Data loss is not a question of if — it is a question of when. Hard drives fail. Files get accidentally deleted. Ransomware encrypts entire drives. Cloud services have outages. Organizations that have not prepared for data loss discover the cost of that oversight at the worst possible moment.

The 3-2-1 Backup Rule

The 3-2-1 rule is the most widely recommended backup strategy for good reason — it is simple and effective:

  • 3 copies of your data (the original plus two backups)
  • 2 different storage media (e.g., local drive and cloud, or internal drive and external drive)
  • 1 copy offsite (so a fire, flood, or theft at your location does not destroy all copies)

Cloud backup services make the offsite requirement easy to meet. If your organization uses cloud storage as its primary location, ensure you also have a separate backup — cloud providers can have outages, and accounts can be compromised.

What to Back Up

Not everything needs the same backup frequency or retention. Prioritize:

  • Active working files and databases
  • Configuration files for critical systems
  • Records with legal or compliance retention requirements
  • Data that would be difficult or impossible to recreate

Temporary files, software installers, and easily recreatable content are lower priority.

Test Your Backups

A backup you have never tested is a backup you cannot trust. Regularly verify that your backups are complete and that you can actually restore from them. Many organizations discover their backups were incomplete or corrupted only when they need them. Schedule restoration tests at least annually.

Backup Frequency

How often you back up depends on how much data loss you can tolerate. The recovery point objective (RPO) is the maximum acceptable data loss measured in time. If you back up daily, your RPO is up to 24 hours of data. For critical operational data, more frequent backups — hourly or continuous — may be appropriate.

Ransomware Considerations

Ransomware encrypts your files and demands payment for the decryption key. A backup that is connected to your network when ransomware strikes may also be encrypted. Protect against this by keeping at least one backup that is offline or air-gapped — not continuously connected to your systems.

Key Takeaways

  • Follow the 3-2-1 rule: 3 copies, 2 media types, 1 offsite
  • Prioritize backing up data that is difficult or impossible to recreate
  • Test your backups regularly — an untested backup is an unreliable backup
  • Keep at least one backup offline to protect against ransomware
  • Match backup frequency to your acceptable data loss tolerance
Next Step

Good data practices require ongoing attention, not just initial setup. Learn how to build a culture of continuous improvement in Review and Improve Regularly.

← Protect Sensitive InformationReview and Improve Regularly →