Skip to content

Finance & real estate

Backup and disaster recovery for banks and insurers

Mindtime keeps immutable, encrypted copies of your databases, servers and Microsoft 365 in its own Tier III data centres in the Netherlands and Germany, plus an air-gapped copy. Recovery runs in an isolated environment, and failovers are tested every quarter, which gives your ICT risk team a record to work from.

In Dutch, German or English.

Office building of a financial institution
  • NL · DEStored only in our own Tier III data centres in the Netherlands and Germany
  • ImmutableObject Lock storage plus an air-gapped copy; every backup job is checked
  • ISO 27001 · NEN 7510Audited security, with a data processing agreement in every contract
  • NL · DE · ENSupport from people, no offshore call centres or chatbots

In short

Banks and insurers need backups that sit apart from production and are tested, because DORA requires documented backup and restoration procedures and segregated systems for restoring data. Mindtime stores immutable, encrypted copies in its own Tier III data centres in the Netherlands and Germany, keeps an air-gapped copy, checks every backup job and tests disaster recovery quarterly.

What's at stake

The data banks and insurers can't afford to lose

  • Policy and account administration

    The policy administration or core banking database is the single record of who is covered, who owes what and what has been paid. Losing even one day of changes means rebuilding contracts, premiums and balances by hand.

  • Claims files and customer correspondence

    Claims dossiers, damage photos, expert reports and email threads often live outside the main system, on file shares and in mailboxes. You need them to settle claims and to answer complaints.

  • Evidence for your supervisor

    Customer due diligence files, incident logs and test reports are what you show DNB or the AFM. If ransomware encrypts them, you lose the proof along with the data.

Rules and obligations

What the rules ask of banks and insurers

Summarised from the sources listed at the bottom of this page. This is general information, not legal advice.

  1. DORA has applied since 17 January 2025

    The Digital Operational Resilience Act (Regulation (EU) 2022/2554) applies to banks, insurers, payment institutions, pension funds and other financial entities. It covers ICT risk management, reporting of serious ICT incidents, resilience testing and a register of the ICT services you buy from third parties. [1]

  2. Backup and restore rules in DORA Article 12

    Article 12 requires backup policies that set the scope and minimum frequency of backups based on how critical or confidential the data is, plus restoration and recovery procedures that are tested periodically. Restores must use ICT systems that are physically and logically segregated from the source system. [2]

  3. DNB and the AFM supervise; DORA comes first

    In the Netherlands, DNB and the AFM supervise DORA and can impose penalties, while small firms do not have to meet every rule. Where DORA overlaps with the NIS2 and CER directives, DORA's provisions take precedence. [4]

  4. Banking is a sector under the Cyberbeveiligingswet

    The NCSC lists banking (bankwezen) among the sectors in Annex 1 of the Cyberbeveiligingswet, the Dutch law that implements NIS2. Insurers are not named as a separate sector in that list. [5]

  5. Wwft duties for banks and life insurers

    Banks and life insurers are institutions under the Wwft, the Dutch anti-money-laundering act. Their customer due diligence records are part of the data a backup has to protect. [8]

When it goes wrong

When the attackers go after the snapshots too

Illustrative example: a small insurer finds its file servers and policy administration database encrypted, and the attackers have also deleted the snapshots on its own storage. The Mindtime copies are immutable and one copy is air-gapped, so nothing on the compromised network could change them. The team restores into an isolated recovery environment, scans the restored data for malware and only then returns the systems to production. The backup logs and DR test history go into the incident file for the supervisor.

How Mindtime protects it

Backup for banks and insurers, workload by workload

The software you use, and what we protect around it

ANVACloud platform used across the insurance chain, from advisers and volmachten to insurers. As it is a SaaS platform, check ANVA's export and retention terms; Mindtime protects the Microsoft 365 data, file shares, laptops and servers around it.
Core banking or policy administration databases (SQL Server, Oracle)If your core or policy system runs on your own SQL Server or Oracle database, Mindtime backs up that database and the servers it runs on.
VMware or Hyper-V virtual serversMindtime backs up the virtual machines and, with Disaster Recovery, keeps standby infrastructure ready for a failover.
Microsoft 365 (Exchange, SharePoint, OneDrive, Teams)Claims mail, customer correspondence and board documents. Mindtime backs up the tenant to its own data centres in the Netherlands and Germany.
Document archives on file servers or NASScanned claims, KYC documents and contracts outside the core system. Mindtime backs up the Linux or Windows servers and Synology or QNAP NAS devices that hold them.

Before you switch

What banks and insurers ask us first

  • Our core system supplier already makes backups.

    Your supplier's backup protects their platform, on their terms, while DORA expects you to have your own backup and restore procedures. Mindtime keeps an independent, immutable copy of the data you run yourself: databases, servers, Microsoft 365 and laptops. Every backup job is checked and monitoring runs 24/7.

  • Will our customer data leave the EU?

    No. Mindtime stores data only in its own Tier III data centres in the Netherlands and Germany. Data is encrypted with AES-256 in transit, admin actions require MFA, and a data processing agreement comes with every contract. Mindtime is ISO 27001 and NEN 7510 audited.

  • We don't have the capacity for a migration project.

    Start with a free 15-minute demo to see what moving your backups involves. For Disaster Recovery, the first test failover typically happens within 10 days. Support comes from people who speak Dutch, German or English, not from a chatbot or an offshore call centre.

FAQ

Questions about backup for banks and insurers

Can a backup service cover our DORA obligations?

Only part of them. DORA covers your whole ICT risk framework: governance, incident reporting, resilience testing and third-party management. Mindtime helps you meet the backup and recovery part, with immutable copies kept apart from production in the Netherlands and Germany, an air-gapped copy, checked backup jobs and quarterly disaster recovery tests whose results you can keep as evidence.

Does the Cyberbeveiligingswet apply to us as well as DORA?

Banking is one of the sectors in the Cyberbeveiligingswet, the Dutch NIS2 law that took effect on 15 August 2026. Where its rules overlap with DORA, the Dutch government says DORA takes precedence. For backup and recovery, DORA Article 12 is the more detailed standard to work to, and the NCSC's scope check tells you what else applies.

Do we need to list Mindtime in our register of ICT third-party services?

DNB expects financial institutions to keep an information register of all ICT services they buy from third parties, so a backup service belongs in it. Mindtime provides a data processing agreement with every contract, is ISO 27001 and NEN 7510 audited, and stores data only in its own Tier III data centres in the Netherlands and Germany, which makes the arrangement straightforward to document.

How do we show that our backups can actually be restored?

Every backup job is checked and monitoring runs 24/7. With Disaster Recovery, standby infrastructure is kept ready and failover is tested every quarter, with the first test failover typically within 10 days of starting. DORA asks for periodic testing of backup and restore procedures, and these tests leave a record you can show.

What if ransomware targets the backups themselves?

Backups are written with Object Lock, which makes them immutable, and one copy is kept air-gapped from your network. Backups are scanned for malware, and recovery runs in an isolated environment, so you bring clean data back into production instead of restoring the infection along with it.

See it with your own data

Book a 15-minute demo

We show you a backup and a restore, and answer your questions in Dutch, German or English. No offshore call centres, no chatbots.