Almost every business we meet says it has backups. Far fewer can tell us when anyone last restored from one, and that is usually where data gets lost: the backup exists, but nobody has checked that it can be recovered.
The 3-2-1 rule has been the standard answer for decades because it’s easy to remember and still protects you when one part of it fails.
The rule
- 3 copies of your data — the live version plus two backups
- 2 different types of storage — so one failure can’t take out both
- 1 copy kept off-site — protection from fire, theft or ransomware
Why each part matters
Multiple copies protect against a single device dying. Different media protect against a whole class of failure. An off-site copy is what saves you when ransomware or a physical disaster hits the office.
Each number protects against a different kind of problem, which helps when you’re deciding whether you can bend the rule:
Three copies covers the ordinary case: a drive fails, a file is overwritten, someone empties a folder. Two copies sounds sufficient until you realise the second one is often mid-write when the first fails.
Two types of storage covers correlated failure. Two external drives bought together, from the same batch, plugged into the same power board, are not really two copies. Neither are two folders on the same NAS.
One copy off-site covers everything that takes out the building — fire, flood, theft — and, increasingly, ransomware. Modern ransomware deliberately looks for and encrypts connected backups first, because the operators know an intact backup is the reason you won’t pay. A copy that is off-site and not permanently connected is out of its reach.
Where Microsoft 365 fits
This is the most common misunderstanding we run into. Microsoft 365 is not a backup. Microsoft replicates your data so their service stays available; that protects against their hardware failing, not against you.
If someone deletes a mailbox and the retention window passes, if a departing employee wipes a SharePoint library, or if ransomware encrypts files that then sync to OneDrive, Microsoft’s copies simply copy the damage. The retention and recycle-bin periods help, but they’re measured in days to a few months, and they run out. If your business data lives in Microsoft 365, it needs its own backup with its own retention.
The step everyone skips
Until you’ve restored from a backup, you don’t know it works. Test restores on a schedule. A backup that can’t be recovered can be worse than none, because everyone assumes they’re covered.
A test doesn’t have to be elaborate. Pick a real file from a month ago and a real mailbox, restore both, and confirm they open. Do it quarterly, and write down the date. That habit catches most of the problems nobody notices: the job that has been failing since a password change, the folder nobody added to the selection, the retention setting that was shorter than anyone thought.
Two numbers worth agreeing on
Before you choose any backup product, agree on two things: they determine what you actually need to buy.
How much data can you afford to lose? If backups run nightly, a failure at 4pm loses a day’s work. If that’s unacceptable for your accounting system, it needs to run more often than nightly.
How long can you afford to be down? Restoring a few files takes minutes. Rebuilding a server from an off-site copy over a business internet connection can take a day or more. If you can’t be down that long, keep a local copy you can restore from quickly, with the off-site copy as the fallback.
Most businesses have never been asked these two questions, and the answers often change what they need to buy.
Making it automatic
- Automate backups so they don’t depend on anyone remembering
- Monitor them daily and get alerted the moment one fails
- Document how long a full recovery actually takes
Monitoring matters more than people expect. When a backup system sends a success email every morning, everyone learns to ignore backup emails. Alerts should go out when a backup fails, to someone whose job is to act on them.
To recap: keep three copies, on two types of storage, one of them off-site, and someone responsible for noticing when a backup stops working.