because they had no working recovery option of their own (CIRA 2025 Cybersecurity Survey). The table below breaks down what actually separates a resilient offsite backup provider from one that just resells someone else’s infrastructure.
| What to check | Hyperscaler-resold backup | Foreign-owned regional provider | ThinkOn (Canadian-owned) |
| Ownership & operation | Often a reseller layer over hyperscaler infrastructure | Frequently foreign-owned despite a Canadian-sounding brand | Canadian-owned, Canadian-operated |
| CLOUD Act / foreign law exposure | Present if underlying infrastructure is U.S.-headquartered | Present unless ownership is independently confirmed | Eliminated — no foreign parent |
| RTO/RPO commitment | Varies by tier, often untested | Varies, rarely disclosed | Defined and tested per workload |
| Immutable backup support | Varies by tier or add-on | Varies | Included |
| Egress fees on restore | Common, billed per GB | Varies by provider | No-egress, fixed-cost model |
| Independent certifications | Varies | Varies | SOC 2, ISO 27001 |
| Partner/channel path for MSPs | Often resale-only, thin margin | Varies | Channel-only — resell, white-label, or host |
Get pricing — and see it in action
Evaluating an offsite backup and DR provider in Canada? Get a no-obligation quote from ThinkOn.
Want proof first? Download the Umbra case study — a Toronto-based company that rebuilt its recovery strategy with ThinkOn after discovering its backups weren’t running reliably — or download the Accelerated Backup & Recovery tech sheet for full specs and recovery-time commitments.
Key figures at a glance
- CA$6.98 million — average cost of a Canadian data breach in 2025, up 10.4% year-over-year (IBM Cost of a Data Breach Report 2025).
- 26% — average year-over-year increase in Canadian ransomware incidents, 2021–2024 (Canadian Centre for Cyber Security).
- 74% — Canadian ransomware victims who paid the ransom demand in 2025 (CIRA 2025 Cybersecurity Survey).
- 69% / 10% — organizations hit by ransomware in the past year / that recovered more than 90% of their data (Veeam 2025 Ransomware Trends Report).
- $0 — egress fees on ThinkOn offsite backup and DR restores.
Sources
- Canadian Centre for Cyber Security — Ransomware Threat Outlook 2025-2027
- IBM — Cost of a Data Breach Report 2025 (Canada)
- CIRA — 2025 Cybersecurity Survey
- Veeam — 2025 Ransomware Trends: From Risk to Resilience
