Guide · Backup
The 3-2-1 rule: what a backup really needs to do
Three copies, two media, one off site – and why adding an immutable copy has become essential in the age of ransomware.
What the rule says – and why it is so old
The 3-2-1 rule comes from photography and is older than most of the businesses that apply it today. It goes like this: three copies of your data, on two different types of media, one of them off site. The reason it has held up for decades is that it doesn't depend on any particular technology – it covers risks.
Three copies means the original plus two backups. Not the original plus one backup — because if that backup fails during a restore, you are left empty-handed. Two media means not both on the same type of storage, because the same type has the same weaknesses. And a copy off site covers exactly what can't be solved within your own building: fire, water, burglary.
What the rule in its original form doesn't cover is the scenario that causes the most damage today: someone takes over your environment and encrypts your backup along with everything else. That is why a fourth point belongs with it.
The addition that matters since ransomware
One copy must be immutable
Anyone who gains administrator rights on your network looks for the backup first. A backup that can be deleted from the compromised system is no backup when it counts.
- Immutable storage. Once written, backups cannot be changed or deleted for a set period – not even with administrator rights. With cloud storage, the setting is usually called Object Lock or immutability.
- Separate credentials. The account used to run backups must not be the same as the Windows sign-in. A compromised administrator account must not automatically have access to the backup.
- One medium kept offline. A hard drive that is unplugged after the backup is technically inelegant and worth its weight in gold in an emergency. For small businesses, often the simplest way to meet the fourth requirement.
- Retention for weeks, not days. Encryption attacks often begin weeks before the damage becomes visible. If you only keep seven days, you may already be backing up the tampered data.
What backups regularly leave out
When we take over IT environments, we almost always see the same gaps. Not because anyone was careless, but because these things are out of sight.
- Microsoft 365. Microsoft protects its own infrastructure, not your data against your own mistakes. A deleted email is gone for good once the retention period has expired.
- The configuration, not just the files. Firewall rules, switch settings, phone system, permissions. Without them, rebuilding takes days instead of hours.
- Data on individual workstations. Whatever is saved on a computer's desktop is not included in any server backup.
- Databases in live operation. Copying a file while the database is writing to it produces a backup that can't be restored.
- Encryption keys. The recovery key for an encrypted hard drive that is stored only on that very drive is of no use to anyone.
- The documentation itself. When the restore instructions are stored on the server that needs restoring.
Backup and archive are two different things
A backup exists to restore a previous state — it is designed for speed and overwrites itself after a set period. An archive exists to keep something retrievable for years, because the law requires it or because it will be needed later.
Confusing the two is expensive either way: if you want to keep accounting records in your backup, you have to retain that backup for eight years (the statutory retention period in Germany) and pay for storage you will never need. Conversely, if you believe the backup meets your retention obligations, you discover after a year that the data has been overwritten.
In practice this means: backups with short to medium retention for day-to-day operations, and separate archiving for everything subject to statutory retention periods.
Frequently asked questions
What we are often asked about this
Is a backup to the cloud enough?
As the off-site copy: yes, that is exactly what it is for. As your only backup: no. After a major failure you have to pull everything back over your internet connection, and with several terabytes that takes days. A local copy restores quickly; the cloud copy covers the disaster scenario.
How often should you back up?
Turn the question around: how much work can you afford to lose? If you back up every night, in the worst case you lose one working day. For most businesses that is acceptable. For inventory management or accounting systems that are written to all day, shorter intervals make sense.
Work it out once: one day of lost data entry times the hourly rate times the number of people affected. That figure answers the question more precisely than any rule of thumb.
Does the backup need to be encrypted?
Yes, as soon as it leaves the building — so for every off-site copy and every removable drive that is taken away. An unencrypted backup contains all of your business's data in a single file.
What matters is where the key is kept: not on the same medium and not only in one person's head.
What about tapes – aren't they outdated?
Tapes have two properties that no other medium offers in the same way: once ejected, they are physically separated from the network, and they last for decades. For large volumes of data with long retention, they are still the cheapest solution.
For a business with twenty workstations they are usually overkill. There, hard drives used in rotation serve the same purpose.
We have a RAID – isn't that enough?
No, and this is one of the most consequential misunderstandings. A RAID protects against the failure of a single hard drive, and nothing else. It doesn't help against accidental deletion, encryption, fire or a faulty controller — a deleted file is deleted on all drives at the same time.
A RAID increases availability. A backup restores data. Those are two different jobs.
Dipl.-Ing. Mohamed Khater
Dipl.-Ing. Mohamed Khater founded INFONET Computer GmbH in Cologne in 1992. When we take over an IT environment, backup is the area with the most surprises – it has often been running for years without a restore ever being tested.
Further reading
- IT Security – Firewall, endpoint protection and emergency plan
- Cloud or your own server? – The calculation over five years
- All guides – More answers from practice
Free security check
Does your backup run – or does it work?
We look at what is backed up, where to, how long it is kept and whether a restore actually succeeds. Free of charge and with no obligation.
+49 221 984300-0Switchboard and support hotline
[email protected]Reply within 4 hours on working days
Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen
Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement
