2 September 2026
At a Glance
The 3-2-1 backup rule reduces reliance on a single recovery copy by keeping multiple copies of important business data across different storage locations, including one offsite. However, ransomware can also target backups, so effective recovery requires protected or immutable copies, suitable retention, regular restore testing and clear recovery objectives alongside the traditional 3-2-1 approach.
Find out more about how the 3-2-1 backup rule can support your ransomware recovery plan. Talk to our experts today.
Why Backups Are Important for Your Business
A single ransomware incident can turn business as usual into a complete crisis in no time. When systems freeze and your teams can’t access files, there’s only one question lingering on your mind: “Will I get my data back?”
You don’t need a ransomware incident to understand why backups are important for modern businesses. Backups are highly critical, but having one you can rely on matters more.
If your only backup is connected to the same environment as your live data, the attacker may be able to reach both. If nobody has tested your backups recently, you may not find a problem till you have to restore them.
The 3-2-1 backup rule is a practical way to reduce this risk. It gives your business multiple paths to recover instead of relying on a single copy of data.
But in reality, can the 3-2-1 backup save your business from ransomware? Find out in this guide.
What Is the 3-2-1 Backup Rule?
Simply put, the 3-2-1 rule for backup means keeping,
- 3 copies of your important data
- 2 copies on different devices or storage locations
- 1 copy at an offsite location
This rule follows the underlying principle of avoiding the risk of losing every copy of your data in the same incident.
This backup framework, also recommended by the National Cyber Security Centre (NCSC), can help your business retain data after server failure and human error. If ransomware compromises part of your systems, this strategy allows you a better chance of retaining a clean recovery point.
However, just implementing the 3-2-1 backup rule doesn’t automatically protect one of those copies from ransomware.
How the 3-2-1 Backup Rule Works in Practice for a UK Business
Let’s take an example of a UK business that stores important customer, financial and operational data across its servers and in the cloud. It also takes a backup every night. This process can look reassuring on paper, but if the backup is the only additional copy, the business has only one recovery option.
The 3-2-1 backup approach adds a separation. The business can keep production data and backups on separate storage, plus an offsite backup service. This strategy isn’t about creating more data copies but about preventing one event, like ransomware, from taking out everything at once.
Why One Backup Copy Is Not Enough Against Ransomware
A backup only helps when it survives the incident that caused you to need it. Ransomware attackers often deliberately target, delete, or destroy backup data to make recovery harder and increase pressure on an organisation to pay the demanded ransom. Over 323 businesses, of which 50% were SMEs, contacted the UK’s cybercrime and fraud reporting service between April 2025 and March 2026 alone.
If they delete, encrypt or make backups unusable, your ransomware recovery plan disappears with it. This is why one backup copy is not enough and a backup strategy needs separation and protection, not just duplication.
What Happens When an Attack Reaches Your Backups Too
If a ransomware attacker gains access to your systems, they may spend time inside your environment before the main attack begins. Once inside, they may compromise privileged accounts and interfere with recovery options.
This can also cause your backups to automatically copy corrupted or encrypted files and may make older recovery points unavailable.
This makes retention and version history important. These factors can help your business go back far enough to reach a known-good version of your data. If newer backup versions become corrupted, the NCSC recommends that backup systems allow recovery from earlier versions.
Why Offsite and Immutable Copies Close the Gap
Offline or immutable backups are separated from the live network. This separation prevents malware or an attacker in the environment from reaching it.
An immutable backup is designed to prevent the stored backup data from being altered or deleted during a defined retention period. It can make it harder for an attacker with compromised credentials to destroy your recovery points.
This can call for a tweak to the traditional 3-2-1 rule for backups, which includes maintaining multiple copies but ensuring at least one has strong protection from the environment you are trying to recover from.
Why Testing Your Backups Matters as Much as Making Them
Backups alone don’t prove your business can recover from an incident like ransomware. Your backups could be incomplete, contain corrupt data or take longer to restore.
Discovering these problems during a ransomware incident is too late. Testing your backups at regular intervals gives you a more realistic update of your RPO and RTO.
- RPO, or Recovery Point Objective, is how much recent data you can afford to lose.
- RTO, or Recovery Time Objective, is how quickly systems need to return.
More than a backup copy, a successful restore tells you that the copy can help your business recover.
How Redpalm Helps Build a Backup Strategy That Actually Recovers
The 3-2-1 rule is a great backup strategy for businesses. But your ransomware recovery plan and staying resilient for the long term need more.
Your backup strategy needs to reflect the systems your organisation depends on, how quickly you need them and what would happen if an attacker gained access.
Redpalm provides managed backup and disaster recovery services to help UK businesses not only protect data but also recover when things go wrong.
We don’t set up your backup and assume it will work. We also create a wider recovery process. Regular testing, checks and monthly test scores confirm backups are working as intended and data can be recovered when needed.
Our IT and cyber security experts can also help your organisation consider:
- Which of your systems and data need protection
- Protection against ransomware and other disruptive events
- Appropriate backup frequency and retention
- Cloud-based backup options
- Recovery requirements
- Disaster recovery planning
- Backup monitoring and testing
Get in Touch Today
Would your current backups survive a ransomware attack, and more importantly, could you restore from them?
Talk to Redpalm about your backup and disaster recovery strategy to see where your ransomware recovery plan may leave you exposed. Book your free IT review today.