Back to all articles Information Security

Backups: Your Business’s Last Line of Defense — and How to Do It Right in 2026

Key points

  • The 3-2-1 rule evolved into 3-2-1-1-0: an Immutable/Air-Gapped copy and "zero errors"
  • Modern ransomware hunts for and deletes backups — so an isolated copy is essential
  • Cloud sync (OneDrive/Drive) is not a backup — an encrypting change syncs instantly
  • An untested backup is an assumption, not a certainty — periodic restore tests are a must
  • Microsoft 365 runs on "shared responsibility" — the backup is your responsibility

When people think about information security, they usually picture firewalls, antivirus or intrusion-detection systems first. In reality, one of the most important measures — and often the last one standing when everything else fails — is a proper, organized and isolated backup. In this guide we explain why backup is the last line of defense, how it changed in the face of modern ransomware, and what you actually need to do so your backup truly saves you at the moment of truth.

Why backup is the last line of defense

Reality shows that even organizations with advanced security systems can be hit. Whether it’s ransomware, human error, a hardware failure or even a physical disaster like fire or flooding — the ability to restore data quickly is ultimately what determines how much damage is done. All the other layers of defense are meant to prevent the incident; the backup is what lets you return to operation after it has already happened.

The numbers illustrate the scale of the risk. According to industry reports, ransomware attacks rose by roughly 37% during 2025, and the average cost of a data-breach incident reached about $4.44 million globally. For a small or mid-sized business, a single such event can be the difference between staying open and shutting down.

The 3-2-1-1-0 Rule: The Modern Backup Strategy 3Copies 2Media types 1Off-site 1Immutable 0Errors Protection from failure, human error & disasterOriginal 3-2-1 rule Protection from backup-targeting ransomware + ongoing restore verificationThe modern addition: 1-0 Source: Industry best practices (Sophos, AvePoint, Veeam, SentinelOne)

The 3-2-1 rule — and its modern update for the ransomware era

The classic rule that has guided the industry for nearly two decades is the 3-2-1 rule: keep three copies of your data, on two different media types, with one copy stored off-site. This rule is still relevant — but in the ransomware era it is no longer enough on its own.

The reason is simple and worrying: modern ransomware attackers no longer settle for encrypting your production data. They actively hunt for backups on the network and try to delete or encrypt those too, to stop you from recovering without paying. Industry reports indicate that in the vast majority of ransomware attacks, attackers attempt to compromise the backup infrastructure as well.

That’s why the rule evolved into what’s now called 3-2-1-1-0: the same three copies on two media types and one off-site copy, plus two critical layers — one Immutable or Air-Gapped copy, and "zero errors": ongoing verification that the backup can actually be restored.

Copy typePurposeRansomware protection
Local copyFast recovery from everyday failuresLow — reachable by attacker
Off-site copyProtection from on-site physical disasterMedium
Immutable / Air-Gapped copyRecovery even after a full breachVery high

What an "immutable" backup is, and why it’s critical

An immutable backup is a copy that cannot be changed or deleted for a predefined period — not even by a user with administrator privileges, and not even if the admin account is compromised. This is exactly the answer to the modern threat: even if an attacker gains full control of the network, they cannot touch this copy. Combined with an air-gapped backup — a copy physically or logically isolated from the network — you get a layer of protection that’s very hard to bypass.

A common mistake: cloud sync is not a backup

One of the most common misconceptions is that OneDrive, Google Drive or Dropbox constitute a backup. They don’t. Sync services replicate every change almost instantly — so if ransomware encrypts your local files, the encrypted files are immediately synced to the cloud too, and both copies are lost. Sync provides availability and convenience, but it’s no substitute for a real backup strategy with isolated copies and version history.

Worth knowing: SaaS platforms like Microsoft 365 operate on a "shared responsibility" model — the vendor ensures platform availability, but recovering your data is largely your responsibility. It’s wise to ensure a dedicated, external backup also exists for mailboxes, SharePoint and organizational OneDrive.

"Zero errors": why you must test your backups

An untested backup is essentially an assumption, not a certainty. Quite a few businesses discover only after an incident that their backup hadn’t worked properly for months — a corrupted file, a process that failed silently, or media that filled up. The "zero errors" principle means continuously monitoring backups and running periodic restore tests, to ensure that at the moment of truth the data truly comes back — complete and usable.

A backup checklist for your business

  • At least three copies, on two different media types, with one copy off-site.
  • At least one Immutable or Air-Gapped copy that cannot be deleted or altered.
  • A dedicated backup for the Microsoft 365 / Google Workspace environment.
  • Periodic restore tests — not just confirming that "the backup ran".
  • Monitoring and alerts for failures in the backup process.
  • Defined recovery objectives (RTO/RPO) that fit the business.

Frequently asked questions

How often should I back up?
It depends on how much data you can afford to lose (your RPO). For many businesses a daily backup is a reasonable minimum, and for critical systems more frequent or continuous backup is preferable.
Is backing up to an external drive enough?
An external drive is a good start, but if it’s permanently connected to the computer it’s exposed to the same ransomware. It’s better to add a disconnected or immutable copy, and keep an additional copy off-site.
I have Microsoft 365 — is my data backed up automatically?
Not fully. Microsoft ensures service availability, but full recovery of deleted or encrypted data is your responsibility. A dedicated third-party backup for the environment is recommended.
How long does recovery take after an attack?
It depends on data volume, backup quality and advance preparation. A business with an isolated, tested backup and a recovery plan can return to operation within hours; without preparation it can take days or weeks.

Want to make sure your backup will truly save you? We help businesses build an organized backup strategy — from defining requirements, through choosing and implementing the solution, to periodic restore testing. Talk to us for an introductory call.

Want a backup review for your business?

A short introductory call will show you exactly where you stand and what’s worth improving.

Book a call →

Send us a message and we’ll get back to you

Fill in your details and Elad will reach out for an introductory call, no obligation

Your information is stored in accordance with our Privacy Policy.

Message received!

Thank you! Elad will get back to you shortly.

Something went wrong

You can try again, or write directly to info@maromcyber.com