IT operations

A backup you have never restored is a rumour: the 3-2-1 rule, honestly applied

Everyone “has backups”, until the day they need them. What 3-2-1 actually means, why ransomware changed the rules, and the one habit that separates companies that recover from companies that close.

A backup you have never restored is a rumour: the 3-2-1 rule, honestly applied

Ask any company whether they have backups and the answer is yes. Ask when they last restored one, and the room goes quiet. That silence is the actual state of most backup systems: software dutifully running, nobody watching, restore never rehearsed. It works right up until the one day it is the only thing that matters.

What 3-2-1 means in practice

  • Three copies of anything you cannot afford to lose. The original counts as one.
  • Two different media or systems: the server and a NAS, or the server and a cloud service. Not two folders on the same disk.
  • One copy off-site or offline: physically elsewhere, or logically unreachable from your network.

The third point stopped being paranoia the day ransomware started encrypting backups first: modern attacks hunt the backup server before announcing themselves, precisely because a restorable victim does not pay.

The failures we actually find

The backup job that has been failing silently for months, its alert emails going to a mailbox nobody reads. The “full backup” that excludes the one database that matters, because someone unticked it during a space crunch years ago. The USB disk faithfully rotated, and stored in the same drawer as the server. The cloud sync that mirrored the ransomware’s encryption within minutes, because sync is not backup. Every one of these passed as “we have backups” until tested.

Restore is the product

Nobody needs backups; everybody needs restores. So the only metric that matters is: how long does it take to get system X back, and when did you last prove it? A quarterly habit (pick one system, restore it for real, time it, write the number down) turns backup from a belief into a measurement. It also surfaces the unticked database while that is still a funny story.

Two numbers your management should set

How much data can we afford to lose (a day? an hour?), that sets backup frequency. How long can we afford to be down, that sets the recovery architecture, because restoring a full server from cloud backup over an office internet line can take days, and knowing that before the incident changes what you build. These are business decisions wearing technical clothes; a consultant’s job is to price the options so management can choose deliberately.

Self-check

Does your backup actually satisfy 3-2-1?

Most companies believe they are backed up until the day they need it. Tick only what you could prove this afternoon.

A structural check, not an audit. The details (retention, encryption keys, who can delete what) are where a real review spends its time.

Start with a conversation

An initial consultation with a consultant rather than a salesperson, about your IT, security or systems question.