Backups that actually work: the 3-2-1 rule for SMBs
A backup you cannot restore is not a backup. Here is how to set up a reliable backup strategy with the 3-2-1 rule that saves you after an incident.
By Limburg Cyber Group
Almost everyone “has some kind of backup”. But the question that matters is: after an outage, theft, or ransomware attack, can you actually restore your data? Surprisingly often the answer is no, the backup was incomplete, outdated, or stored in the same place that was also hit. A reliable approach starts with the 3-2-1 rule.
What the 3-2-1 rule means
A simple, proven rule of thumb:
- 3 copies of your important data (the original plus two backups);
- 2 different types of storage (for example a local drive and the cloud);
- 1 copy in another location or offline.
That one offline or immutable copy is what saves you from ransomware: if the attacker cannot reach it, you can always restore.
Just as important: testing
A backup that has never been restored is an assumption, not a certainty. Schedule a periodic restore test: actually restore a file or system and check that it works. This exposes problems before you discover them in a crisis.
What to watch for
- What do you back up? Not just files, but also email, cloud applications, and settings. Note: cloud services are not automatically a backup.
- How often? Match the frequency to how much work you are willing to lose at most (a day? an hour?).
- How long do you keep it? Multiple versions, so you can also go back to before an infection you only notice later.
- Is it encrypted? Backups with personal data in particular should be secured.
Part of a bigger picture
Backups are your last safety net, and thereby your strongest weapon against ransomware. They belong in a broader foundation together with MFA and an update policy, and in your IT policy so the agreements are recorded.
Help setting it up?
We help you set up a backup strategy that fits your business, including the restore tests that give certainty. See our cybersecurity service or book a conversation.
Read more
Security awareness: from a one-off training to a safe culture
Your employees are your biggest risk and your best defence. Here is how to build genuine security awareness that sticks, beyond a mandatory course.
Updates and patch management: the dullest measure that stops the most attacks
Outdated software is the most common way in for attackers. Why patching promptly matters so much, and how to approach it simply and in a structured way.
Securing your office network and wifi: the basics that are often forgotten
Your network is the front door of your business. Practical steps to secure your wifi, router, and guest network, without becoming a network administrator.