Blog Operational continuity

Backup Strategy 3-2-1: How to protect business data from ransomware and outages

The attacker encrypts your data, and then you discover that backups were connected to the same network and are also encrypted. Thousands of companies experience this scenario every year. The 3-2-1 rule is a proven strategy that prevents it.

22 September 2025 · 10 minutes reading · Operational continuity

Ransomware is today the most expensive form of cyberattack for most companies. The average ransom in Europe exceeded 1 million euros in 2024. But the real cost is not the ransom. It is operational downtime, data loss, reputational damage and recovery costs, which multiply the total losses. And yet there is one measure that effectively eliminates the worst-case scenarios: a good backup strategy.

But merely "having backups" is not enough. Attackers know this and, in sophisticated attacks, deliberately seek out and destroy reserves as their first step before your own data encryption. Backups connected to the network, cloud backups with identical login credentials, and backups without recovery testing, all of this is a false sense of security.

Rule 3-2-1: The foundation of an advance payment strategy

The 3-2-1 rule was formulated by photographer Peter Krogh as protection against photo loss, today it is a basic cybersecurity standard recommended by NÚKIB, ENISA and NIST.

These three rules address three different categories of failure: technical media failure (disk breakdown), local disaster (fire, flood, physical theft) and cyber attack (ransomware, sabotage). No single failure should result in the loss of all data copies.

Extension 3-2-1-1-0 for ransomware-threatened environments

Modern best practice extends the original rule with two conditions:

Offline backup is key against ransomware: even if an attacker gains access to the entire network, they cannot encrypt a medium that is not connected to it. An air-gapped backup (physically isolated, never connected to the internet or internal network) offers absolute protection, but requires regular manual media replacement.

RTO and RPO: what a company can truly afford to lose

Before setting up a backup strategy, every organisation must answer two key questions:

RPO (Recovery Point Objective) - how old may data be after recovery? If the RPO is 4 hours, the backup must not be older than 4 hours. For financial systems, the RPO can be 15 minutes or less, every transaction is critical. For archival documents, the RPO can be 24 hours.

RTO (Recovery Time Objective) - how long is recovery allowed to take? If the RTO is 2 hours, systems must be operational again within two hours of the incident. The RTO determines how fast the backup solution must be and how robust the recovery plan needs to be.

RPO and RTO are not technical parameters. They are management business decisionIT must provide a backup solution that meets these parameters. Companies that never defined their RPO and RTO discover their actual values only during a real incident, and by then it is often too late.

Different dates, different requirements

Do not attempt to apply uniform RPO and RTO targets to all corporate data. Segment them instead.

Cloud backups versus local backups: how to combine them

The debate between "cloud versus local backups" is a false dichotomy. The correct answer is both, with a clear role for each layer.

Local backups

Advantages: rapid recovery (not transmitted over the internet), low ongoing costs for larger data volumes, full control. Disadvantages: vulnerable to physical disasters and ransomware if located on the network.

Recommendation: NAS or backup server on the internal network (online backups) plus physically disconnected media (offline backups) stored in a safe or off-site.

Cloud backups

Advantages: geographic redundancy, resilience to physical disasters, scalability. Disadvantages: slower recovery for large data volumes, ongoing costs increase with volume, dependence on provider availability.

Key measure for cloud backups: immutable storage (backups cannot be overwritten or deleted for a defined period) and separate login credentials from the production environment. Ransomware that compromises a corporate Azure or AWS account could otherwise delete cloud backups as well.

Recovery testing: the only thing that matters

A backup that has not been successfully tested is not a backup. It is merely a promise of one. Practice shows shocking statistics: up to 30% of backup processes fail or produce inconsistent data without the IT department knowing. The error is only discovered during restoration, precisely at the moment of greatest stress.

Regular recovery testing must include:

  1. Verification of backup integrity - automatic checksums after each backup
  2. Test recovery - restore randomly selected data to an isolated environment at least quarterly
  3. Full DR test - simulate a complete outage at least once a year and measure the actual RTO
  4. Documentation of results - audit records of tests for compliance purposes

The NIS2 Directive and the Cybersecurity Act require a business continuity plan (BCM - Business Continuity Management), which must include a backup strategy and a regularly tested recovery plan. Organisations without BCM are in direct conflict with legal requirements during an audit by NÚKIB.

Configuring a backup strategy that meets the 3-2-1 rule, your RPO and RTO, and NIS2 requirements is not a trivial task, but it is one of the most important projects your IT department can undertake. The SecureOn.cz team helps you design, implement and regularly test backup solutions that precisely match your data and business requirements.

Do you need advice on cybersecurity?

Our experts are ready to assess your situation. The first consultation is free of charge.

Get a free consultation