just would like to add they should encrypt the remote backup server password in the database. If there is an injection, then it will be more difficult to delete all the backups, or download them.
They had injection issue recently. We do not use the backup feature. we prefer r1soft on our side for this.