Operate//guide // IT management
Business backup: the 3-2-1 rule and restore testing
What a backup that survives a failed disk, an accidental deletion and ransomware looks like, and how to check that it actually works.
Updated: 02.10.2026 · ~6 min read
Almost every company has a backup configured. Fewer know how long it would take to get working again if the server failed today, and how much data they would lose. The answer depends on three things: where the copies are, who can delete them and when they were last restored.
The 3-2-1 rule
- 3 copies of the data: the original and two more copies;
- 2 different types of storage, for example a NAS and a cloud service;
- 1 copy off site, so a fire or flood cannot destroy them all.
The extended version, 3-2-1-1-0, adds one offline or immutable copy, which cannot be changed or deleted during its retention period, and zero errors when restores are verified. After a ransomware attack, the immutable copy is usually the one left intact.
What is not a backup
- RAID protects against a disk failure, but replicates deletions and encrypted files instantly;
- sync services (OneDrive, Google Drive, Dropbox) copy mistakes too: a file deleted or encrypted locally is deleted or encrypted in the cloud as well;
- the Microsoft 365 recycle bin keeps deleted items only for a limited time and does not cover every loss scenario;
- an external hard drive permanently connected to the server is attacked together with the server.
Backup and ransomware
Modern ransomware looks for backups before it encrypts the data. A NAS on the same network, reachable with the same administrator account as the server, usually falls with it. The measures that matter:
- separate accounts for the backup system, with multi-factor authentication;
- an immutable copy or one disconnected from the network;
- alerts when a backup job fails or when the volume of changed data suddenly jumps;
- access to the backup console only for the people who really need it.
How often and how fast: RPO and RTO
Two figures should be agreed with management for each important system:
| Metric | The question it answers |
|---|---|
| RPO (Recovery Point Objective) | How many hours of data can you afford to lose? If the answer is “one hour”, a daily backup is not enough. |
| RTO (Recovery Time Objective) | How soon must you be working again? Restoring 2 TB from the cloud over an ordinary connection can take days. |
The ERP and the invoicing database usually have stricter requirements than the document archive. Not every system has to be treated the same way.
The restore test
Without a restore test you do not know whether the backup works. Testing means actually restoring, periodically and in a separate environment, a whole server, a database or a mailbox. Restoring a single file picked at random tells you very little. The test is documented: what was restored, how long it took, what problems came up. The document also checks the RTO and, for companies covered by NIS2, serves as evidence of business continuity measures.
Checklist
- you know exactly which systems are included in the backup, including Microsoft 365 or Google Workspace;
- you have at least one copy off site and one that is immutable or offline;
- someone reads the failure alerts and resolves them;
- the last test restore took place within the past three months;
- there is a written plan for what gets restored first and who decides.
We set up and run backups as part of IT management. For companies covered by NIS2, business continuity and backup are among the minimum measures required by law; details on the NIS2 page.
When did you last test a restore?
We check what your backup covers, where the copies are and how long a real restore takes.