Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Business Backups: The 3-2-1 Rule and Disaster Recovery

In short

Backups are the difference between a bad day and a business-ending one. The 3-2-1 rule keeps three copies of your data, on two types of storage, with one kept off-site. This guide explains how to apply it, what to back up (including your Microsoft 365 data, which is not backed up for you), how to test that restores actually work, and how good backups get you through a ransomware attack.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Why backups are the safety net under everything

Most of the security advice you read is about keeping the bad thing from happening. Backups are different: they are what saves you when something gets through anyway. Fire, flood, a stolen laptop, a deleted folder, a failed hard drive, or a ransomware attack — a good backup turns any of these from a disaster into an inconvenience.

The uncomfortable truth is that many small businesses believe they are backed up when they are not. Files sit on one laptop. Microsoft 365 is assumed to protect itself. A USB drive in a drawer was last updated eighteen months ago. This guide gives you a clear, proven approach — the 3-2-1 rule — so you know your data is genuinely safe.

The 3-2-1 backup rule

The 3-2-1 rule is the industry standard, and it is easy to remember:

  • 3 copies of your data — the live version you work on, plus two backups.
  • 2 different types of storage — for example, an external drive or a network device and the cloud. Using two types means one problem is unlikely to wipe out both.
  • 1 copy kept off-site — somewhere physically separate, such as a cloud backup or a drive stored in another location. This is what saves you from fire, theft, or flood at your premises.

A simple example for a small office: your working files live on your computers (copy one), they sync to a secure cloud service (copy two, off-site), and a nightly backup runs to a network device in the office (copy three, a different type of storage). That single arrangement satisfies all three parts of the rule.

A stronger version: 3-2-1-1-0

Security professionals increasingly add two more numbers. The extra 1 is one copy kept offline or “immutable” — meaning it cannot be altered or deleted, even by an attacker who gets into your systems. The 0 stands for zero errors, confirmed by testing your restores. Both directly address ransomware, which we come back to below.

What you actually need to back up

It is easy to protect the obvious things and forget the rest. Work through this list:

  • Documents and shared files — everything your team creates and relies on day to day.
  • Email — often the most valuable asset in the business, and the hardest to recreate.
  • Accounting and business software data — check whether your provider backs this up or whether that is on you.
  • Customer records and databases — your CRM, booking system, or line-of-business app.
  • Device settings and configurations — so a replacement machine can be rebuilt quickly.

The Microsoft 365 blind spot

This one deserves its own heading because it catches so many people out. If you use Microsoft 365 (or Google Workspace), your data is not automatically backed up for you. Microsoft keeps the service running and protects its own infrastructure, but under what it calls the shared-responsibility model, protecting your actual emails, files and folders is your job.

That means if a member of staff deletes something, an account is hijacked, or ransomware reaches files stored in OneDrive or SharePoint, the built-in retention may not save you. A dedicated third-party backup of Microsoft 365 fills this gap and is one of the most important backups a modern business can have.

Choosing your off-site copy

Your off-site copy is usually cloud-based, and choosing where it lives matters — both for reliability and for privacy. Look for storage that is encrypted, based somewhere with strong data-protection law, and that supports keeping older versions of files so you can roll back.

For secure file storage and sharing with strong encryption, Proton Drive is a solid option — it is part of the privacy-focused Proton suite that we use ourselves and is subject to Switzerland’s strong privacy law. It works well for holding an encrypted off-site copy of important documents. For a full business backup, you will typically pair cloud storage with a dedicated backup tool that automates the whole process; our managed IT services cover exactly this kind of setup.

Testing your restores — the step everyone skips

Here is the hard-won lesson behind every backup horror story: a backup you have never restored from is not a backup — it is a hope. Backups fail silently all the time. The drive fills up, a setting changes, a folder gets missed, and nobody notices until the day they desperately need to recover — and cannot.

Make restore testing a routine:

  1. Schedule a test restore. At least quarterly, actually recover a few files (and ideally a whole mailbox) from your backup to prove it works.
  2. Check the data is complete and usable. Open the restored files. Confirm they are the right version and not corrupted.
  3. Time it. Note how long a realistic recovery takes. This tells you how much downtime to expect in a real incident.
  4. Write down the steps. So recovery does not depend on one person remembering how everything works.

The “0” in 3-2-1-1-0 is this discipline: zero errors, verified by testing rather than assumed.

Recovering from ransomware

Ransomware encrypts your files and demands payment for the key. Good backups are your way out — instead of paying criminals (with no guarantee they will restore anything), you wipe the affected systems and restore clean copies of your data.

But there is a catch modern attackers know well: they hunt for your backups first and try to encrypt or delete them too. This is why the strongest protection is a copy they cannot reach — one that is off-site and either offline or immutable, so it stays clean no matter what happens to your live systems.

A sensible ransomware recovery position looks like this:

  • Daily automated backups following the 3-2-1 rule.
  • At least one copy that is offline or immutable, beyond an attacker’s reach.
  • A dedicated Microsoft 365 backup so your email and cloud files are covered.
  • Tested restores, so you know recovery works before you need it.
  • A written plan naming who does what and in what order.

For the wider picture of preventing an attack in the first place, see our guide to ransomware protection for UK small businesses, and our cyber-security services for how the pieces fit together.

The bottom line

Backups are not glamorous, but they are the single thing most likely to save your business when something goes badly wrong. Apply the 3-2-1 rule, remember that Microsoft 365 is your responsibility to back up, keep one copy out of an attacker’s reach, and — above all — test that your restores actually work. Do that, and almost any disaster becomes recoverable.

Not sure whether your current backups would survive a real incident? Get in touch and we will review your setup honestly, with no jargon and no pressure.

Frequently asked questions

Doesn't Microsoft 365 back up my data automatically?

No, and this catches many businesses out. Microsoft keeps your service running and protects against its own hardware failures, but under its shared-responsibility model your data is your responsibility. If a file is deleted, an account is compromised, or ransomware encrypts your files, Microsoft's built-in retention is limited and time-bound. A separate third-party backup of Microsoft 365 is strongly recommended.

How often should we back up?

For most small businesses, at least daily for anything that changes regularly — email, documents, and accounting data. The real question is how much work you can afford to lose. If losing a day's work would hurt, back up more often. Modern backup tools run automatically in the background, so frequent backups need not mean extra effort.

What is the difference between a backup and disaster recovery?

A backup is a copy of your data. Disaster recovery is the whole plan for getting back up and running after something goes wrong — which systems come back first, who does what, and how long it takes. Backups are an essential ingredient of disaster recovery, but a pile of backups with no plan and no tested restore is not the same as being prepared.

Will backups protect us from ransomware?

Good backups are your strongest defence against ransomware, because they let you restore your data instead of paying a criminal. The catch is that modern ransomware tries to find and destroy backups too. That is why an off-site or offline copy that attackers cannot reach — sometimes called an immutable or air-gapped backup — is so important.

How long should we keep backups for?

It depends on your needs and any legal or accounting obligations, but a common approach is to keep recent backups for quick recovery (daily copies for the last few weeks) plus longer-term copies (monthly for a year or more). The key is being able to go back far enough to recover from a problem you did not notice straight away, such as data that was quietly corrupted or encrypted weeks ago.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.