Backup & Recovery Guide
The 3-2-1 Backup Rule Explained: How Many Copies of Your Data Do You Actually Need?
Let’s take a moment and picture an accountancy firm in County Louth getting a ransomware attack. Their server is locked. Nothing is working. Their “backup” is a second folder on the same machine. It’s locked too.
That’s not a story. It’s the real thing. It’s the single most common gap we see when we review a business’s setup for the first time: backups that exist but don’t actually protect anything are not worth the backup. The 3-2-1 backup rule exists to close that exact gap, and it’s simpler than most people expect.
What Is the 3-2-1 Backup Rule?
The 3-2-1 backup rule is a data backup strategy that says: keep three copies of your data, store them on two different types of storage, and keep one copy offsite. It’s not a product or a tool. It’s a structure that stops any single event, a fire, a laptop theft, or a ransomware attack, from wiping out everything at once.
How Does the 3-2-1 Backup Rule Work?
Break it into its three parts and it stops sounding abstract.
3 Copies of Your Data
Your live, working file counts as one copy. You need two more: a local backup and a remote one. Three data protection copies means one disaster, however bad, can only ever take out one of them.
2 Different Types of Storage
Don’t put both backup copies on the same kind of drive, or worse, the same drive. A common 3-2-1 backup strategy pairs a local device, like network attached storage (NAS), with a cloud platform. If a power surge fries your NAS, the cloud copy survives. If your internet drops, the NAS copy is still there.
1 Copy Kept Offsite
This is where most small businesses actually fall down. An offsite backup solution means at least one copy lives somewhere physically separate from your office; a data centre, a cloud provider, or anywhere a break-in or a burst pipe at your premises can’t reach it. Off site data protection is the part of the rule that turns “we have backups” into “we can actually recover”.
Why Backup Redundancy Actually Matters
Backup redundancy sounds like a nice-to-have until you’ve watched a business try to reopen without it. Ransomware attacks don’t just encrypt your live files anymore; modern strains actively search the network for connected backup drives and encrypt those too. A backup sitting on the same network, always powered on, always connected, is often the first thing an attacker finds.
That’s the uncomfortable insider detail most guides skip: ransomware protection isn’t just about stopping the initial infection. It’s about making sure your recovery path is somewhere the infection physically cannot reach.
How Many Backups Should a Business Have?
Three, at minimum, following the structure above. But “how many copies of data should you keep” is the wrong question to ask. A more useful one is: how many independent failure points can your business survive?
A business backup strategy built on one device and one location has exactly one failure point. Add a second storage type and an offsite copy, and you’ve turned a single point of failure into a structure that can absorb hardware failure, theft, and a site-wide incident, all without losing your data.
Applying the 3-2-1 Backup Rule With Cloud Storage
The original 3-2-1 rule predates cloud computing, but it maps onto it neatly. Running the 3-2-1 backup rule with cloud storage usually looks like this:
- Copy one: your live, working files
- Copy two: a local NAS or server backup, for fast recovery of recent work
- Copy three: a cloud backup for Ireland businesses can restore from anywhere, even if the office itself is inaccessible
Cloud storage backup on its own, without a local copy, still leaves you dependent on one provider and one internet connection at the exact moment you need speed most. The two-storage-type rule exists precisely so you’re never relying on a single link in the chain.
Building a Backup Schedule That Actually Holds Up
A backup that runs once a month is a photograph of your business from four weeks ago. Automated backups remove the human error that causes most backup failures: someone forgetting to run it, someone assuming it’s handled.
A working backup schedule typically includes:
- Continuous or hourly backups for anything changing constantly (email, active documents, databases)
- Daily backups for general file storage
- Weekly full-system backups, retained for a set period rather than overwritten immediately
Pair this with encrypted backup at rest and in transit. An unencrypted backup copy is just a second place for a criminal to steal your data from, not a protected one.
Where Businesses Get This Wrong
We see the same handful of mistakes on repeat. A backup that’s never been tested. A cloud sync tool (Dropbox, OneDrive) mistaken for a true backup, when it actually syncs deletions and encryption too. And cyber recovery plans that exist on paper but were never run through end to end, so nobody actually knows how long a real restore takes.
The 3-2-1 rule fixes the storage side of this. It doesn’t replace testing, and it doesn’t replace a documented recovery process. It’s the foundation those things sit on.
Conclusion
Getting the structure right matters more than which tools you buy to run it. If you’re not sure whether your current setup actually meets the 3-2-1 standard, it’s worth having someone check before you find out the hard way.Book a consultation with ImageIT and we’ll walk through what your backups can actually recover and what they can’t.
Frequently Asked Questions
A backup strategy: keep three copies of your data, on two different storage types, with one copy stored offsite away from your main location.
At least three: your working copy plus two backups. More copies only help if each removes a genuine, separate failure point.
A minimum of two backup copies beyond your live data, on different storage types, with at least one kept offsite from your premises.
Any copy stored physically away from your office, such as a cloud platform or a separate data centre, so a local incident can’t reach it.
You can, but pairing cloud storage with one local copy gives faster recovery for recent files and removes reliance on a single connection.
NAS is physical storage on your premises for fast local recovery. Cloud backup stores data offsite, protecting against theft, fire, or site-wide loss.
Frequency should match how often your data changes: near-continuous for active files, daily for general storage, weekly for full system backups.
It significantly reduces the risk, since an offsite, separated copy can’t be reached by ransomware that spreads across your local network.
Encrypted backup scrambles stored data so it’s unreadable without the correct key, protecting it even if a backup copy is stolen or intercepted.
Does Your Setup Actually Meet the 3-2-1 Standard?
We’ll walk through what your backups can actually recover, and what they can’t.

