When people think about information security, they usually picture firewalls, antivirus or intrusion-detection systems first. In reality, one of the most important measures — and often the last one standing when everything else fails — is a proper, organized and isolated backup. In this guide we explain why backup is the last line of defense, how it changed in the face of modern ransomware, and what you actually need to do so your backup truly saves you at the moment of truth.
Why backup is the last line of defense
Reality shows that even organizations with advanced security systems can be hit. Whether it’s ransomware, human error, a hardware failure or even a physical disaster like fire or flooding — the ability to restore data quickly is ultimately what determines how much damage is done. All the other layers of defense are meant to prevent the incident; the backup is what lets you return to operation after it has already happened.
The numbers illustrate the scale of the risk. According to industry reports, ransomware attacks rose by roughly 37% during 2025, and the average cost of a data-breach incident reached about $4.44 million globally. For a small or mid-sized business, a single such event can be the difference between staying open and shutting down.
The 3-2-1 rule — and its modern update for the ransomware era
The classic rule that has guided the industry for nearly two decades is the 3-2-1 rule: keep three copies of your data, on two different media types, with one copy stored off-site. This rule is still relevant — but in the ransomware era it is no longer enough on its own.
The reason is simple and worrying: modern ransomware attackers no longer settle for encrypting your production data. They actively hunt for backups on the network and try to delete or encrypt those too, to stop you from recovering without paying. Industry reports indicate that in the vast majority of ransomware attacks, attackers attempt to compromise the backup infrastructure as well.
That’s why the rule evolved into what’s now called 3-2-1-1-0: the same three copies on two media types and one off-site copy, plus two critical layers — one Immutable or Air-Gapped copy, and "zero errors": ongoing verification that the backup can actually be restored.
| Copy type | Purpose | Ransomware protection |
|---|---|---|
| Local copy | Fast recovery from everyday failures | Low — reachable by attacker |
| Off-site copy | Protection from on-site physical disaster | Medium |
| Immutable / Air-Gapped copy | Recovery even after a full breach | Very high |
What an "immutable" backup is, and why it’s critical
An immutable backup is a copy that cannot be changed or deleted for a predefined period — not even by a user with administrator privileges, and not even if the admin account is compromised. This is exactly the answer to the modern threat: even if an attacker gains full control of the network, they cannot touch this copy. Combined with an air-gapped backup — a copy physically or logically isolated from the network — you get a layer of protection that’s very hard to bypass.
A common mistake: cloud sync is not a backup
One of the most common misconceptions is that OneDrive, Google Drive or Dropbox constitute a backup. They don’t. Sync services replicate every change almost instantly — so if ransomware encrypts your local files, the encrypted files are immediately synced to the cloud too, and both copies are lost. Sync provides availability and convenience, but it’s no substitute for a real backup strategy with isolated copies and version history.
Worth knowing: SaaS platforms like Microsoft 365 operate on a "shared responsibility" model — the vendor ensures platform availability, but recovering your data is largely your responsibility. It’s wise to ensure a dedicated, external backup also exists for mailboxes, SharePoint and organizational OneDrive.
"Zero errors": why you must test your backups
An untested backup is essentially an assumption, not a certainty. Quite a few businesses discover only after an incident that their backup hadn’t worked properly for months — a corrupted file, a process that failed silently, or media that filled up. The "zero errors" principle means continuously monitoring backups and running periodic restore tests, to ensure that at the moment of truth the data truly comes back — complete and usable.
A backup checklist for your business
- At least three copies, on two different media types, with one copy off-site.
- At least one Immutable or Air-Gapped copy that cannot be deleted or altered.
- A dedicated backup for the Microsoft 365 / Google Workspace environment.
- Periodic restore tests — not just confirming that "the backup ran".
- Monitoring and alerts for failures in the backup process.
- Defined recovery objectives (RTO/RPO) that fit the business.
Frequently asked questions
Want to make sure your backup will truly save you? We help businesses build an organized backup strategy — from defining requirements, through choosing and implementing the solution, to periodic restore testing. Talk to us for an introductory call.

