Ask yourself a simple question: if your data vanished this morning, how long before you could resume operations? If the answer makes you uncomfortable, this post is for you.
Disk failures, a wrong click, ransomware, water damage, a stolen laptop… the causes of data loss are many and ordinary. The only real protection is a good backup. And “good” has a precise definition.
The 3-2-1 rule, plainly
- 3 copies of your data (the original + 2 backups).
- 2 different media (for example a local disk and the cloud).
- 1 copy off-site (somewhere other than your office).
Why it works: each “layer” covers a weakness of the others. A fire destroys the office? The off-site copy survives. Ransomware encrypts the server and the disk attached to it? The immutable cloud copy stays intact.
The 3 traps that make a backup useless
Many businesses believe they’re protected… until the day it matters. The most common mistakes:
- The backup is never tested. A backup you’ve never restored is a bet. Too often, people discover it was corrupt or incomplete at the worst possible moment. Test your restores regularly.
- Everything is in one place. A disk permanently attached to the server gets encrypted along with it by ransomware. You need at least one offline or immutable copy.
- Microsoft 365 isn’t backed up. Many assume “it’s in the cloud, so it’s backed up.” False: Microsoft replicates your data but doesn’t protect you against a deletion, a hacked account, or ransomware in OneDrive/SharePoint. A third-party backup of M365 is essential.
Beyond backup: continuity
Backup is being able to recover your data. Continuity is being able to keep working during recovery. Two questions to ask:
- RPO — how much data can I afford to lose? (1 hour? 1 day?) → this sets the frequency of backups.
- RTO — how long can I stay down? → this sets the solution (a simple restore vs fast failover to a standby environment).
What we put in place
Automatic, monitored and tested backups (devices, servers, and Microsoft 365), with at least one immutable off-site copy, and a documented recovery plan matched to your RPO/RTO. You no longer have to think about it — and on the day it counts, you’re back up fast.
Bottom line: the 3-2-1 rule fits in one sentence, but it prevents disasters. The mistake is almost never “having no backup” — it’s having one that’s never tested, all in one place, or that forgets Microsoft 365. Check those three points today.