Hi There,
If your backup is encrypted, then whoever stole a copy of it would have to know the password in order to use it. There is no way around it.
For your second question: as long as you don't add any new key pairs to your wallet (generate new addresses), then you only need one back-up. It doesn't matter how old it is. However, you will have to create a new back-up if you generate any new addresses in your client.