CRYPTOITDATACRYPTOITDATA

IT Infrastructure

Backup 3-2-1: how to protect your business from ransomware

The 3-2-1 rule (and the 3-2-1-0 variant) explained simply: how many data copies you need, where to keep them and how to make sure your backup actually works when ransomware hits.

7 min read

A ransomware attack does not ask for permission. It encrypts your files, locks your servers and leaves you with a single question on screen: pay, or lose everything? The only answer that does not make you a hostage is a backup that truly works. And the gold standard, recognised in the industry for decades, is the 3-2-1 rule.

What the 3-2-1 rule means

  • 3 copies of the data — the original plus two backups. Redundancy means a single failure does not leave you without data.
  • 2 different types of media — for example local disk plus cloud, or NAS plus tape. That way a problem specific to one media type does not affect both copies.
  • 1 copy in another location (off-site) — physically separate from your premises. If you have a fire, flood or theft, the external copy survives.

The logic is simple: no single event — hardware failure, attack, physical disaster — can destroy all copies at once, because they are diversified in number, type and location.

From 3-2-1 to 3-2-1-0

Modern ransomware forced an upgrade of the classic rule. The variant we implement is 3-2-1-0:

  • 0 errors on verification — each backup is automatically tested for integrity and for actual restore capability. A backup that has not been tested is not a backup, it is a hope.

In addition, we recommend at least one immutable or air-gapped copy: data that cannot be modified or deleted within a predefined time window, not even by an administrator with full rights. Precisely because modern attackers seek out and encrypt backups before hitting production.

The most common backup mistakes

  1. 1Backup on the same server / same network as production — ransomware encrypts it too.
  2. 2Backup that has never been restore-tested — you discover it is corrupt exactly when you need it.
  3. 3A single copy, in the cloud, without immutability — a compromised account deletes everything.
  4. 4Backups without monitoring — they fail silently for weeks and no one notices.
  5. 5No documented recovery plan — you have the data, but no one knows in what order to bring services back.

The two parameters you must define: RPO and RTO

Before choosing the technology, answer two business questions:

  • RPO (Recovery Point Objective): how much data can you afford to lose? If you back up once a day, in the worst case you lose a day of work. For some companies that is acceptable, for others it is a disaster.
  • RTO (Recovery Time Objective): how quickly must you be operational again? An hour? A day? The answer dictates the architecture and cost of the solution.

These two figures turn backup from an abstract technical expense into a clear business decision.

How we implement the backup strategy

In our IT infrastructure projects we design the 3-2-1-0 strategy with proven tools — Veeam, Acronis or cloud-native solutions — chosen according to your existing stack. We then configure daily verification, monthly reports and a tested recovery plan, not just an assumed one. Backup thus becomes a measurable guarantee, not a box ticked out of habit.

There is no such thing as "backup that is too expensive" — only the recovery cost you are willing to pay. It is always cheaper than a ransom.

Conclusion

The 3-2-1 rule is not textbook theory — it is the best insurance policy a company can have against ransomware and disasters. The key is to apply it fully — including the testing and immutability parts — and to tie it to real business objectives (RPO/RTO). The rest is just discipline.

Frequently asked questions

How often should I back up?+

It depends on the RPO — how much data you can afford to lose. For critical business data we recommend incremental backups several times a day; for slowly changing data, once a day may be enough. The key is that it is automated and monitored, not manual.

Is cloud backup (Google Drive, OneDrive) enough?+

Cloud sync is not backup: if ransomware encrypts a local file, the encrypted version syncs and overwrites the cloud. You need versioned and, ideally, immutable backup — not mere synchronisation.

What is an immutable backup?+

An immutable backup cannot be modified or deleted within a set time window, neither by an administrator nor by an attacker who has gained rights. It is the key defence against ransomware that specifically targets backups.

Why must the backup be tested?+

Because an unverified backup can be corrupt, incomplete or unrestorable — and you find out only at the critical moment. Periodic restore testing turns "I think I have a backup" into "I know for sure I can recover".

Have a concrete question?

30 minutes, free. We discuss exactly your situation.

Book a consultation