Most companies that lose data did in fact have a backup system. The problem is not the absence of backups but their failure at the moment of need. Corrupted, incomplete or attacker-deleted backups produce the same outcome as having none. A good strategy accounts for those possibilities up front.
The long-standing reference consists of three clauses:
Together these close most hardware-failure and physical-disaster scenarios.
The 3-2-1 rule took shape before ransomware became widespread. A significant share of today's attacks reach the backups first, deleting or encrypting them, and only then touch the primary data. A backup drive that is permanently connected is simply a second target.
So the rule needs one more clause: at least one copy must be immutable or offline. Storage that cannot be deleted for a defined period, or a physically disconnected disk, satisfies this.
Backup frequency is a commercial decision, not a technical one. The question is: how many hours of data can we afford to lose? A company backing up daily loses, at worst, a day of work. If that is acceptable, daily is enough; if not, increase the frequency.
The second question concerns recovery time: when a system fails, how quickly must it be running again? Without those two numbers, no backup design can be evaluated.
This is the most critical and most skipped item. A backup job reporting success says nothing about whether a restore works. Run a genuine restore drill at least annually: not a single file, but a full system, and measure how long it takes.
Which system is backed up where, how often, and retained for how long? If that information lives only in one person's head, nobody will know what to do during an incident while that person is away. A short document becomes your most valuable asset in a crisis.
Cookies are used to make the most of our site. By logging into this site you agree to our use of cookies.