← All articles Backup & Security

The 3-2-1 backup rule: a simple way to protect your business data

Most small businesses think they have backups — until the day they need one. The server dies, ransomware locks every file, or someone deletes the wrong folder, and it turns out the "backup" was an old USB drive nobody had checked in months. The 3-2-1 rule is a simple way to make sure that never happens to you.

The rule in one line

Keep 3 copies of your important data, on 2 different types of storage, with 1 copy off-site.

What it looks like for a small business

A typical setup for an office with a server running ERP, Tally or shared files:

  1. Live data on your server.
  2. Nightly backup to a NAS (a network storage box) in the office — quick to restore from.
  3. Encrypted backup to the cloud — your off-site copy.

Don't forget laptops and your Microsoft 365 or Google Workspace data. These services keep your data online, but their recycle bins only keep deleted items for a limited time — a separate backup covers you for mistakes you notice too late.

Five things that make backups actually work

  1. Automate it. Backups that depend on someone remembering will eventually be missed.
  2. Test restores regularly. A backup only counts if you have successfully restored from it.
  3. Keep versions. If ransomware encrypts your files, you need a clean copy from before the attack — not just last night's.
  4. Protect the backups themselves. Ransomware often targets backups too, so the backup system should not share the same admin password as everything else.
  5. Get alerts. You should know the same day if a backup fails — not weeks later.

A quick self-check

If any answer is "not sure", it's worth fixing now — before you need it. Backups are your last line of defence; for the rest, see our ransomware protection checklist.

Get your backups checked — free

Our free IT health check includes a backup review and a written report of what to fix.

More articles

WhatsApp