Insights › Backups & Ransomware

The 3-2-1 Backup Rule: How to Make Your Business Ransomware-Resilient

Conceptual illustration of three data copies across two media with one offline copy on a navy background.

Ask any business that has survived a ransomware attack what saved them, and the answer is always the same: backups the attacker couldn’t reach. Ask any business that paid the ransom, and you’ll usually find backups that were connected, unmonitored, or had never been tested.

The 3-2-1 rule in plain terms

Modern ransomware adds a new requirement: at least one copy should be offline or immutable. Attackers deliberately search for connected backup drives and cloud backup accounts and encrypt or delete those first. If every copy is reachable from a compromised computer with a compromised password, you don’t really have backups; you have extra targets.

What “immutable” means, without the jargon

An immutable backup is one that can’t be changed or deleted for a set period, even by an administrator account. Most reputable cloud backup services now offer this as versioning or object-lock. Turn it on, and a ransomware operator who steals your admin password still can’t destroy last week’s backup.

The five-point backup checklist

  1. Automate it. Backups that rely on someone remembering don’t happen. Daily at minimum for business-critical data.
  2. Cover everything that matters. Server files, cloud drives, your accounting data, your website and its database, and key configurations.
  3. Keep one copy unreachable. Offline, in a separate account with different credentials, or immutable.
  4. Restrict who can delete backups. Separate credentials, MFA on the backup account, and no everyday admin access.
  5. Test restores quarterly. Restore a sample of files and time it. An untested backup is a hope, not a plan. Record how long a full recovery would take and decide whether the business can survive that downtime.

The question most businesses can’t answer

“If everything was encrypted at 9am tomorrow, when would you be trading again?” If you don’t know, that’s the gap. Regular backups are one of the ACSC Essential Eight controls, and our assessment weights them accordingly.

Related reading: the 3-2-1 rule is the backbone of a wider recovery plan. See how it fits together in our guide to backups and ransomware recovery, or step back to the complete guide to cyber security for small business in Australia.

Would your backups survive an attack?

Find out in 10 minutes. Answer 27 plain-English questions and get a free, personalised PDF report showing exactly what to fix first.

Get my free Security Score

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading