Security

Backups for Small Business: The 3-2-1 Rule, and Why It Grew Two Extra Digits

Everyone knows they should have backups. Far fewer could answer the only question that matters during a real incident: can we actually restore, right now, from a copy the attacker couldn't reach? Here's the rule that gets you there — and why it's quietly evolved.

A ransomware attack hits on a Wednesday afternoon. Files are encrypted, systems are locked, and the only question that decides how bad your week is going to be is this: do you have a clean backup you can restore from? For an uncomfortable number of businesses, the honest answer is "I think so" — which, on the day, is the same as no.

Backups are the single control that most reliably turns a catastrophe into an inconvenience. But "having backups" and "being able to recover" are two very different things, and the gap between them is where businesses get caught. This is the practical version.

The 3-2-1 rule: still the right foundation

The classic rule, and still the right starting point, is 3-2-1:

  • 3 copies of your data — the live version plus two backups.
  • 2 different types of media — not two backups sitting on the same drive or in the same system, which share a single point of failure.
  • 1 copy off-site — so a fire, flood, theft, or a single compromised location doesn't take out everything at once.

It's deliberately simple, and it's simple on purpose: it's the bridge between merely owning a backup tool and actually having a strategy that survives an incident. If you don't have even this, that's the first thing to fix — today.

The catch that catches everyone: a "backup" that's really just a synced folder isn't a backup. If deleting or encrypting a file on your computer also deletes or encrypts it in the synced copy, that's replication, not backup — the damage propagates straight through. This is one of the most common false-confidence traps in small business.

Why the rule grew: ransomware changed the target

The original 3-2-1 rule was designed for a world of hardware failure, accidental deletion, and natural disaster — threats that don't think. It quietly assumes your backups are safe simply because they exist somewhere else.

Ransomware breaks that assumption. Modern ransomware crews don't just encrypt your production systems — they specifically hunt across the network for backup servers, snapshots, and cloud storage, and try to delete or encrypt those first, before they set off the visible attack. The goal is to leave you with nowhere to turn but the ransom. A backup that's online and reachable with the right credentials is exactly what they're looking for.

That's why the rule has evolved. You'll now see it written as 3-2-1-1-0. The two new digits are the ones that specifically defend against a thinking adversary:

DigitMeansProtects against
3Three copies of the dataAny single copy being lost
2Two different media typesA whole class of storage failing
1One copy off-siteFire, flood, theft, site loss
1One copy immutable or air-gappedRansomware deleting your backups
0Zero errors — verified recoveryDiscovering your backup was broken all along

The extra "1": immutable or air-gapped

This is the ransomware-killer. An immutable backup uses a storage policy that prevents any copy being altered or deleted for a set retention period — even by someone holding admin credentials. An air-gapped backup goes further, keeping a copy physically or logically disconnected from the network entirely, so it can't be reached at all. Either one gives you a copy an attacker who owns your network still can't touch. This is the difference between a bad week and a business-ending event.

The "0": zero errors, verified recovery

This one is less a technology than a discipline. A backup job reporting "success" only means data was written — not that it can be read back into a working system. The "0" means you actually test restoration, regularly, and confirm it completes without errors. An untested backup is a hope, not a plan, and "our last successful restore test was over a year ago — or never" is one of the most common gaps found in real environments.

What this looks like for an actual small business

You don't need an enterprise budget to hit this. A realistic small-business shape:

  • Copy 1 — live data on your working systems.
  • Copy 2 — a local backup on separate storage (a NAS, a dedicated backup drive) for fast everyday restores.
  • Copy 3 — an off-site/cloud backup, ideally with an immutability option enabled so a set of recovery points can't be altered or deleted for their retention window. Many cloud backup services offer this as a setting — use it.
  • Verify recovery on a schedule — actually restore a sample of files (and periodically a whole system) and confirm it works, rather than trusting the green "success" tick.
  • Protect the backup admin separately — the account that manages backups should have its own strong, phishing-resistant login, because that account is exactly what an attacker wants to reach the backups.

Two questions worth answering before you need to

Backup strategy is really driven by two numbers most businesses have never consciously set:

  • How much data can you afford to lose? If you back up nightly, a mid-afternoon incident loses most of a day's work. If that's unacceptable for some systems, they need more frequent backups. This is your recovery point — how far back "the last good copy" sits.
  • How long can you afford to be down? Restoring terabytes over a slow link can take days. Knowing this in advance tells you whether your current setup can actually meet the downtime your business can survive — before the day you find out it can't.

A five-minute audit you can do right now: list where your critical data actually lives, then check three things — is any "backup" really just a synced folder? Is even one copy immutable or genuinely offline? And when did you last actually restore from a backup to confirm it works? If any answer is uncomfortable, you've just found the most valuable thing to fix this month.

Frequently asked questions

What is the 3-2-1 backup rule?

Keep three copies of your data, on two different types of media, with at least one copy off-site. It's the long-standing baseline for protecting against hardware failure, accidental deletion, and disaster.

What does 3-2-1-1-0 add?

Two things aimed at ransomware: one immutable or air-gapped copy that can't be altered or deleted even with admin access, and "zero errors" — verified, regularly tested recovery rather than just a successful backup job.

Is a synced cloud folder a backup?

No. If deleting or encrypting a file locally also removes it from the synced copy, that's replication, not backup — the damage propagates through. A real backup keeps recovery points the live system can't reach back and destroy.

Why do ransomware attackers target backups?

Because backups are what let you refuse to pay. Modern ransomware searches the network for backup servers and snapshots and tries to delete or encrypt them before triggering the visible attack, leaving the victim with no clean copy to restore from.

Not sure whether your backups would actually survive a bad day? Get in touch for a straight assessment — no sales pitch.

Get in touch →