How to Back Up Your Business Data: The 3-2-1 Rule Explained

By J. Mesa

World Backup Day falls on March 31. Use it as a deadline. Ransomware crews count on one fact about small businesses: most of them cannot restore their own data. A working backup turns a business-ending attack into a bad week. This guide covers what to back up, where to keep it, and how to prove it works.

What is the 3-2-1 backup rule?

The 3-2-1 rule says you keep three copies of your data, on two different types of storage, with one copy stored offsite.

  • Three copies. The original plus two backups. One backup fails more often than you expect.
  • Two types of storage. For example, an external drive or network storage device in the office, plus a cloud backup service. A single power surge or a single bad firmware update should not reach both.
  • One offsite. Fire, flood, typhoon, and theft take the office and every device in it. An offsite copy survives.

Many security teams now extend the rule to 3-2-1-1-0. The extra 1 stands for one copy that is offline or immutable, which means nobody can change or delete it for a set period. The 0 stands for zero errors when you test a restore.

What data should a small business back up?

Start with a list of what you could not operate without for one week. For most small businesses that list includes:

  • Accounting and payroll files, such as your QuickBooks company file
  • Customer and patient records
  • Contracts, proposals, and signed forms
  • Email and calendars
  • Point-of-sale data and inventory
  • Shared drives and project files
  • Website files and the website database
  • Licenses, software installers, and configuration exports for your firewall and router
  • The password manager vault export, stored encrypted

Ask each employee one question: if your laptop died right now, what would you lose? The answers often reveal a desktop folder holding the only copy of something important.

Do I need to back up Microsoft 365 or Google Workspace?

Yes. Microsoft and Google keep their services running, and they protect against their own hardware failures. Your data remains your job. Microsoft calls this the shared responsibility model.

The recycle bin and retention settings help with small accidents. They do not help when an employee deletes a folder and nobody notices for four months, when a departing employee wipes a mailbox, or when ransomware syncs encrypted files over the good ones. A third-party backup service for Microsoft 365 or Google Workspace costs a few dollars per user per month and keeps an independent copy of mail, OneDrive or Drive, and shared sites.

Is cloud sync the same as backup?

No. Dropbox, OneDrive, and Google Drive sync changes. If you delete a file, the sync deletes it everywhere. If ransomware encrypts a file, the sync uploads the encrypted version. Version history can save you, but retention limits vary by plan, and restoring ten thousand files one at a time takes days.

A backup keeps point-in-time copies on a schedule, holds them for a period you choose, and restores a whole folder or a whole machine in one operation. Use sync for convenience and backup for survival.

How often should I back up?

Answer two questions.

How much work can you afford to redo? IT people call this the recovery point objective. If you back up nightly, you can lose up to one day of work. A busy office with constant transactions may need hourly backups for its key systems.

How long can you stay down? This is the recovery time objective. If the answer is four hours, a cloud-only backup that needs two days to download will not meet it. You need a local copy for speed and a cloud copy for disasters.

Daily automated backups suit most small offices. Automate them. A backup that depends on someone remembering to plug in a drive stops in the second week.

How do I protect backups from ransomware?

Attackers hunt for backups first. They delete them, then encrypt everything else, then send the ransom note. Make your backups hard to reach.

  • Keep one copy offline or immutable. Rotate external drives and unplug them, or choose a cloud backup with object lock or immutability turned on.
  • Use separate credentials. The backup account should have its own password, stored in a password manager, with multi-factor authentication. Do not log in to the backup console with the same admin account you use for everything else.
  • Encrypt the backups. A stolen backup drive is a data breach. Turn on encryption and store the key somewhere other than the device it protects.
  • Limit who can delete. Few people need the power to erase backup history. Require a delay or a second approval for deletions if your product offers it.
  • Patch the backup system. Network storage devices are frequent ransomware targets. Update the firmware and keep the device off the public internet.

How do I test a backup?

A backup you never restored is a guess. Run these tests on a schedule.

  1. Monthly file restore. Pick three random files from different folders and restore them to a different location. Open each one.
  2. Quarterly system restore. Restore a full machine or your accounting database to spare hardware or a virtual machine. Time it. Compare the time against how long you said you could stay down.
  3. Check the logs weekly. Backup software fails without telling anyone. Send the success and failure reports to a real person, and name a second person who covers when the first is out.
  4. Write down the steps. Document where the backups live, who holds the credentials, and how to restore. Print a copy. During an attack your shared drive is the thing you lost.

What does backup cost?

Less than one day of downtime. A typical five-person office spends roughly this:

  • Cloud backup for computers: $7 to $10 per computer per month
  • Backup for Microsoft 365 or Google Workspace: $2 to $5 per user per month
  • A network storage device with two drives: a one-time $400 to $700
  • Two external drives for rotation: about $150

Compare that against a week with no invoices, no schedules, and no customer records.

What are the most common backup mistakes?

  • One backup drive that stays plugged in all year. Ransomware encrypts it along with the computer.
  • Backing up the server and forgetting the laptops, or the reverse.
  • Nobody reading the failure alerts.
  • Storing the only copy of the encryption key on the machine being backed up.
  • Assuming the IT vendor handles it. Ask for a restore demonstration and a written report.
  • Keeping only seven days of history. Some attacks sit unnoticed for weeks, so keep at least 30 to 90 days of versions.
  • Forgetting the systems outside the office: the website, the cloud accounting system, the phone that holds every customer text.

Does compliance require backups?

Often, yes. The HIPAA Security Rule requires a data backup plan and a disaster recovery plan for health records. PCI DSS and the FTC Safeguards Rule both expect you to protect and recover the data you hold. Cyber insurance applications now ask whether you keep offline or immutable backups and whether you test them. Answer those questions with evidence, such as dated restore test records.

Your next step

Pick one critical file today and restore it from backup. If you can’t, you have found your project for March. Cerberus Cybersecurity reviews backup and recovery as part of our risk and compliance assessments, and we write the recovery plan your team follows under pressure. Contact us to schedule a review.