Skip to content
Operations HubIT & Cybersecurity

Backup Strategy: The 3-2-1 Rule Every Business Should Follow

If you're running a small or medium business in Australia, there's a good chance technology and security isn't the part of your day you look forward to.

By Andrew Northcott·4 April 2026·5 min read·Last reviewed 8 July 2026

The short answer

The 3-2-1 rule says keep three copies of your data, on two different types of media, with one copy stored off-site. This protects you when a device fails, ransomware strikes, or a location is lost, because no single event can wipe out every copy. Test your restores regularly, since a backup you have never recovered from is only an assumption. For SMEs, this simple rule is a core part of the ASD Essential Eight's backup guidance.

Backups are one of those things every business owner knows they should have sorted, and most assume they have — right up until the day they need to restore and discover the backup was incomplete, out of date, or itself encrypted by the same ransomware that took out the original. The 3-2-1 rule is a simple, durable discipline that turns "we have backups" into "we can actually recover".

What the 3-2-1 rule actually says

It's three numbers, and each one defends against a different way of losing data.

  • 3 copies of your data — the live version you work from, plus at least two backups. Two copies isn't enough, because a single backup that fails leaves you with nothing.
  • 2 different types of storage media — so a fault or flaw affecting one kind of storage doesn't take out every copy at once. In practice this often means local disk plus cloud.
  • 1 copy kept off-site — physically or logically separate from your premises, so a fire, flood, theft or building-wide failure can't destroy every copy in one event.

The elegance is that the three rules stack. Multiple copies protect against corruption, multiple media protect against a storage-type failure, and off-site protects against a site-wide disaster. You need all three because each covers a gap the others don't.

The modern addition: 3-2-1-1-0

Ransomware changed the threat model, so security practitioners now often extend the rule. The extra 1 is a copy that is offline, air-gapped or immutable — one an attacker who's inside your network cannot reach, alter or delete. This matters because modern ransomware deliberately hunts for and destroys connected backups before it triggers, so that you have no choice but to pay. A backup an attacker can encrypt is not a backup you can rely on.

The final 0 stands for zero errors on recovery — verified by testing, which is the part almost everyone skips.

The rule that undoes all the others: test your restores

An untested backup is a hope, not a plan. The most common — and most painful — failure we see isn't the absence of backups; it's backups that ran faithfully every night for a year and then couldn't be restored when it mattered. The job wasn't configured to include the right data. The files were there but the database was in an inconsistent state. Nobody knew the restore process, so recovery took days instead of hours.

Test restores on a schedule. Actually pull data back from each backup and confirm it opens, it's complete, and it's recent. Time how long a full recovery takes, because that number is what you'll be living through during a real incident.

Two questions that shape your whole strategy

Before choosing tools, answer these for each important system:

  • How much data can you afford to lose? This is your recovery point objective. If losing a day's work is survivable, a nightly backup is fine. If it isn't, you need more frequent backups or continuous replication.
  • How long can you afford to be down? This is your recovery time objective. A business that can limp along for two days needs a very different setup from one that loses serious money for every hour offline.

These two answers tell you what to spend and where. Not everything deserves the same protection — your accounting data and customer records almost certainly warrant more than an archive of old marketing images.

Don't forget what lives in the cloud

A common blind spot: assuming that because your email, files and documents sit in a cloud service, they're automatically backed up. Providers protect their infrastructure, but under the shared-responsibility model your data is generally your responsibility. If a staff member deletes a folder, or an account is compromised and mailboxes are wiped, native retention may not save you. Cloud-hosted data needs a backup strategy too, and it should follow the same 3-2-1 discipline.

Where this fits

Backup sits inside a broader posture that includes patching, access control and the sort of layered defences described in the ASD Essential Eight — regular backups are one of its mitigation strategies. If you're building out your IT foundations more broadly, our Operations hub covers the wider picture.

The whole rule fits on a sticky note, which is part of its power: three copies, two media, one off-site, one offline, tested to zero errors. This is general information rather than tailored IT advice — a provider who knows your specific systems can help you translate it into the right configuration.

About the author

Andrew Northcott

Founder & Chairman, Valont

Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.

LinkedIn →

Want to know where your business stands?

Take our free Business Health Check — it takes 5 minutes and gives you a clear picture across finance, people, operations, and growth.