With ransomware, your backup is the difference between two days and two months of standstill. Attackers know that too, which is why "we make backups" has not been the whole answer for years.
Why does a backup have to sit outside the network?
Because ransomware encrypts any backup it can reach as a matter of course. A backup drive permanently attached to the server, or a network share the administrator account can reach, is lost in the same attack as everything else.
So the requirement is: at least one copy offline, on a separate account, or stored immutably. The three-two-one rule of thumb helps: three copies, on two kinds of storage, one of which is off site.
What is a restore test and why does everyone ask about it?
A restore test is actually putting a backup back on a test environment, with a written outcome. It is where most companies come unstuck, and auditors know it: backups that have run for years but were never restored regularly turn out to be incomplete, corrupt or unworkably slow during a real incident.
Testing at least once a year and recording the outcome is enough. That report is immediately a strong piece of evidence towards customers; few documents say so much in so few pages.
Am I missing anything if everything is in the cloud?
The common assumption is that the cloud provider takes care of it. But they look after the availability of the platform, not your data: whoever deletes something in a cloud package, or has it encrypted, is usually simply without it. So include your cloud applications in the backup schedule, or record why that is not necessary.
What belongs in a continuity plan?
The answer to the question: how do we keep delivering, invoicing and communicating if IT is out for days? Fallback scenarios per critical business process, a phone list that also exists offline, and a rehearsal once a year. It does not have to be a tome; it has to be right on the day you need it.
How long do I have to keep backups?
The law names no period, because that follows from how you run your business and from the retention duties you have. What customers do want to see is that you made a choice and can explain it.
A common schedule for a supplier: daily backups going back a month, weekly ones kept for a quarter, and monthly ones for a year. The reason to go back further than a few days is ransomware: attackers are often inside a network for weeks before they strike, and yesterday's backup may already contain the attacker.
Watch the overlap with privacy law. Personal data you should have deleted under your own retention policy is still sitting in old backups; record how you deal with that, because the question comes back in the data processing agreement.
What does a customer mean by RTO and RPO?
Two numbers that together summarise your whole continuity story. The RTO (recovery time objective) is how long it may take before you are running again. The RPO (recovery point objective) is how much work you may lose at most, and therefore follows from how often you back up: back up once a night and your RPO is a day.
Questionnaires increasingly ask for these, and it is one of the few places where a concrete number is expected. Decide per critical process what you promise, check at the annual restore test whether you make it, and put the result in your answer. An RTO you have tested is worth more than a nicer RTO you are hoping for.
This part sits alongside the other nine; a customer rarely asks about a single measure. That the backups themselves should be encrypted is one of the standard follow-up questions.