Blog

How to Back Up a Small Business Properly: The 3-2-1 Rule in Practice

Secure Data Backup

Every week a business owner sits across the counter from us with two failed devices: the computer that held the files and the external drive that was supposed to be the backup. The backup was real. It was just plugged into the same machine, on the same desk, and it died in the same power surge, or it was encrypted by the same ransomware, or it was last run fourteen months ago. This guide is about backing up a small business in a way that survives the failures we actually see, using the 3-2-1 rule as it works in practice rather than as a slogan.

Why backups fail when they are needed

The backups that arrive in our lab failed for a short list of reasons, and none of them involve exotic technology.

  • Same place, same fate. An external drive on the desk next to the computer shares its surge, its spill, its theft, and its fire.
  • Sync mistaken for backup. OneDrive, Dropbox, and Google Drive copy every change to every device, including the deletion or the encryption. They are excellent at sharing and poor at protection.
  • Never tested. The job ran every night for a year and wrote zero bytes because a folder was renamed. Nobody looked until the day it mattered.
  • Ransomware reached it. A backup drive that is always connected, or a network share the workstation can write to, is encrypted in the same hour as everything else.
  • One copy of the backup. The backup drive itself is a hard drive. It fails at the same rate as any other.

The 3-2-1 rule, in plain terms

NumberMeaningIn a small business
3 copiesThe working data plus two backupsThe server or workstations, a local backup, and an off-site backup
2 kinds of storageDo not rely on one technology or one deviceA NAS or external drive locally, and a cloud backup service or rotated drives off site
1 off siteOne copy physically or logically separatedCloud backup with its own credentials, or a drive that leaves the building on a schedule

Some people add a fourth element: one copy that is offline or immutable, meaning nothing on your network can change or delete it. After ransomware became the most common way businesses lose everything at once, that fourth copy is the one that decides whether you recover in a day or start over.

Step 1: decide what you are protecting

Make a short list before choosing any tool. For most small businesses it looks like this: the accounting file or database, the shared documents folder, email, the customer list or CRM export, the website and its database, the project or job files currently in progress, and the one or two computers that hold things nobody has moved to the server. Anything not on the list is not protected, and that is a deliberate decision rather than an accident.

Step 2: the local copy

A network storage device (NAS) or a dedicated external drive that receives an automatic backup every night, and ideally versioned snapshots through the day. Two rules make it useful: the backup software should own the connection, so the drive is not simply a mapped share that every workstation and every piece of malware can write to, and the device should sit somewhere other than beside the machine it protects, even if that only means the other side of the office. This copy is for speed: restoring a deleted folder or a dead workstation from a local device takes minutes.

Step 3: the off-site copy

For most small businesses this is a cloud backup service, meaning a product that backs up files on a schedule to storage you do not manage, with its own login that is not shared with your email or your file sync. The alternative that still works is two or three external drives rotated weekly, with the current one locked in a drawer at someone’s home or in a safe deposit box. Rotation only works if someone actually rotates, so put it on a calendar. This copy is for disaster: the office is flooded, the server is stolen, or the whole network is encrypted.

Step 4: the offline or immutable copy

Ransomware operators look for backups before they encrypt anything, and they delete or encrypt what they find. The defence is a copy nothing on your network can reach with your everyday credentials: a cloud backup with immutability or object lock turned on, a backup account with multi-factor authentication and a password no workstation stores, or a rotated drive that is physically unplugged. If your backup can be deleted from a workstation that is logged in, it does not count as this copy.

Microsoft 365 and Google Workspace are not backups

Email and shared documents in Microsoft 365 or Google Workspace feel permanent, and for everyday mistakes they nearly are: a deleted file or message can usually be restored for 30 to 90 days depending on the plan and settings. Beyond that window, or after an attacker with admin access empties a mailbox, the data is gone and the provider will not recover it. A third-party backup of the tenant, or at minimum of the critical mailboxes and SharePoint sites, is the standard answer, and it is inexpensive next to reconstructing a year of correspondence.

Step 5: automate it, then test it

Backups that depend on a person remembering are backups that stop. Schedule them. Then test them, which means restoring rather than reading a green checkmark: once a quarter, pick a file and a folder from three months ago and restore them to a different computer. Time it. If it takes longer than an hour or fails, fix the backup while nothing is on fire. Keep a one-page note of where each copy lives, how to log in, and who is responsible, and store that note somewhere other than on the systems being backed up.

Home and sole-proprietor version

The same rule scaled down: keep the working files on the computer, an automatic backup to an external drive that you unplug when it finishes, and a cloud backup service running in the background. Photos and tax records are the two things people bring us most often after a single-copy failure, and both fit in a small cloud plan.

When the backup has already failed

If you are reading this because the backup drive is dead or the backup turned out to be empty, the data on the original device is usually still recoverable. Failed backup drives are ordinary drives and we recover them in the same cleanroom lab; a workstation or server that died is handled the same way, and a business that has been encrypted starts with the ransomware first 24 hours guide. The free evaluation tells you within 48 hours what can come back. For businesses in the Lower Mainland that would rather not build this themselves, we also set up and maintain backup systems that follow the plan above.

Frequently asked questions

Is cloud sync like OneDrive, Google Drive, or Dropbox a backup?

No. Sync mirrors changes, including deletions and ransomware encryption, to every copy within minutes. Most services keep deleted versions for 30 days, which helps with a single mistake, but it is not a backup you control. Use sync for convenience and a separate backup for protection.

How often should a small business back up?

Daily for working files and accounting data at a minimum, and hourly or continuous for anything that changes all day, such as a database or a shared project folder. The question to ask is how many hours of work you are willing to redo.

What is the 3-2-1 rule?

Three copies of your data, on two different kinds of storage, with one copy off site. The working copy on your computer or server counts as one. A local backup drive or NAS is the second. A cloud backup or a drive stored elsewhere is the third.

Does Microsoft 365 or Google Workspace back up my email and files?

Not in the way people assume. They keep deleted items and versions for a limited window, typically 30 to 90 days depending on settings, and they will not restore an account that was wiped by an attacker beyond that. A third-party backup of the tenant, or at least of the critical mailboxes and sites, closes that gap.

How do I know my backup actually works?

Restore from it. Pick a random folder and a random file from three months ago and get them back onto a different machine. If you cannot do that in under an hour, the backup is not ready for the day you need it.

The backup drive failed too. Can it be recovered?

Usually, yes. Backup drives are ordinary hard drives and fail in the same ways. We recover them in the same lab, and a failed backup drive plus a failed main drive is a case we see more often than you would think.

Backup failed, or never existed?

The original drive is usually recoverable. Free evaluation within 48 hours, no data no fee, and honest odds before you decide.

Instant AI EvaluationHard Drive RecoveryContact Us