Real IT Consulting article cover: building a 3-2-1 backup strategy that restores reliably

How to Build a 3-2-1 Backup Strategy That Actually Restores

Almost every business believes it has backups. A much smaller number have backups that would actually restore under pressure. The gap between those two states is where businesses fail permanently after a ransomware attack, a failed drive, or an employee emptying the wrong folder. This guide covers how to build a backup strategy that survives contact with a real disaster.

The 3-2-1 rule

The long-standing baseline, and still the right starting point:

  • 3 copies of your data — the live copy plus two backups
  • 2 different types of storage media
  • 1 copy kept offsite

Ransomware has pushed the industry to extend this. The modern version is often written as 3-2-1-1-0: add 1 copy that is offline, air-gapped or immutable, and 0 errors on your restore tests.

Those two additions matter enormously. Ransomware operators specifically hunt for and destroy backups before they encrypt anything, because a business with working backups does not pay. A backup that your compromised administrator account can delete is not protection.

Step 1: Work out what you actually need to protect

Most businesses back up either everything indiscriminately or whatever the software defaulted to. Neither is a strategy.

List your data and sort it into three buckets:

  • Cannot operate without it. Accounting file, customer database, current project files, email.
  • Would hurt badly to lose. Historical records, completed project archives, photo libraries.
  • Replaceable. Software installers, cached files, things you could download again.

Then find the data you have forgotten. It is almost always in the same places: files on individual desktops, a local QuickBooks or MYOB file on the bookkeeper's laptop, the CCTV recorder, the POS system's local database, configuration on network equipment, and anything in a cloud service you assume is backed up but is not.

Step 2: Define your two numbers

Every backup decision follows from two figures. Decide them before you buy anything.

Recovery Point Objective (RPO): how much data can you afford to lose, measured in time? If you back up nightly, your RPO is up to 24 hours — a failure at 4pm loses a full day's work. If that is unacceptable for your accounting system, that system needs more frequent backups.

Recovery Time Objective (RTO): how long can you be down? A business that can work from paper for two days has a very different requirement from a clinic that cannot see patients without its system.

These two numbers drive everything: how often you back up, where the backups sit, and how much you spend. Write them down and check your current setup against them. Most businesses discover a mismatch immediately.

Step 3: Build the layers

Layer 1: Local backup

Fast to restore from and good for the everyday case — a deleted file, a corrupted document, a failed workstation. A network-attached storage device or dedicated backup appliance onsite. Image-based backups of whole machines beat file-level backups when you need to recover fast, because you restore the entire system rather than rebuilding it.

Layer 2: Cloud backup

Your offsite copy. Protects against fire, flood, theft and the total loss of a site — all realistic scenarios in South East Queensland. Modern cloud backup runs continuously in the background and only sends changes, so bandwidth impact is manageable after the initial seed.

Check the restore side, not just the backup side. Downloading several terabytes over a business internet connection takes considerably longer than people expect. Ask your provider whether they can ship a drive or spin up a temporary virtual machine.

Layer 3: Immutable or offline copy

The layer that defeats ransomware. Options include immutable cloud storage where objects cannot be modified or deleted for a defined retention period, rotating external drives kept physically disconnected, or a backup service with a separately authenticated deletion process.

The test is simple: if an attacker had full administrative control of your network right now, could they destroy this copy? If yes, it does not count as your protected copy.

Step 4: Cover your cloud services

This is the most common blind spot in modern small business.

Microsoft 365 and Google Workspace do not back up your data in the way you probably assume. They provide redundancy and short-term retention. They protect against their own infrastructure failing. They do not protect you from a user deleting a SharePoint library, a departing employee wiping their mailbox, ransomware encrypting synced files, or a mistake discovered six months later.

Retention windows are typically measured in weeks. If you need more, you need a third-party backup covering Exchange, OneDrive, SharePoint and Teams. The same logic applies to your accounting platform, your CRM, and your e-commerce store — check what each vendor actually guarantees, and export what they don't.

Step 5: Test restores — properly

This is the step everyone skips and the only one that proves the rest worked.

A backup that reports success but produces a corrupt or incomplete restore is worse than no backup, because you were relying on it. A green tick in a dashboard is not evidence.

Build a testing rhythm:

  • Monthly: restore a handful of individual files from each backup set and open them. Confirm the contents are correct, not just that the file appeared.
  • Quarterly: restore a full system or a complete folder structure to a test location. Time it, and compare against your RTO.
  • Annually: a full disaster recovery rehearsal. Assume the office is inaccessible. Can you actually get operational elsewhere? Who does what?

Record the results. If a restore takes six hours and your RTO is two, you have learned something important at a moment when it costs you nothing.

Step 6: Monitor and be alerted

Backups fail quietly. A drive fills up, a credential expires, an agent stops running after an update, a new server never gets added to the job. Months pass.

You need active alerting on failures, and — just as importantly — someone whose job it is to respond to that alert. An email going to an unmonitored inbox is not monitoring. Check that the size of your backup set makes sense: a backup that suddenly got much smaller usually means something stopped being included.

Step 7: Write the recovery plan down

When you need this, you will be stressed, possibly locked out of your systems, and quite likely without your usual documentation. Keep a written plan somewhere physically accessible:

  • What systems exist, and their restore priority order
  • Where each backup lives and how to access it
  • Credentials, stored securely but reachable in a crisis
  • Who to call: your IT provider, your internet provider, your insurer, your bank
  • What you tell staff and customers, and who says it
  • Your legal notification obligations if personal information was involved

Print it. Keep a copy offsite. A recovery plan stored only on the file server you just lost is a lesson people learn exactly once.

What good looks like

A well-run small business backup setup usually looks like this: continuous or hourly local image backups to an onsite device, daily replication to cloud storage, an immutable retention policy on the cloud copy, third-party backup for Microsoft 365, automated alerting on failures, monthly file-level restore tests, quarterly full restore tests, and a printed recovery plan.

That sounds like a lot. In practice it is a few hundred dollars a month for most small businesses and one afternoon to set up properly — against a loss that routinely ends companies.

Real IT Consulting designs and manages cloud and backup solutions for businesses across the Gold Coast, Brisbane, Logan, Pimpama and Sydney, including restore testing you can actually see the results of. Call 0489 940 359 for an honest assessment of whether your current backups would survive a real incident.

Back to blog