Key takeaways
- 3 copies of your data, on 2 different types of storage, with 1 copy off-site.
- Ransomware added a new requirement: at least one copy must be offline or immutable.
- A backup you have never restored is a hope, not a plan.
- Decide how much data you can afford to lose (RPO) and how long you can be down (RTO) — then design to those numbers.
What the 3-2-1 rule means
The 3-2-1 rule is the simplest framework for not losing data:
- 3 copies — the live data plus two backups. One failure should never leave you with nothing.
- 2 different media — for example a local backup appliance and cloud storage. A single fault, bug or bad batch of disks shouldn't take out both.
- 1 off-site — so that fire, flood, theft or a building-wide power event doesn't destroy every copy at once.
Ransomware changed the rule
Ransomware operators know backups are the reason victims refuse to pay, so they hunt for them first. A backup drive permanently plugged into the server, or a NAS reachable with the same admin password, will be encrypted along with everything else.
That is why the modern version is often written 3-2-1-1-0:
- the extra 1 — one copy that is offline, air-gapped or immutable (it cannot be changed or deleted, even by an administrator, until its retention period ends);
- the 0 — zero errors when you verify and test-restore your backups.
Backup vs. disaster recovery
A backup is a copy of data. Disaster recovery (DR) is the ability to get the business running again. You can have perfect backups and still be down for a week if restoring them means rebuilding servers from scratch.
| Term | Question it answers | Example target |
|---|---|---|
| RPO — Recovery Point Objective | How much recent data can we afford to lose? | Accounting: 1 hour. Archive: 1 day. |
| RTO — Recovery Time Objective | How long can we be down? | POS & ERP: 4 hours. Intranet: 2 days. |
Tight targets usually call for image-based backups of whole servers (not just files), frequent snapshots, and the ability to boot a server directly from the backup system or the cloud while the original is repaired.
What to back up
- Servers and databases — ERP, accounting, POS, file servers — ideally as full images.
- Microsoft 365 / Google Workspace. Cloud providers keep the service running, but deleted or encrypted mailboxes and files are your responsibility. Dedicated cloud-to-cloud backup closes that gap.
- Configurations — firewall, switches, Wi-Fi controllers. Rebuilding a network from memory takes days.
- Key laptops where important work lives outside the server.
How to know your backups will work
- Automated checks. Every job should report success or failure to someone who reads it.
- Regular test restores. Restore individual files monthly and a complete server at least quarterly — into an isolated environment.
- Time it. Measure how long a full restore takes and compare it with your RTO.
- Protect the backup system itself. Separate credentials, MFA, and no access from normal user accounts.
- Write it down. A one-page runbook: who does what, in what order, with which passwords stored where.
The bottom line
Backups are the last line of defence when everything else fails — the firewall, the antivirus, the training. They deserve to be designed, monitored and tested like any other critical system. If you aren't certain how quickly you could recover your main server today, a free IT assessment is a good place to find out.



