HomeServicesIndustriesAboutBlogContact Book a free IT assessment
+961 81 073 228
syc@syc-company.com
Home/Blog/Cloud & Backup

The 3-2-1 Backup Rule (and Why “We Have a Backup” Usually Isn't Enough)

Almost every business says it has backups. Far fewer have backups that would survive a ransomware attack, a fire or a failed disk — and fewer still have ever tested a full restore.

Cloud & Backup6 min readOctober 3, 2026By SYC Engineering Team
The 3-2-1 Backup Rule (and Why “We Have a Backup” Usually Isn't Enough)

Key takeaways

  • 3 copies of your data, on 2 different types of storage, with 1 copy off-site.
  • Ransomware added a new requirement: at least one copy must be offline or immutable.
  • A backup you have never restored is a hope, not a plan.
  • Decide how much data you can afford to lose (RPO) and how long you can be down (RTO) — then design to those numbers.

What the 3-2-1 rule means

The 3-2-1 rule is the simplest framework for not losing data:

  • 3 copies — the live data plus two backups. One failure should never leave you with nothing.
  • 2 different media — for example a local backup appliance and cloud storage. A single fault, bug or bad batch of disks shouldn't take out both.
  • 1 off-site — so that fire, flood, theft or a building-wide power event doesn't destroy every copy at once.

Ransomware changed the rule

Ransomware operators know backups are the reason victims refuse to pay, so they hunt for them first. A backup drive permanently plugged into the server, or a NAS reachable with the same admin password, will be encrypted along with everything else.

That is why the modern version is often written 3-2-1-1-0:

  • the extra 1 — one copy that is offline, air-gapped or immutable (it cannot be changed or deleted, even by an administrator, until its retention period ends);
  • the 0 — zero errors when you verify and test-restore your backups.
Sync is not backupServices that mirror your files — like a shared folder that syncs between computers — copy deletions and encryption too. If a file is destroyed in one place, it is destroyed everywhere within seconds.

Backup vs. disaster recovery

A backup is a copy of data. Disaster recovery (DR) is the ability to get the business running again. You can have perfect backups and still be down for a week if restoring them means rebuilding servers from scratch.

TermQuestion it answersExample target
RPO — Recovery Point ObjectiveHow much recent data can we afford to lose?Accounting: 1 hour. Archive: 1 day.
RTO — Recovery Time ObjectiveHow long can we be down?POS & ERP: 4 hours. Intranet: 2 days.

Tight targets usually call for image-based backups of whole servers (not just files), frequent snapshots, and the ability to boot a server directly from the backup system or the cloud while the original is repaired.

What to back up

  • Servers and databases — ERP, accounting, POS, file servers — ideally as full images.
  • Microsoft 365 / Google Workspace. Cloud providers keep the service running, but deleted or encrypted mailboxes and files are your responsibility. Dedicated cloud-to-cloud backup closes that gap.
  • Configurations — firewall, switches, Wi-Fi controllers. Rebuilding a network from memory takes days.
  • Key laptops where important work lives outside the server.

How to know your backups will work

  1. Automated checks. Every job should report success or failure to someone who reads it.
  2. Regular test restores. Restore individual files monthly and a complete server at least quarterly — into an isolated environment.
  3. Time it. Measure how long a full restore takes and compare it with your RTO.
  4. Protect the backup system itself. Separate credentials, MFA, and no access from normal user accounts.
  5. Write it down. A one-page runbook: who does what, in what order, with which passwords stored where.
A simple setup that meets the ruleNightly image backups of servers to a local backup appliance (fast restores), replicated automatically to immutable cloud storage (off-site, ransomware-resistant), plus cloud backup for Microsoft 365 — with a monthly test restore.

The bottom line

Backups are the last line of defence when everything else fails — the firewall, the antivirus, the training. They deserve to be designed, monitored and tested like any other critical system. If you aren't certain how quickly you could recover your main server today, a free IT assessment is a good place to find out.

SYC Engineering TeamNetwork, security and systems engineers in Beirut, helping businesses in Lebanon and Africa run reliable, secure IT since 2015.
Need a second opinion?

Let's look at your network.

A free IT assessment shows exactly where you stand — firewall, Wi-Fi, backups and security — with clear next steps.