Hardening · 10 July 2026 · 4 min read
Backups with the 3-2-1 rule — the plan that survives ransomware
3 copies, on 2 kinds of storage, with 1 off-site. How to build a backup ransomware can't reach, and how to test it so it's a plan, not a hope.
ClearSecurity Vision
In a ransomware attack, one question separates “two bad days” from “we lost the company”: do you have a copy of your data the attacker couldn’t reach? Modern ransomware hunts down and encrypts reachable backups first — precisely because they are your escape plan.
That’s why the practical standard is the 3-2-1 rule: at least 3 copies of your important data, on at least 2 different kinds of storage, of which 1 is off-site — disconnected or separated from your network.
What you need
- Your data inventory — if you don’t have one, build it first: you can’t copy what you haven’t located
- A cloud storage subscription for backup with a separate account (not the company’s day-to-day account), or a dedicated backup service
- An external drive for the disconnected copy, if you go the physical route
- 2–3 hours of setup, then a few minutes a month for checks
Step 1: decide what you copy
Not “everything” — the data that would hurt: accounting, contracts, customer files, the main application’s database. From your data inventory, mark the critical categories. The rest (operating system, programs) can be reinstalled; data can’t be reinvented.
Mind a common trap: OneDrive/SharePoint/Google Drive are not backup. Sync faithfully copies the encryption too — if ransomware encrypts files locally, the encrypted versions sync over the good ones. Version history on these platforms helps, but has retention limits — don’t rest your whole plan on it.
Step 2: the automatic daily copy
- Set up an automatic, daily backup for the critical categories — any manual process means, in practice, forgotten.
- Destination: a cloud backup service or a local NAS — but the backup account gets its own long password and two-factor authentication, used for nothing else.
- Turn on versioning (keeping older variants of files): with ransomware, the latest copy may already be encrypted — you need to step back a few days.
Step 3: the off-site copy
This is where everything is won or lost:
- Cloud route: a second storage service or account, with credentials no company computer has saved. Ideally with an “immutability” option (copies can’t be deleted or altered for a set period — not even by an administrator).
- Physical route: an external drive connected only for the duration of the copy (weekly, say), then disconnected and kept somewhere other than the server — another site, a safe, the administrator’s home. A permanently connected drive gets encrypted along with everything else.
Step 4: the restore test
An untested backup is a hope, not a plan:
- Once a quarter, restore a few randomly chosen files into a separate folder and open them. Does it actually work? How long did it take?
- Once a year, play out the big scenario: “the server died last night” — how long until you’re working again? The answer (hours? days?) is something leadership needs to know and accept.
Verify the result
- You receive (or can see) confirmation that the daily backup ran — and when it doesn’t run, someone finds out actively, not three months later.
- The key test: “if an attacker has the company’s admin password, can they delete all 3 copies?” If the answer is yes, the off-site copy isn’t truly separate.
Common mistakes
- Backup on a drive permanently attached to the server. Ransomware’s first target. Disconnected or immutable — otherwise it doesn’t count.
- Sync mistaken for backup. Drive/OneDrive faithfully replicate destruction, not just work.
- The same passwords everywhere. If the backup account opens with the administrator’s compromised password, the attacker finds it first.
- “It’s worked for two years, surely it still works.” Without restore tests, you learn the backup was broken on exactly the day you needed it.
If you want to see the money at stake too, we did the maths in what a security incident really costs.
Under NIS2? Business continuity and backup management are named explicitly among the law’s minimum measures.
One step done. See the full picture.
Answer a few questions across the 8 essential areas — from passwords and backups to suppliers — and get a report by email with your weak spots and next steps.
Start the self-assessment →
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.