Finance & real estate
Backup and disaster recovery for banks and insurers
Mindtime keeps immutable, encrypted copies of your databases, servers and Microsoft 365 in its own Tier III data centres in the Netherlands and Germany, plus an air-gapped copy. Recovery runs in an isolated environment, and failovers are tested every quarter, which gives your ICT risk team a record to work from.
In Dutch, German or English.

- NL · DEStored only in our own Tier III data centres in the Netherlands and Germany
- ImmutableObject Lock storage plus an air-gapped copy; every backup job is checked
- ISO 27001 · NEN 7510Audited security, with a data processing agreement in every contract
- NL · DE · ENSupport from people, no offshore call centres or chatbots
In short
Banks and insurers need backups that sit apart from production and are tested, because DORA requires documented backup and restoration procedures and segregated systems for restoring data. Mindtime stores immutable, encrypted copies in its own Tier III data centres in the Netherlands and Germany, keeps an air-gapped copy, checks every backup job and tests disaster recovery quarterly.
What's at stake
The data banks and insurers can't afford to lose
Policy and account administration
The policy administration or core banking database is the single record of who is covered, who owes what and what has been paid. Losing even one day of changes means rebuilding contracts, premiums and balances by hand.
Claims files and customer correspondence
Claims dossiers, damage photos, expert reports and email threads often live outside the main system, on file shares and in mailboxes. You need them to settle claims and to answer complaints.
Evidence for your supervisor
Customer due diligence files, incident logs and test reports are what you show DNB or the AFM. If ransomware encrypts them, you lose the proof along with the data.
Rules and obligations
What the rules ask of banks and insurers
Summarised from the sources listed at the bottom of this page. This is general information, not legal advice.
DORA has applied since 17 January 2025
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) applies to banks, insurers, payment institutions, pension funds and other financial entities. It covers ICT risk management, reporting of serious ICT incidents, resilience testing and a register of the ICT services you buy from third parties. [1]
Backup and restore rules in DORA Article 12
Article 12 requires backup policies that set the scope and minimum frequency of backups based on how critical or confidential the data is, plus restoration and recovery procedures that are tested periodically. Restores must use ICT systems that are physically and logically segregated from the source system. [2]
DNB and the AFM supervise; DORA comes first
In the Netherlands, DNB and the AFM supervise DORA and can impose penalties, while small firms do not have to meet every rule. Where DORA overlaps with the NIS2 and CER directives, DORA's provisions take precedence. [4]
Banking is a sector under the Cyberbeveiligingswet
The NCSC lists banking (bankwezen) among the sectors in Annex 1 of the Cyberbeveiligingswet, the Dutch law that implements NIS2. Insurers are not named as a separate sector in that list. [5]
Wwft duties for banks and life insurers
Banks and life insurers are institutions under the Wwft, the Dutch anti-money-laundering act. Their customer due diligence records are part of the data a backup has to protect. [8]
When it goes wrong
When the attackers go after the snapshots too
Illustrative example: a small insurer finds its file servers and policy administration database encrypted, and the attackers have also deleted the snapshots on its own storage. The Mindtime copies are immutable and one copy is air-gapped, so nothing on the compromised network could change them. The team restores into an isolated recovery environment, scans the restored data for malware and only then returns the systems to production. The backup logs and DR test history go into the incident file for the supervisor.
How Mindtime protects it
Backup for banks and insurers, workload by workload
- Disaster RecoveryStandby infrastructure and quarterly failover tests give you a tested way to keep running when your own environment is down.
- Database backupPolicy, claims and account data usually sits in SQL Server, Oracle or PostgreSQL databases that need consistent, checked backups.
- VMware and Hyper-V backupMost in-house financial applications run as virtual machines that you want to restore as a whole.
- Microsoft 365 backupCustomer and claims correspondence in Exchange and SharePoint is part of the record you must be able to produce.
- Linux server backupApplication and integration servers often run on Linux and belong in the same backup policy as the databases.
The software you use, and what we protect around it
| ANVA | Cloud platform used across the insurance chain, from advisers and volmachten to insurers. As it is a SaaS platform, check ANVA's export and retention terms; Mindtime protects the Microsoft 365 data, file shares, laptops and servers around it. |
|---|---|
| Core banking or policy administration databases (SQL Server, Oracle) | If your core or policy system runs on your own SQL Server or Oracle database, Mindtime backs up that database and the servers it runs on. |
| VMware or Hyper-V virtual servers | Mindtime backs up the virtual machines and, with Disaster Recovery, keeps standby infrastructure ready for a failover. |
| Microsoft 365 (Exchange, SharePoint, OneDrive, Teams) | Claims mail, customer correspondence and board documents. Mindtime backs up the tenant to its own data centres in the Netherlands and Germany. |
| Document archives on file servers or NAS | Scanned claims, KYC documents and contracts outside the core system. Mindtime backs up the Linux or Windows servers and Synology or QNAP NAS devices that hold them. |
Before you switch
What banks and insurers ask us first
Our core system supplier already makes backups.
Your supplier's backup protects their platform, on their terms, while DORA expects you to have your own backup and restore procedures. Mindtime keeps an independent, immutable copy of the data you run yourself: databases, servers, Microsoft 365 and laptops. Every backup job is checked and monitoring runs 24/7.
Will our customer data leave the EU?
No. Mindtime stores data only in its own Tier III data centres in the Netherlands and Germany. Data is encrypted with AES-256 in transit, admin actions require MFA, and a data processing agreement comes with every contract. Mindtime is ISO 27001 and NEN 7510 audited.
We don't have the capacity for a migration project.
Start with a free 15-minute demo to see what moving your backups involves. For Disaster Recovery, the first test failover typically happens within 10 days. Support comes from people who speak Dutch, German or English, not from a chatbot or an offshore call centre.
FAQ
Questions about backup for banks and insurers
Can a backup service cover our DORA obligations?
Only part of them. DORA covers your whole ICT risk framework: governance, incident reporting, resilience testing and third-party management. Mindtime helps you meet the backup and recovery part, with immutable copies kept apart from production in the Netherlands and Germany, an air-gapped copy, checked backup jobs and quarterly disaster recovery tests whose results you can keep as evidence.
Does the Cyberbeveiligingswet apply to us as well as DORA?
Banking is one of the sectors in the Cyberbeveiligingswet, the Dutch NIS2 law that took effect on 15 August 2026. Where its rules overlap with DORA, the Dutch government says DORA takes precedence. For backup and recovery, DORA Article 12 is the more detailed standard to work to, and the NCSC's scope check tells you what else applies.
Do we need to list Mindtime in our register of ICT third-party services?
DNB expects financial institutions to keep an information register of all ICT services they buy from third parties, so a backup service belongs in it. Mindtime provides a data processing agreement with every contract, is ISO 27001 and NEN 7510 audited, and stores data only in its own Tier III data centres in the Netherlands and Germany, which makes the arrangement straightforward to document.
How do we show that our backups can actually be restored?
Every backup job is checked and monitoring runs 24/7. With Disaster Recovery, standby infrastructure is kept ready and failover is tested every quarter, with the first test failover typically within 10 days of starting. DORA asks for periodic testing of backup and restore procedures, and these tests leave a record you can show.
What if ransomware targets the backups themselves?
Backups are written with Object Lock, which makes them immutable, and one copy is kept air-gapped from your network. Backups are scanned for malware, and recovery runs in an isolated environment, so you bring clean data back into production instead of restoring the infection along with it.
See it with your own data
Book a 15-minute demo
We show you a backup and a restore, and answer your questions in Dutch, German or English. No offshore call centres, no chatbots.