Business backup: the 3-2-1 rule explained | ALAconnect

Guide · Backup

Business backup: the 3-2-1 rule and how to check it really works

Why one backup is not enough, how to apply the 3-2-1 rule in an SME and why the restore test matters more than the copy.

ALAconnect · Published on 7 October 2026 · 5-minute read

At a glance

  • The 3-2-1 rule means 3 copies of your data, on 2 different media, with 1 off-site.
  • Against ransomware you also need an immutable or offline copy.
  • An untested backup is not a backup: restores must be tested regularly.
  • Microsoft 365 needs backing up too: cloud retention does not replace backup.

What is the 3-2-1 rule

The 3-2-1 rule is the basic principle for protecting business data: keep at least 3 copies of your data (the original plus two backups), on 2 different media or technologies, for example an office NAS and cloud storage, with at least 1 copy off-site. This way a single failure, theft or fire cannot destroy all copies at once.

Why today you need 3-2-1-1-0

Modern ransomware looks for and encrypts backups reachable over the network. That is why the rule has evolved into 3-2-1-1-0: the basic structure gains 1 immutable or offline copy, which cannot be changed or deleted even with administrator credentials, and the goal of 0 errors in restore checks.

How to apply it in an SME

  1. Fast local copy: a backup to a NAS or dedicated storage on site, to restore files and virtual machines in minutes.
  2. Off-site copy: an encrypted replica in the cloud or an external datacenter, for disasters affecting the whole office.
  3. Immutable copy: storage with deletion lock for a defined period, which resists even an attacker with administrative access.
  4. Separate accounts: backup system credentials must not match domain credentials and should be protected with multi-factor authentication.

RPO and RTO: how much can you afford to lose

Before choosing the technology, define two values. RPO (Recovery Point Objective) is the maximum amount of data the company can lose, measured in time: with a nightly backup the RPO is about 24 hours. RTO (Recovery Time Objective) is the maximum time within which systems must be back up and running. A critical business system may need hourly backups and recovery within hours; a document archive can tolerate longer times.

The restore test is the most important part

Many companies discover their backup does not work exactly when they need it: incomplete copies, failed media, lost passwords or restore times far longer than expected. To avoid this:

  • schedule a restore test at least every three months, alternating single files, a virtual machine and a complete service;
  • measure the actual restore time and compare it with the RTO;
  • record date, result and issues of each test, which also serves as evidence for GDPR and NIS2;
  • check backup job result notifications every day.

What about Microsoft 365?

Email, OneDrive, SharePoint and Teams are hosted by Microsoft, but responsibility for the data stays with the company: accidental or malicious deletions, compromised accounts and ransomware on synced files can cause losses that standard retention does not cover. A dedicated Microsoft 365 backup lets you restore mailboxes, files and sites even months later.

How ALAconnect works

ALAconnect designs and manages backup systems following the 3-2-1-1-0 rule, with local copies, encrypted off-site replicas, immutable storage, Microsoft 365 backup, daily job monitoring and documented restore tests. Discover the Backup & Business Continuity service or contact us for a review of your current system.

Need support?
Need support?