Lesson of the Month #4 — 3-2-1 Backup: The Backup That Really Saves You (October 2026) (image: lesson-2026-10-vertical.jpg)

Three different attacks this month could have ended the same way: with the company's files encrypted or deleted. When prevention fails, a tested 3-2-1 backup is what gets the company back on its feet.

The good news for a company with 10–50 employees is that the defense strategy fits on one page and costs almost nothing. The 3-2-1 rule means three copies of your data (the original plus two backups), on two different types of media (for example, an external drive and a cloud service), with one copy stored off-site. Add an extra “1”: an offline or immutable copy that modern ransomware cannot encrypt, since it searches for and encrypts even backups connected to the network.

Include in your backup not only the documents on a computer, but also emails and files from Microsoft 365 or Google Workspace, accounting data, your website, and server configurations. Be aware of a common misconception: the cloud is not a backup—the provider guarantees service availability, not data recovery after you accidentally delete it or it gets encrypted.

The step that almost everyone skips is the restore test. A backup you’ve never restored isn’t a backup—it’s just a hope. At least once a quarter, actually restore a file from it—ideally, an entire system—and check whether the backup actually works, whether the files open, and how long it takes you to get back up and running. NIS2 explicitly requires business continuity and a recovery plan, but beyond the law, a tested 3-2-1 backup is the difference between an unpleasant incident and a company being shut down for a week. If you want to see where your company stands, the free assessment takes 5 minutes: https://xdn-cs.ro/instrument-nis2.html

This article was generated with AI assistance.

Request a quote

← All news