
Ask any business that has survived a ransomware attack what saved them, and the answer is always the same: backups the attacker couldn’t reach. Ask any business that paid the ransom, and you’ll usually find backups that were connected, unmonitored, or had never been tested.
The 3-2-1 rule in plain terms
- 3 copies of your important data: the original plus two backups.
- 2 different types of storage: for example, a local drive or NAS plus cloud storage.
- 1 copy off-site: somewhere physically and logically separate from your office and main systems.
Modern ransomware adds a new requirement: at least one copy should be offline or immutable. Attackers deliberately search for connected backup drives and cloud backup accounts and encrypt or delete those first. If every copy is reachable from a compromised computer with a compromised password, you don’t really have backups; you have extra targets.
What “immutable” means, without the jargon
An immutable backup is one that can’t be changed or deleted for a set period, even by an administrator account. Most reputable cloud backup services now offer this as versioning or object-lock. Turn it on, and a ransomware operator who steals your admin password still can’t destroy last week’s backup.
The five-point backup checklist
- Automate it. Backups that rely on someone remembering don’t happen. Daily at minimum for business-critical data.
- Cover everything that matters. Server files, cloud drives, your accounting data, your website and its database, and key configurations.
- Keep one copy unreachable. Offline, in a separate account with different credentials, or immutable.
- Restrict who can delete backups. Separate credentials, MFA on the backup account, and no everyday admin access.
- Test restores quarterly. Restore a sample of files and time it. An untested backup is a hope, not a plan. Record how long a full recovery would take and decide whether the business can survive that downtime.
The question most businesses can’t answer
“If everything was encrypted at 9am tomorrow, when would you be trading again?” If you don’t know, that’s the gap. Regular backups are one of the ACSC Essential Eight controls, and our assessment weights them accordingly.
Related reading: the 3-2-1 rule is the backbone of a wider recovery plan. See how it fits together in our guide to backups and ransomware recovery, or step back to the complete guide to cyber security for small business in Australia.