The 3-2-1 rule means keeping three copies of your data on two types of storage with one copy stored offsite. It is the simplest framework for protecting your business data against hardware failure, ransomware and human error.
The 3-2-1 backup rule has been around for decades because it works. It is the simplest framework for making sure your business data survives anything, whether that is a hardware failure, a ransomware attack, a fire or simple human error.
The rule is straightforward. Keep three copies of your data, on two different types of storage, with one copy stored offsite. If you follow this rule, your data is protected against virtually any single point of failure.
Most businesses do not follow it. Many do not even come close.
What the numbers mean
Three copies means your original data plus two backups. If you only have one backup and both the original and the backup fail or are compromised at the same time, you lose everything. Two backups means you always have a fallback even if one backup fails.
Two types of storage means your backups should not all be on the same kind of media. If your data is on a hard drive and your backup is on another hard drive in the same machine, a power surge or hardware failure could take out both. Having one backup on a local drive and another in the cloud gives you diversity that protects against different failure modes.
One offsite means at least one copy of your data should be physically separated from the others. If your office floods, burns down or is broken into, a backup sitting on a hard drive next to the server is just as lost as the server itself. An offsite or cloud backup survives because it is somewhere else entirely.
Where most businesses fall short
The most common backup setup in a small business is a single external hard drive or a USB drive that someone plugs in periodically. This fails the 3-2-1 rule on multiple counts. There is only one backup, not two. It is on the same type of storage. It is often kept in the same location. And it is rarely monitored or tested.
Some businesses have OneDrive syncing their files to the cloud and consider that their backup. It is not. OneDrive is a sync service, not a backup. If ransomware encrypts your files, those encrypted files sync to OneDrive. If someone deletes a folder, it is deleted from OneDrive. Sync mirrors everything, including damage.
Other businesses have a backup solution installed but nobody is checking whether it actually runs. A backup that failed three months ago without anyone noticing is not a backup. It is a false sense of security.
How 3-2-1 works in practice for a small business
For most small businesses using Microsoft 365, a practical 3-2-1 setup looks like this.
Copy one is the live data in Microsoft 365, your email in Outlook, your files in OneDrive and SharePoint, your conversations in Teams. This is what your team works with every day.
Copy two is a cloud backup of your entire Microsoft 365 environment using a dedicated backup service. This captures email, OneDrive, SharePoint and Teams data independently from Microsoft's platform. It retains data for months or years, not just 30 or 93 days. And it stores the backups in a separate cloud environment that is isolated from your production data.
Copy three is an additional backup stored in a different location. For some businesses this is a second cloud region. For others it is a local backup device in the office that captures the most critical data.
The exact implementation depends on your business size, your data volume and your recovery requirements. But the principle is always the same. Three copies, two types, one offsite.
Why testing matters as much as having backups
A backup you have never tested is a theory, not a plan. You do not know whether it works until you try to restore from it. And discovering that your backup was not capturing what you thought it was, or that the restore process takes three days instead of three hours, is not something you want to learn during an actual emergency.
Testing does not need to be complex. A quarterly restore test of a sample of data, enough to confirm the backup is running, the data is intact and the restore process works, is sufficient for most small businesses.
The cost of not following the rule
Every business that loses data permanently has the same story. They thought they were backed up. They were not backed up properly. By the time they discovered the gap, it was too late.
Recreating lost data is expensive when it is possible and devastating when it is not. Client records, financial history, email archives, project documentation, employee records. If these disappear, the impact goes far beyond the cost of the backup solution that would have prevented it.
The bottom line
The 3-2-1 rule is not complicated and it is not expensive. For most small businesses, implementing it properly costs a fraction of what a single data loss event would cost. The question is not whether you can afford to follow the rule. It is whether you can afford not to.
At Recloud we design and manage backup solutions for Cape Town businesses that follow the 3-2-1 rule as a minimum standard. If your current backup is a USB drive in a desk drawer or an OneDrive sync that nobody monitors, get in touch and we will show you what proper data protection looks like.