Call NowFree Quote
Backup & DR

The 3-2-1 Backup Rule Explained: A Plain-English Guide for Perth Businesses

Most businesses think they have backups. Far fewer have backups that would actually survive the situation they're meant to protect against. The 3-2-1 rule is a decades-old standard precisely because it forces you to plan for the ways backups commonly fail, not just the fact that a backup exists.

What the 3-2-1 Rule Actually Says

  • 3 copies of your data - the original plus at least two backups. One backup is a single point of failure; two means you can lose one and still recover.
  • 2 different types of media or storage - for example, a local NAS or server and a cloud backup, rather than two copies on the same type of disk or the same platform.
  • 1 copy stored offsite - physically or logically separate from your main location and network, so a local disaster or a network-wide compromise can't take out every copy at once.

None of this is new or exotic. It's been standard advice in IT for years - but it gets skipped or half-implemented constantly, usually because the easy version of "having backups" looks fine right up until the day it's actually needed.

Why Each Part of the Rule Exists

Why three copies, not two

With only the original and one backup, a single failure during that backup - corruption, an interrupted job, ransomware that reached it before encryption was noticed - leaves you with nothing to fall back on. A third copy means there's still a safety net even if one backup turns out to be bad when you actually need it.

Why two different media types

If both backup copies live on the same type of storage, run the same software, or sit behind the same login credentials, a single flaw or attack that affects one is likely to affect both. Mixing media types - local disk plus cloud, for example - means a problem specific to one technology doesn't take out every backup at once.

Why one copy has to be offsite

This is the part that gets skipped most often, and it's the one that matters most for ransomware specifically. If your "backup" is a second drive sitting in the same office, on the same network, using the same credentials as your production systems, ransomware that spreads across the network can encrypt the backup right along with everything else. An offsite copy - genuinely separate, ideally with different credentials and limited connectivity - is what survives that scenario.

Common Ways Perth Businesses Get This Wrong

  • Only one backup copy exists - often a single external drive or a single cloud sync, with nothing to fall back on if that one copy fails or is compromised.
  • Backups live on the same network as production data - a NAS sitting next to the server it backs up, both reachable from the same compromised account, gives ransomware a direct path to the backup too.
  • "Backup" is actually just sync - a synced cloud folder mirrors changes immediately, including encrypted or deleted files. That's not a backup, it's a mirror, and it will faithfully copy ransomware's damage unless versioning is genuinely enabled and tested.
  • Nobody has tested a restore - a backup that's never been restored is an assumption, not a guarantee. The first time many businesses discover a backup doesn't work is during an actual emergency.
  • Backup credentials aren't separated from everyday accounts - if the same admin account that runs daily operations can also delete or modify backups, a compromised account threatens both at once.

Is 3-2-1 Still Enough on Its Own?

Some more recent guidance extends the rule to "3-2-1-1-0" - adding a requirement for at least one immutable or air-gapped copy (one that can't be altered or deleted, even by an attacker with admin credentials), and zero errors confirmed through regular testing. This isn't a contradiction of 3-2-1, it's a sharper version of the same idea, written specifically with ransomware in mind. For most small and medium Perth businesses, the practical takeaway is the same either way: at least one backup copy needs to be genuinely untouchable by anything that compromises your main network, including an attacker with administrator-level access.

This is also where backup retention length matters. A business that only keeps the last few days of backups can find that every available recovery point is already affected, if the ransomware sat undetected on the network for a week or more before triggering encryption. Keeping several weeks of versioned backups, not just the most recent one, gives you a far better chance of finding a genuinely clean recovery point when it counts.

Applying 3-2-1 Practically for a Small or Medium Business

In practice, a workable setup for most Perth SMBs looks like this: the live data (copy one), a local backup on a NAS or backup appliance for fast restores of everyday issues like accidental deletion (copy two, different media), and a cloud backup with versioning and immutability, stored with a provider genuinely separate from the production network and using its own credentials (copy three, the offsite copy). Microsoft 365 data needs the same thinking applied separately, since Microsoft's own retention settings are not a substitute for a real backup.

The other half of the equation is testing. A backup that follows 3-2-1 on paper but has never been restored is still a guess. Quarterly test restores, even of a small sample of files, are what turn 3-2-1 from a checklist into something you can actually rely on.

Frequently Asked Questions

What is the 3-2-1 backup rule?

It's a simple standard for resilient backups: keep at least 3 copies of your data, on at least 2 different types of media or storage, with at least 1 copy stored offsite or away from your main systems. It's been a standard recommendation in IT for years because it accounts for the most common ways backups fail.

Does cloud backup count as the offsite copy?

Yes, generally - cloud backup that's genuinely separate from your production network satisfies the offsite requirement, provided it isn't just a synced folder that mirrors changes (including ransomware encryption) in near real time. A proper cloud backup keeps versioned, point-in-time copies rather than a live mirror.

Is a NAS device on the same network as the offsite copy?

No. A NAS on your office network is a second copy on different media, which is genuinely useful, but it isn't offsite. If ransomware spreads across your network or the office has a fire or flood, a NAS sitting next to the servers it's backing up can be affected at the same time.

How do I know if my current backup setup actually follows 3-2-1?

Map out exactly where every copy of your data lives, what type of storage each is on, and whether any of them share the same network, building, or login credentials as your production systems. If two or more copies would be affected by the same event - a ransomware attack, a fire, a stolen laptop - the rule isn't being met.

We design and manage 3-2-1 backup setups for Perth businesses, including the offsite copy and the testing schedule most businesses skip.

Backup & Disaster Recovery →

Not sure if your backups would actually survive a real incident?

Call 0433 087 091 for a free, no-obligation review of your current backup setup against the 3-2-1 standard.

Book a Free Consultation

For related reading, see our guides to How to Test Your Business Backup and Cloud Backup vs Local Backup for Perth Businesses.

Share this article