Faced with the explosion of ransomware attacks and growing compliance requirements (GDPR, NIS2, ISO 27001), traditional backup strategies are no longer sufficient. An immutable backup solution combined with ransomware protection through physical isolation (air-gap) has become essential. This article presents the current state of the art in backups for Proxmox VE infrastructure, detailing the key concepts every IT manager needs to master.
For Proxmox infrastructures, adopting a managed PBS in the cloud offers a complete solution: offsite Proxmox backup, native immutability via Proxmox Backup Server, and advanced air-gap options (disk rotation, LTO archiving, bank vault). Unlike an on-premise PBS that requires constant administration and manual replication to a second site, a managed PBS provides offsite backup immediately, with 24/7 monitoring and the technical building blocks GDPR and NIS2 require.

The ransomware threat: why your backups are targeted
Cybercriminals have evolved. Aware that backups represent the last line of defense for businesses, they now prioritize targeting backup systems before encrypting production data. According to the Veeam Ransomware Trends 2024 report, 93% of ransomware attacks explicitly target backups.
A backup accessible from the production network is no longer a backup: it's a target.
This reality requires a fundamental rethinking of backup architecture, integrating principles of physical and logical isolation that we detail below.
The 3-2-1-1-0 rule: evolution of the industry standard
The 3-2-1 rule, popularized by photographer Peter Krogh, recommended keeping 3 copies of your data, on 2 different types of media, with 1 stored offsite. This rule, while still relevant, has been extended to address current threats.
The 3-2-1-1-0 rule explained:
- 3copies of your data (production + 2 backups)
- 2different media types (disk + tape or cloud)
- 1offsite copy (geographically separated)
- 1air-gapped or immutable copy (inaccessible to attackers)
- 0errors after verification (regular restore tests)
This evolution, recommended notably by CISA (Cybersecurity and Infrastructure Security Agency) andENISA, adds two critical requirements: isolation (air-gap) and systematic verification.
ANSSI, for its part, sticks to "3 - 2 - 1"
Mind the source: 3-2-1-1-0 is not an ANSSI recommendation, and attributing it to the French cybersecurity agency is a mistake your reader can check in thirty seconds. The guide "Sauvegarde des systèmes d'information — Les fondamentaux" (ANSSI-BP-100, v1.1, 27 November 2025) states in R11: "It is recommended to apply the '3 - 2 - 1' rule: 3 distinct copies of the data, i.e. the production data plus 2 backups stored on different media, of which 1 offline." Five digits become three.
The nuance is worth the detour, because it is stricter than the extended version: in ANSSI's wording the third digit is offline, not off-site. A copy held at a remote provider but permanently reachable does not satisfy R11 to the letter.
And the next recommendation, R12, is printed in bold — the way the guide flags its highest-priority items: "An offline backup is indispensable (or at least an online off-site one, under certain conditions), even if it is less frequent than regular local online backups." So it is not one tip among many, and the order is explicit: offline first, online off-site as a conditional fallback.
Air-Gapped backup: physical isolation as the ultimate protection
An "air-gapped" backup is a backup that is physically disconnected from the network. This disconnection can be permanent (LTO tapes stored offsite) or temporary (connection only during the backup window).

Common air-gap implementations:
LTO Magnetic Tapes
LTO (Linear Tape-Open) tapes offer a natural air-gap once ejected from the drive. Stored in a fireproof safe, they are completely inaccessible to network attackers.
Rotational disconnected storage
Removable disk system exchanged regularly, with one copy always offline in a separate secure location.
Dedicated isolated network
Backup infrastructure on a physically separate network, with controlled and temporary connection via network diode or unidirectional firewall.
Dedicated sovereign cloud
Offsite backup to a trusted hosted PBS provider with separate strong authentication and no direct connection from the production network. A managed PBS service adds monitoring and maintenance.
Important note: A backup on NAS or SAN accessible via the network, even with different credentials, is NOT air-gapped. An attacker who has compromised your Active Directory or management systems can often reach these systems.
Immutability: tamper-proof backups
Immutability guarantees that a backup cannot be modified or deleted for a defined period, even by an administrator with full privileges. It is a logical protection complementary to physical isolation. Learn why backup account segregation further strengthens this protection.
Immutability technologies for Proxmox:
Proxmox Backup Server (PBS) with protected datastore
PBS allows configuring datastores in append-only mode or with locked retention policies. Combined with a file system like ZFS, it provides robust protection.
PBS DocumentationS3 Object Lock (WORM)
S3-compatible storage with Object Lock allows defining legal or governance retention periods during which objects are immutable. Compliant with SEC 17a-4 requirements. This is the model behind our immutable S3 object backup, kept offsite.
S3 Object Lock DocumentationLTO Tapes with WORM
LTO tapes in WORM (Write Once Read Many) mode offer hardware immutability: once written, data physically cannot be modified.
Each of these technologies fits a different need: our guide to choosing the right backup method helps you weigh immutability, air-gap and archiving against your data volume, budget and regulatory obligations.
Proxmox Backup Server: the optimized native solution
Proxmox Backup Server (PBS) is the backup solution developed by Proxmox for its hypervisors. It offers significant advantages for Proxmox VE environments:
- Block-level deduplication: up to 90% storage space reduction
- Client-side encryption: data is encrypted before transmission (AES-256-GCM)
- Integrity verification: automatic data corruption detection
- Granular restore: recover individual files without restoring the entire VM
- Datastore synchronization: replication to a remote site for DR
Technical reference: For a detailed implementation of PBS in an enterprise context, consult the official Proxmox Backup Server documentation. For a real-world walkthrough — including 75% deduplication on a first full backup — see our Windows 1 TB to PBS case study.
Regulatory compliance: GDPR, NIS2 and ISO 27001
European regulations impose strict requirements for data protection, explicitly including backups:
GDPR (Article 32)
Requires "the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident". Backups must also comply with data subject rights (notably the right to erasure).
NIS2 Directive (2024)
Strengthens cybersecurity obligations for essential and important entities, including risk management measures explicitly covering "business continuity, such as backup management".
ISO 27001 (Annex A.12.3)
Control A.12.3.1 requires "backup copies of information, software and system images made and tested regularly in accordance with an agreed backup policy".
A compliant backup strategy must therefore integrate: encryption, documented restore tests, data location within the EU, and deletion procedures compatible with the right to erasure.
Want to migrate to Proxmox to benefit from these protections?
Discover our complete guide to leaving VMware and migrating to Proxmox VE, with personalized support from our experts.
Read: Leaving VMware — why and howRDEM Systems: your backup partner meeting industry standards
At RDEM Systems, we position ourselves as a secure, reliable offsite backup provider meeting the best market standards. Our NimbusBackup offering natively implements the principles detailed in this article:
Air-gapped backup
Our Drive Bank PBS and Magnetic Bank PBS plans include monthly transfer to a physically isolated vault (LTO tapes stored offsite).
LTO tape archiving
LTO magnetic tapes offer natural cold storage protection: once stored offsite, they are inaccessible to attackers and ransomware.
Our own infrastructure in France, second geo-replication site inside the EU
Our own infrastructure in the Equinix datacenters of the Paris region, on our own BGP network (AS206014). For geo-replicated plans, the second site is in Germany, with a French hosting provider: the distance between sites is what makes geo-replication worth having, and the contract stays under French law. The technical building blocks GDPR requires. Need to host your Proxmox VMs? Discover our 3-2-1 multi-datacenter backup strategy.
End-to-end encryption
Your data is encrypted client-side (AES-256) before transmission. We never have access to your data in clear text.
All our offsite Proxmox backup plans implement these principles. Also check our pricing guide to choose the right plan for your budget. And for complete infrastructure protection, RDEM Systems also offers DRP/BCP facilitated by managed services.
Sources and references
- Veeam - Ransomware Trends Report 2024
- ANSSI — Sauvegarde des systèmes d'information, les fondamentaux (ANSSI-BP-100, v1.1)
- CISA - Stop Ransomware
- ENISA - Ransomware Threat Landscape
- Proxmox Backup Server - Official Documentation
- ISO/IEC 27001 - Information Security
- Directive (EU) 2022/2555 - NIS2
- GDPR - Article 32: Security of Processing
Protect your Proxmox VMs with NimbusBackup
Offsite, immutable and sovereign backup. Starting at 12 EUR/TB/month.
