The 3-2-1 backup strategy involves keeping at least three copies of your data, on two different storage media, with one off-site copy. However, in the face of ransomware, this approach is no longer sufficient unless the backups are tested, encrypted, and protected against deletion. For an SMB, the real challenge isn’t just backing up data—it’s being able to restore it quickly, cleanly, and without paying a ransom.
What is the 3-2-1 backup rule?
The 3-2-1 backup rule is a simple method that has been promoted for years by data protection providers such as Veeam. It requires three copies of the data: the production data, a first local backup, and then an off-site copy. All of this should be stored on two different types of media, such as a NAS (network-attached storage) server and cloud storage.
The benefit is very practical. If a disk fails, you have a copy. If your premises are inaccessible, you have a copy on the hors site. If ransomware encrypts your main server, you have a restore point that isn’t supposed to be affected.
The problem is the word “supposed to.” Attackers target backups starting from or but before encryption is triggered. A backup that’s constantly connected using the same credentials as the rest of the system can be deleted in a matter of minutes. This is the most common pitfall: having backups, but no recoverable backups.
Recent recommendations therefore go a step further. In 2023, CISA’s #StopRansomware guide recommends offline backups that are encrypted, regularly tested, and, if possible, immutable. Veeam now refers to the 3-2-1-1-0 model: three copies, two backups, one off-site copy, one online or immutable copy, and zero restore failures after verification.
What Really Changes in the Event of a Ransomware Attack
A ransomware attack isn't just a technical incident. It's a business disruption. The more scattered, poorly documented, or dependent on a single provider your data is, the longer it takes to recover. To gauge the financial stakes, consider the parallel with the The Actual Cost of a Ransomware Attack for an SME is often more telling than a technical explanation.
The 3-2-1 backup strategy reduces three risks. First, the permanent loss of files. Second, dependence on ransom. Finally, it minimizes the risk of making hasty decisions under stress. A company that knows where its backups are, can access them, and understands its ord recovery plan makes better decisions when everything comes to a halt.
Be careful, though, about the goal. Restoring “something” is not the same as restoring the business. Your showcase site It can wait a few hours; your ERP, email system, or customer database, however, cannot. The right strategy organizes data by business priority, not by technical location.
In the projects we manage, we often see the same mistake: backing up everything at the same rate, without distinguishing between critical data and cold files. As a result, the budget skyrockets, but the recovery plan remains vague. Given this budget, it’s better to start with a more limited backup scope but thoroughly test the data that drives your revenue.
Supports, cloud, immutability: Which options should you choose?
A different support doesn't just mean another shared folder. The idea is to minimize common failure scenarios. A NAS on your premises protects against accidental deletion, but not against a fire. Cloud storage protects against local damage, but requires strict configuration of access rights and retention policies.
Immutability deserves an explanation. An immutable backup is a copy that cannot be modified or deleted for a defined period of time. Services such as Backblaze B2 Object Lock or Azure Blob Storage Immutable offer this mechanism. Microsoft also notes, regarding Azure Backup, that the locked immutability of a Recovery Services vault cannot be shortened during the retention period. This is reassuring, but it means you must choose your retention periods carefully from the start.
The hors line remains very useful. A disk that is disconnected, or a tape sortie from the network chain, is inaccessible to active malware. Veeam points out that tape is inherently resistant to ransomware as long as it is disconnected, with costs sometimes cited at around $5 to $8 per TB depending on the configuration. Honestly, this approach is particularly justified when volumes are large or when retention requirements are strict.
| Option | Relevant use case | Indicative cost | Point of vigilance |
|---|---|---|---|
| Local NAS | Quick file recovery or servers | A few hundred to a few thousand euros, depending on capacity | Must be isolated from regular administrator accounts |
| Backblaze B2-style object storage | Copy the hors site using Object Lock | 6.95 $/To/month at the 2026 retail price | Test the costs and recovery times of sortie |
| Azure Backup | Microsoft Infrastructure, VMs, Servers, Hybrid Cloud | Varies depending on storage, retention, and replication | Properly Configure Immutability, Soft Delete, Alerts, and Regions |
| Veeam Community Edition | Small parks, up to 10 workloads | Free license announced for 10 workloads | Estimated Administration and Storage Times |
| Band or support hors line | Long-term archiving, offline copy | Low orders of magnitude in the To range, equipment to be upgraded | A rigorous, humane procedure is essential |
How can you test your backups without disrupting operations?
Testing a backup isn’t just about verifying that a file exists. It involves restoring data to a separate environment, opening the files, checking their dates, and then verifying that the applications restart. In 2020 and in its recent publications, NIST reiterates that backups must be performed, maintained, and tested. CISA also emphasizes availability and integrity in recovery scenarios.
A simple test can be completed in half a day for a small organization: restoring a critical folder, a database, and a user account. For a more complex business system, plan on one to two days, especially if multiple service providers are involved. The cost is not insignificant, but it often reveals hidden issues: lost passwords, expired licenses, reliance on an unsaved server, or missing documentation.
The right frequency depends on your risk level. A daily backup that hasn’t been tested in two years doesn’t inspire confidence. For an SME, a quarterly test of critical data and a more comprehensive annual test already provide a solid foundation. After a migration, a change in hosting provider, or an application overhaul, you’ll need to retest.
From the agency’s perspective, the first instinct is to ask about recovery before discussing tools. If no one can say how long it will take for the website, the customer database, or the billing files to come back online, the backup project isn’t complete.
Common Mistakes That Cause a 3-2-1 Backup to Fail
The first mistake is to confuse synchronization with backup. OneDrive, Google Drive, or a synchronized network share are convenient, but if an encrypted or deleted file is replicated everywhere, the problem travels with it. A backup must retain usable versions over time.
Another pitfall: using the same administrator account everywhere. If an attacker gains access to that account, they can compromise servers, backups, and sometimes cloud consoles. In its Azure Backup best practices, Microsoft recommends safeguards such as multi-user authentication, soft delete (recoverable deletion), encryption, security alerts, storage replication, and monitoring.
- Do not make the backup console accessible from all workstations.
- Enable multi-factor authentication for administrator accounts.
- Separate the permissions for production and backup.
- Set a retention period that aligns with payroll, billing, and accounting close cycles.
- Document the ordre restoration process: directory, files, applications, databases, and website.
Backup security must also cover exposed applications. A website, an API, or a mobile application If they are not properly protected, they can become the point of entry for the incident. The controls described in a Mobile App Security Checklist Before Release or in the analysis of API security vulnerabilities complement the recovery strategy, since backups do not prevent intrusions.
What kind of budget should a French SME plan for?
Prices vary significantly depending on volume, the number of servers, data retention, and the level of managed services. For a small business with a few hundred gigabytes of critical data, a robust initial architecture can start at anywhere from a few dozen to a few hundred euros per month, including setup. For several terabytes, VMs, databases, and regular testing, the monthly budget can reach several hundred euros, and sometimes even more.
The initial setup is often underestimated. Taking inventory, setting priorities, configuring permissions, encryption, immutability, documentation, and initial testing all take time. Depending on the service provider, you should often expect a few days of work for a reasonable SME-sized project. It’s not the storage that costs the most up front; it’s the design of a system that can actually be used during a crisis.
It is also important to distinguish between backups and archiving. Archiving preserves data for legal, accounting, or historical reasons; backups are used to restore operations. The two can coexist, but with different rules. For files that need to be retained for a long time, a system forsecure professional archiving avoids unnecessarily increasing the size of daily backups.
A case where the obvious solution is the wrong one: putting everything in the cloud with very long retention periods and no local recovery procedures. On paper, this sounds reassuring. But in the event of an incident, downloading several terabytes could take too long for your business. A fast local copy and an immutable cloud copy complement each other better than they replace one another.
A Simple Plan for Switching to a Reliable 3-2-1 Backup
Start with an inventory. Which data would result in financial losses from day one? Where is it located? Who manages it? This step may seem like a mere administrative task, but it prevents you from backing up unnecessary data while overlooking a production database.
Next, set two objectives: the RPO, which is the acceptable amount of data loss over time, and the RTO, which is the acceptable time to resume operations. An accounting firm may be able to tolerate 24 hours of data loss in certain cases; an online store, however, has much less leeway. These figures determine the frequency of backups and the budget.
The practical approach for an SMB often looks like this: daily local backups for quick restoration, an hors cloud copy of the site with immutability, separate accounts, encryption, monitoring, and scheduled restore tests. Add an online hors copy for your most sensitive data if the risk of ransomware is high or if your business cannot tolerate downtime.
Defining the scope of this type of project early on helps avoid most unpleasant surprises: overlooked volumes, poorly estimated storage costs, and unrealistic recovery timelines. Above all, an outside perspective helps distinguish between what truly protects the business and what merely looks good on paper.
FAQ on the 3-2-1 Backup Method
Does the 3-2-1 backup strategy always protect against ransomware?
It provides full protection if at least one copy is on-site, isolated, or immutable, and if the restores are tested. A backup connected with the same permissions as the production environment can be deleted by an attacker.
What is the difference between an immutable backup and an hors online backup?
An immutable backup remains connected but cannot be modified or deleted for a specified period of time. An hors offline backup is disconnected from the network and therefore inaccessible remotely as long as it remains isolated.
How often should you test your backups?
For an SME, testing critical data on a quarterly basis is a reasonable standard. A comprehensive annual test is recommended, as well as after any migration, overhaul, or change in hosting.
How long does it take to recover from a cyberattack?
This can range from a few hours to several days, depending on the volume of data, application dependencies, and the quality of the documentation. The only reliable figure comes from an actual restore test.