The 3-2-1 Backup Rule: The Only

Storage drives used for data backups

Ask any IT professional how to back up properly and you’ll hear the same three numbers: 3-2-1. The rule is decades old and still the standard, because it’s built around a simple insight — every backup failure story involves all the copies sharing a common weakness. The rule removes the common weaknesses.

The rule

3 copies of your data. The original plus at least two backups. One backup isn’t a backup strategy; it’s a single point of failure with extra steps.

2 different types of storage. Don’t keep every copy on the same kind of system. A server plus an external drive, or a NAS plus cloud storage. Different media fail in different ways, which is exactly the point.

1 copy offsite. Fire, flood, theft, lightning, or ransomware sweeping through your network — anything that can destroy your office can destroy every backup in your office. One copy must live somewhere else, and cloud backup has made this easier than it’s ever been.

The modern addition: make one copy untouchable

Ransomware changed the game. Attackers now deliberately locate and encrypt or delete backups before triggering the attack — a backup drive permanently plugged into the server, or a cloud sync folder, will be encrypted right alongside the originals. (Worth repeating: file sync services like OneDrive or Dropbox are not backups — they faithfully sync your encrypted files over the good ones.)

The answer is at least one copy that’s offline or immutable: storage that can’t be modified or deleted for a set period, no matter whose credentials the attacker holds. Many modern backup platforms support immutability natively — it’s the difference between an incident and a catastrophe.

What most businesses get wrong

  • Backing up only some things. The file server is covered, but the accounting database, mailboxes, and the cloud apps (Microsoft 365 and Google Workspace are your responsibility to back up, not Microsoft’s or Google’s) are forgotten.
  • Never testing restores. A backup you’ve never restored from is unverified. Schedule test restores — quarterly at minimum — and confirm the data actually opens.
  • Nobody watching the jobs. Backups fail silently. Someone (or some system) must check job status daily, because discovering six months of failed backups on the day you need them is the classic disaster.
  • No thought given to restore time. Knowing your data is safe is half the job. How long to get the business running again — hours or days? That’s your Recovery Time Objective, and it should be a decision, not a surprise.

Putting it into practice

A typical SME setup: local backup to a NAS or backup appliance for fast restores, replicated nightly to encrypted cloud storage with immutability enabled, with daily monitoring and quarterly restore tests. That’s 3-2-1 with a ransomware-proof copy — and it’s affordable enough that there’s no excuse not to have it.

We design, run and monitor backup systems for businesses — including Microsoft 365 backup and immutable offsite copies. If you can’t say with certainty when your last successful restore test was, let’s talk.