Support: 1 877 787 0306 PARTNER PORTAL


United States
Canada
Australia

Aug 25, 2026 | Blogs, Resources

Offsite Backup Canada: What Your Provider Must Guarantee

Alvaro Soriano, leader in cloud platforms and infrastructure, specializing in CSP and PaaS strategy across North America, Australia, and Europe

TL;DR: Moving backup and disaster recovery to the cloud trades server-room maintenance for a new set of questions: where the data legally lives, how fast it restores, and what a real recovery will cost. The average Canadian data breach cost CA$6.98 million in 2025, up 10.4% year-over-year (IBM Cost of a Data Breach Report 2025), yet most providers advertising “Canadian backup” can’t actually back that claim up. Before you sign, a provider should guarantee four things: Canadian data residency and jurisdiction, defined and tested RTO/RPO targets, immutable backups that ransomware can’t alter, and no egress fees on restores. ThinkOn delivers all four on its own Canadian-owned, Canadian-operated infrastructure.

Every Canadian organization running backup or DR out of an on-premises server room eventually asks the same question: should this move to the cloud? The honest answer is usually yes — but “moving backup to the cloud” means something different depending on which provider you ask.

The gap shows up in the fine print, not the sales page. Two providers can both claim “Canadian cloud backup” while one resells hyperscaler capacity subject to foreign law, quotes a recovery time objective it has never tested, stores backups that ransomware can still encrypt, and bills per gigabyte the moment a real restore happens. None of that is visible until an audit, an incident, or a legal request tests it.

ThinkOn delivers offsite backup and disaster recovery on infrastructure it owns and operates in Canada, with defined RTO/RPO commitments, ransomware-resistant immutable repositories, and a no-egress, fixed-cost restore model. The rest of this page answers the specific questions IT and operations teams ask before choosing where their backups actually live.

CLOUD Act: U.S. legislation that lets US authorities compel a US-headquartered company to produce data it controls, regardless of where that data is physically stored.

Offsite backup: A copy of data stored at a location separate from the primary system, so a local disaster, ransomware attack, or hardware failure can’t destroy both copies at once.

Disaster Recovery as a Service (DRaaS): A service that replicates workloads to a provider’s infrastructure so they can be failed over and run there if the primary site goes down.

Recovery Time Objective (RTO): The maximum acceptable time between a disruption and full system restoration.

Recovery Point Objective (RPO): The maximum acceptable amount of data loss, measured in time, between the last backup and a disruption.

Immutable backup: A backup copy that cannot be altered, encrypted, or deleted for a set retention period, used to protect recovery points from ransomware.

Data residency: Where data is physically stored, independent of which laws apply to it.

Data sovereignty: The principle that data is subject exclusively to the laws of the country in which it is held — which requires Canadian ownership and operation, not just a Canadian mailing address.

Egress fees: Charges a cloud or backup provider applies when data is moved out of its environment, most commonly during a restore or a provider migration.

Plan for Canadian data residency and law, RTO/RPO targets, immutability against ransomware, and no egress fees, so restores stay fast, compliant, and affordable.

Moving backup and disaster recovery to the cloud trades hardware headaches for a new set of questions: where does the data legally live, how fast can you restore, and what will retrieval cost. Choosing a Canadian, no-egress provider with immutable copies answers all three at once.

Offsite cloud backup stores a copy of your data with a provider outside your own site, protecting it if your primary location fails, floods, or gets encrypted by ransomware.

For most Canadian organizations, offsite backup now means a cloud repository rather than a second physical site or a box of tapes shipped off-site weekly. The difference between providers isn’t whether they can store the copy — nearly all can — it’s whether the infrastructure it sits on is actually owned and operated in Canada, whether the copy can be altered once written, and what it costs to get the data back during a real restore.

A sovereign offsite backup keeps both the data and its legal jurisdiction Canadian, so no foreign law can compel access regardless of who owns the software layer on top.

Data sovereignty is a stricter standard than data residency. A backup can be physically stored in a Canadian data centre while still being subject to a foreign parent company’s legal obligations — the CLOUD Act is the clearest example, letting US authorities compel a US-headquartered provider to produce data it controls no matter where that data sits. ThinkOn is not subject to any foreign data access or privacy regulations outside of Canada. Only Canadian laws apply to the data we host within Canadian borders. This ensures complete sovereignty and protection for your information.

Local backups fail alongside the systems they’re meant to protect during fire, flood, hardware failure, or ransomware, which is why a geographically separate copy is non-negotiable.

Ransomware incidents in Canada rose an average of 26% year-over-year between 2021 and 2024, a trend the Canadian Centre for Cyber Security expects to continue, and the average Canadian data breach now costs CA$6.98 million, up 10.4% year-over-year (IBM Cost of a Data Breach Report 2025). A local backup sitting on the same network as the system it protects is often the first thing ransomware encrypts. An offsite, immutable copy — one that can’t be altered even if an attacker has admin credentials — is what separates a contained incident from a full data-loss event.

Globally, 69% of organizations were hit by ransomware in the past year, yet only 10% recovered more than 90% of their data (Veeam 2025 Ransomware Trends Report) — and closer to home, 74% of Canadian ransomware victims paid the ransom demand in 2025, typically because they had no working recovery option of their own (CIRA 2025 Cybersecurity Survey). The table below breaks down what actually separates a resilient offsite backup provider from one that just resells someone else’s infrastructure.

What to checkHyperscaler-resold backupForeign-owned regional providerThinkOn (Canadian-owned)
Ownership & operationOften a reseller layer over hyperscaler infrastructureFrequently foreign-owned despite a Canadian-sounding brandCanadian-owned, Canadian-operated
CLOUD Act / foreign law exposurePresent if underlying infrastructure is U.S.-headquarteredPresent unless ownership is independently confirmedEliminated — no foreign parent
RTO/RPO commitmentVaries by tier, often untestedVaries, rarely disclosedDefined and tested per workload
Immutable backup supportVaries by tier or add-onVariesIncluded
Egress fees on restoreCommon, billed per GBVaries by providerNo-egress, fixed-cost model
Independent certificationsVariesVariesSOC 2, ISO 27001
Partner/channel path for MSPsOften resale-only, thin marginVariesChannel-only — resell, white-label, or host

Evaluating an offsite backup and DR provider in Canada? Get a no-obligation quote from ThinkOn.

Want proof first? Download the Umbra case study — a Toronto-based company that rebuilt its recovery strategy with ThinkOn after discovering its backups weren’t running reliably — or download the Accelerated Backup & Recovery tech sheet for full specs and recovery-time commitments.

  • CA$6.98 million — average cost of a Canadian data breach in 2025, up 10.4% year-over-year (IBM Cost of a Data Breach Report 2025).
  • 26% — average year-over-year increase in Canadian ransomware incidents, 2021–2024 (Canadian Centre for Cyber Security).
  • 74% — Canadian ransomware victims who paid the ransom demand in 2025 (CIRA 2025 Cybersecurity Survey).
  • 69% / 10% — organizations hit by ransomware in the past year / that recovered more than 90% of their data (Veeam 2025 Ransomware Trends Report).
  • $0 — egress fees on ThinkOn offsite backup and DR restores.
  • Canadian Centre for Cyber Security — Ransomware Threat Outlook 2025-2027
  • IBM — Cost of a Data Breach Report 2025 (Canada)
  • CIRA — 2025 Cybersecurity Survey
  • Veeam — 2025 Ransomware Trends: From Risk to Resilience

Connect on Social