Blog 21.11.2023r.

Secondary Storage: Definition, Devices, and How It Can Support Your Backup Strategy

What secondary storage really means, the storage tiers that hold your backups — from disk and NAS to object storage, cloud, and tape — and how to use them for a resilient, ransomware-proof 3-2-1 strategy.

Data can be lost to hardware failure, human error, ransomware, or disaster — which is why every serious backup strategy depends on somewhere safe to keep a second copy. That “somewhere” is secondary storage. This article clears up what the term actually means, walks through the storage tiers used for backups in 2026, and explains how to use them for a resilient, recoverable data-protection strategy.

What is secondary storage?

The term is used in two different senses, and it’s worth separating them.

In computing terms, storage is split into primary and secondary. Primary storage is the fast, volatile memory the CPU accesses directly — RAM and cache — which loses its contents when powered off. Secondary storage is the non-volatile, persistent storage the CPU reaches through I/O rather than directly: hard drives, SSDs, USB flash, optical media, tape, and network storage. By this definition, even an internal SSD is secondary storage — the distinction is volatile vs. persistent, not internal vs. external.

In data-protection terms, “secondary storage” usually means something more specific: the tier where backups, secondary copies, and less-active data live, as opposed to primary storage — the production storage serving your live workloads. This is the sense that matters for a backup strategy, and the one this article focuses on. Secondary storage is where your recovery points sit, ready to restore when primary storage fails or is compromised.

Types of secondary storage for backups

Modern backup strategies use more than one tier, because each has a different balance of speed, cost, and resilience. The main options:

TierBest forSpeedCost per TBRansomware resilience
External / local disk (HDD, SSD)Fast local backups and restoresFastMediumLow (online)
NASShared, centralized on-site storageFast (LAN)MediumLow–medium (online)
Object storage (S3-compatible)Scalable backup targets, offsite copiesVariesLow–mediumHigh with immutability (Object Lock)
Cloud / STaaSOffsite copies without managing hardwareVariesPay-as-you-goHigh with immutability
TapeLong-term archives and air-gapped copiesSlowLowestHighest (offline air-gap)
  • External and local disk (HDD/SSD) — fast and simple for on-site backups; SSDs are quicker and more durable, HDDs cheaper per terabyte.
  • NAS — centralized, network-accessible storage that multiple systems can back up to (remember: a NAS is a backup target, not a backup by itself).
  • Object storage — S3-compatible storage, on-premises or in the cloud, ideal as a scalable backup destination; with Object Lock it can be made immutable.
  • Cloud / Storage-as-a-Service (STaaS) — offsite backup destinations you consume as a service, without buying and running hardware.
  • Tape — unbeatable cost per terabyte and a true offline air gap, ideal for archives and cyber-resilient copies.

(For a deeper look at choosing among these, see our post on [backup destination types].)

How secondary storage supports your backup strategy

Secondary storage is what turns “we make backups” into “we can recover.” A few principles:

Follow 3-2-1-1-0. The modern standard: 3 copies of data, on 2 different media types, 1 offsite, 1 offline or immutable, and 0 recovery errors (verified by testing). That naturally spreads your data across more than one secondary-storage tier — for example, fast disk on-site plus immutable object storage or tape offsite.

Use the right backup types. A full backup is a complete copy; incremental backups capture only what changed since the last backup, saving time and space (a full restore then needs the full plus its increments). Synthetic fulls merge these into a fresh full without re-reading the source. Matching backup type to tier keeps storage efficient. (See our explainer on [full, incremental, differential, and synthetic backups].)

Keep a copy the attacker can’t reach. This is the single biggest shift in recent years. Ransomware deliberately targets online backups, so at least one secondary copy should be immutable (Object Lock) or air-gapped (offline tape) — untouchable even if production and online backups are compromised.

Choosing secondary storage

Weigh these factors against your needs:

  • Capacity — enough headroom for your data plus growth and retention.
  • Speed — how fast you can back up and, crucially, restore (which drives your RTO).
  • Reliability and durability — component quality, redundancy, and expected media life.
  • Security — encryption in transit and at rest, access controls, and immutability options.
  • Cost — total cost per terabyte over the retention period, including any cloud egress fees.
  • Connectivity — how the tier integrates: local (USB, SATA/SAS), network (Ethernet, NFS/SMB), or API (S3).

Best practices

  • Automate a regular schedule matched to how often your data changes — the more critical and fast-changing, the more frequent.
  • Retain multiple versions (see our [Grandfather-Father-Son] guide) so you can roll back to a clean point, not just the latest one.
  • Encrypt sensitive data before it leaves primary storage.
  • Make a copy immutable or offline for ransomware resilience.
  • Test restores regularly. A backup you’ve never restored isn’t yet a backup you can trust — and tested recovery is increasingly a regulatory expectation (DORA, NIS2).

Where Storware fits

Storware Backup and Recovery is built to use secondary storage flexibly. It supports a wide range of backup destinations — local storage, S3-compatible object storage, tape libraries, third-party targets, and Storware Cloud (a Storage-as-a-Service secondary destination with built-in immutability, deduplication, and geolocation options) — with immutable and air-gapped options for ransomware resilience. That makes it straightforward to implement a proper 3-2-1-1-0 strategy across the tiers that fit your environment, all under a single universal license.

Ready to protect your data?

Final thought

Secondary storage is the foundation of any backup strategy — the place your recovery points live when primary storage fails. In 2026, choosing it well means thinking in tiers (fast disk, scalable object and cloud, and cost-effective air-gapped tape), spreading copies across them per the 3-2-1-1-0 rule, keeping at least one copy immutable, and testing that you can actually restore. Get that right, and whatever happens to your primary data, you’ll have a clean, recoverable copy waiting.

Blog

You might also like...

AI Agents and Data Loss: Why Recovery Comes First Blog

AI Agents and Data Loss: Why Recovery Comes First

An AI agent deleted a production database and its backups in 9 seconds. Why immutable copies, long retention, and anomaly detection now matter

Read more
RAID Is Not Backup: Storage in the AI Price Era Blog

RAID Is Not Backup: Storage in the AI Price Era

Drive prices are surging and capacities ballooning, so one failure hurts more. Why RAID is not backup, and how the 3-2-1-1-0 rule protects data.

Read more
Storware Backup and Recovery 7.5 Release News

Storware Backup and Recovery 7.5 Release

Enterprise-Grade Data Protection Across Environments — and a New Path to Platform9 integration, V2V migration from Citrix Hypervisor and XCP-ng, Nutanix v4 API, Proxmox Ceph v19 support, and a round of deep OpenStack and OS Agent improvements — version 7.5 ships with a lot to unpack.

Read more

Ready to protect your data?