Windows backups are subpoenable by half the governments on the planet, who have bad actors in them, and may also have exploits for dedicated attackers because they present a huge target.
I hate this. People are claiming "state-level" actors are all the same. Microsoft backups are subpoenable by local cops, hell, by your ex-wife in a divorce proceeding in some jurisdictions.
Yes, if the NSA has a decent reason to think you're going to nuke a sports game you'll still have a problem with very, very good security measures.
That doesn't mean there isn't a very large in-between zone where you're fine with better security measures.