To second this, there are some threat models that are often overlooked with backups. Separating the encryption and restore keys makes sense, and is a design pattern few of the modern new backup tools offer - bupstash and duplicacy are the two that spring to mind which support asymmetrically encrypted backups.
The recent lastpass issue shows the importance of keeping the backup decryption keys offline and inaccessible. A headless server with backup script can upload backups, but if someone can access the script and backups, they have the golden goose (users' vaults).
Most other backup tools don't give you the ability to separate out creating and retrieving backups.
Separate moan - very few of the backup tools that use s3 style buckets give a proper description of the IAM security model you should use - I like to understand what object prefixes are used, and what the absolute minimum I require is, as I like to start from minimum privilege - PutObject, GetObject on an index or config file, and nothing else if I can avoid it!
Hopefully we see more focus on backup security after lastpass.