Backing up business data: the 3-2-1 rule that protects you

Updated 15 July 2026 · Let IT Bee

We back up to the disk next to the server" is a phrase we hear often - and it usually means the company has a backup only in quotation marks. Real data protection rests on a simple, long-proven principle known as the 3-2-1 rule. In this article, we explain what this means in practice, where backups should actually be stored, how long they should be retained, and why recovery testing is just as important as the backup itself.

What is the 3-2-1 rule

The rule can be summed up in three numbers:

The rule is simple: no single event - fire, theft, disk failure or malicious software attack - should destroy all copies at once.

Cloud or NAS? Ideally both.

Local storage (NAS) in the office offers fast recovery - data is on hand and transfer over the local network takes minutes. However, it has a weakness: it is physically located in the same building as the source data, so a fire, theft or an attack spreading across the network could affect both simultaneously.

Cloud backup addresses this weakness - data are stored automatically offsite, typically beyond the reach of an attacker who has breached the company network. The disadvantage is a longer recovery time with standard internet connection speeds, especially for larger data volumes.

In practice, the best approach is a combination of both: local copies for quick recovery from routine errors and cloud-based (or otherwise physically separate) copies in case the entire company is affected. This naturally fulfills the 3-2-1 rule.

How many versions to retain

In addition to the number of copies, it is also important how many older backup versions the company retains. A single current backup is insufficient - if data corruption becomes apparent only after some time (typically with slowly progressing malware), you need to revert to a version older than when the problem occurred. It is therefore worthwhile to retain multiple points in time - typically several daily, several weekly and at least one monthly version back, depending on how sensitive the data are and how quickly they change within the company.

How often to test recovery

The existence of a backup does not guarantee that a fully functional system can be restored from it. Backups may be corrupted or incomplete, or restoration may be blocked by missing licenses or passwords that no one remembers. Therefore, it is worthwhile to regularly test the restoration process - not just to verify that it ran and the "log is green".

An appropriate frequency is usually a quarterly test on a selected sample of data or systems, more frequently for critical servers. The test should include restoring a file or the entire system to operational status in real conditions, not merely verifying that a backup file exists. The test result should be briefly recorded - date, what was tested and how long restoration took - so the company has an overview of how quickly it can resume operations after an outage.

What else to back up besides shared files

Companies usually associate backups with data on servers or NAS devices but overlook the content of cloud services such as Microsoft 365. Microsoft is responsible for infrastructure availability, not for backing up your mailbox content - if a user accidentally permanently deletes an email, document, or Teams team and the company has no independent backup, the data is lost irretrievably once the standard retention period expires. Therefore, a backup strategy must also include Exchange, OneDrive, SharePoint, and Teams, not just files on a local server.

Ransomware and Backups - Factual, Without Fearmongering

Malicious ransomware software encrypts not only the local disk but also network and mapped storage accessible to the infected computer - including standard NAS devices if permanently connected to the network. Therefore, it is crucial to maintain at least one copy of data that is isolated or immutable (offline, versioned, or beyond reach of standard login credentials), which attackers cannot compromise in the same way as production data.

Such an isolated copy is the final safety net - if everything else fails, it allows operations to be restored without paying a ransom and without relying on the attacker keeping their word. It is a standard part of any backup strategy, not an exceptional measure for companies at heightened risk - today it concerns practically every company that has data on its network.

Are you sure your backups work?

We will carry out a backup audit and recommend where a separate copy is missing.

Related articles