Why one backup is never enough
Most businesses we speak to think they are covered. There is a copy somewhere: a folder syncing to the cloud, a NAS in the corner, or an external drive a member of staff swaps once in a while. The trouble is that a single copy is not a backup strategy — it is a single point of failure waiting for its moment.
We see the same failures repeatedly in the workshop. An external drive that was “definitely backed up” turns out to have stopped working eighteen months ago and nobody noticed. A cloud sync faithfully copies a ransomware infection up to the cloud, encrypting the only offsite copy. A NAS fails and takes both drives with it because the RAID was never actually redundant. In each case there was technically a backup. It just was not there when it counted.
The 3-2-1 rule exists to remove that risk without needing an IT department to manage it.
What 3-2-1 actually means
The rule is deliberately easy to remember: keep 3 copies of your data, on 2 different types of media, with 1 copy kept offsite. For a typical small business that translates to:
- The live data itself, on your PCs, Mac or server
- A local backup on separate hardware, such as a NAS or dedicated backup drive
- An offsite copy, usually in the cloud or on a rotated drive kept away from the premises
The three numbers each defend against a different kind of disaster. Three copies means a single failure never leaves you with nothing. Two media types mean one flaw — a bad batch of drives, a failed NAS, a corrupt cloud sync — cannot wipe out every copy at once. One offsite copy means a fire, a flood or a break-in at the office does not take your business with it.
Why “different media” matters more than it sounds
The part businesses skip most often is the two-media requirement. Two external drives from the same box, bought on the same day, are not really two media types — they can fail the same way at the same time. A cloud sync and the laptop it syncs from are not independent either, because anything that damages the files locally is copied straight up.
Genuine separation means one copy behaves differently from the others. A local NAS plus a cloud backup is a solid mix. Even better is having at least one copy that cannot be altered after it is written — many cloud backup services now offer immutable or “versioned” storage, so even if ransomware reaches your network, older restore points stay intact. That single feature is often the difference between a bad afternoon and losing everything to a ransomware attack.
Cloud and local: use both, not one
There is a persistent myth that “we are in the cloud now, so we do not need backups”. Microsoft 365 and Google Workspace are excellent, but their own terms make clear that protecting your data is your responsibility, not theirs. A deleted mailbox, a departing employee, or a compromised account can lose data that the platform will not restore for you.
The strongest setup for most firms combines both worlds. Keep a local backup for speed — restoring a large folder or a whole machine from a NAS on your own network takes minutes, not the hours a full cloud download can need. Keep a cloud backup for resilience, because it survives anything physical that happens to the building. If you are moving systems into the cloud anyway, planning the backup as part of that cloud migration rather than bolting it on afterwards saves a great deal of pain later.
The step everyone forgets: test the restore
A backup you have never restored from is not a backup — it is a hopeful assumption. The single most common reason a business loses data despite “having backups” is that the backup had been silently failing for months, or the files were there but unusable when finally opened.
Build a simple habit into the calendar:
- Monthly: restore a handful of real files to a different location and open them. Do they actually open?
- Quarterly: restore something larger — a full folder or a test mailbox — and time how long it takes.
- Annually: run through the worst case. If the main machine or server died today, walk through the exact steps to get trading again, and see how long it would take.
That last exercise tells you your real recovery time, which is usually the number that matters to a business. Knowing it in advance turns a disaster into an inconvenience.
When the backup has already failed
Sometimes the call comes after the drive has died and the backup turns out to be incomplete. That is not the end of the road — professional data recovery can often retrieve files from failed drives, corrupt volumes and even water-damaged devices. It is slower and more costly than restoring from a good backup, which is precisely why the 3-2-1 rule is worth setting up before you need it.
Getting it set up properly
If you would rather not piece this together yourself, we can design and set up a 3-2-1 system that fits how your business actually works — local hardware, cloud copies, sensible retention and, crucially, restores that have been tested. Call us on 020 7610 0500, drop into the Putney workshop, or use the contact form, and we will help you get reliable backup solutions in place.




