Backups that actually work: the 3-2-1 rule for SMBs
A backup you cannot restore is not a backup. Here is how to set up a reliable backup strategy with the 3-2-1 rule that saves you after an incident.
By Limburg Cyber Group
Almost everyone “has some kind of backup”. But the question that matters is: after an outage, theft, or ransomware attack, can you actually restore your data? Surprisingly often the answer is no, the backup was incomplete, outdated, or stored in the same place that was also hit. A reliable approach starts with the 3-2-1 rule.
What the 3-2-1 rule means
A simple, proven rule of thumb:
- 3 copies of your important data (the original plus two backups);
- 2 different types of storage (for example a local drive and the cloud);
- 1 copy in another location or offline.
That one offline or immutable copy is what saves you from ransomware: if the attacker cannot reach it, you can always restore.
Just as important: testing
A backup that has never been restored is an assumption, not a certainty. Schedule a periodic restore test: actually restore a file or system and check that it works. This exposes problems before you discover them in a crisis.
What to watch for
- What do you back up? Not just files, but also email, cloud applications, and settings. Note: cloud services are not automatically a backup.
- How often? Match the frequency to how much work you are willing to lose at most (a day? an hour?).
- How long do you keep it? Multiple versions, so you can also go back to before an infection you only notice later.
- Is it encrypted? Backups with personal data in particular should be secured.
Part of a bigger picture
Backups are your last safety net, and thereby your strongest weapon against ransomware. They belong in a broader foundation together with MFA and an update policy, and in your IT policy so the agreements are recorded.
Help setting it up?
We help you set up a backup strategy that fits your business, including the restore tests that give certainty. See our cybersecurity service or book a conversation.
Read more
Passkeys for your business: logging in without a password, and hard to phish
Passkeys replace the password with a key on your device that will not work on a fake site. What they are, what to watch for and how to start sensibly.
Securing your company website: the maintenance nobody gets round to
Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.
QR code phishing: how quishing works and how your team can spot it
Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.