The 3-2-1 Backup Rule (And Why OneDrive Alone Is Not a Backup)

Ask a small business owner about backups and the most common answer is some version of: everything is in OneDrive, so we are covered. It feels true, because the files are somewhere else, on someone else’s servers, safe from a dead laptop.

Then ransomware encrypts a computer, the sync client dutifully uploads every encrypted file, and the damage is in the cloud within minutes. Or an employee deletes a folder in March and nobody notices until June, past the recycle bin window. Sync is not backup. Sync is a very fast way to replicate whatever just happened, good or bad.

What sync tools actually protect you from

OneDrive, Dropbox, and Google Drive are excellent at one thing: surviving the loss of a device. Laptop stolen, coffee spilled, files are fine. They also keep version history and a recycle bin, which can save you from small accidents if you catch them quickly.

What they do not give you is an independent copy. There is one set of data with multiple windows onto it. Anything that corrupts, encrypts, or deletes the data flows to every window, and retention windows expire. That is the gap the 3-2-1 rule closes.

The 3-2-1 rule in plain English

The rule is older than the cloud and still the standard because it survives every failure mode anyone has invented so far.

  • 3 copies of your data. The live working copy plus two backups. One backup is not enough, because backups fail too, usually discovered at the worst moment.
  • 2 different kinds of storage. Not two copies on the same NAS, and not two cloud accounts with the same password. Different systems fail differently, which is the point.
  • 1 copy offsite. Fire, flood, theft, and a ransomware attacker who finds your local backup all argue for one copy that lives somewhere else entirely.

For a typical small office that translates to: your working data (server or cloud), a local backup on a NAS or backup appliance for fast restores, and a cloud backup service as the offsite copy.

The two details that make backups ransomware-proof

  • Separate credentials. Modern ransomware crews look for backups and delete them before encrypting anything. If your backup system is reachable with the same admin password as everything else, it will be found. The backup account gets its own long unique password and its own MFA, and nothing else uses it.
  • Immutability or true offline. Good cloud backup services offer immutable storage, meaning even the administrator cannot delete backups before the retention period ends. The old-school version is a rotated external drive that spends most of its life unplugged in a drawer or offsite. A backup drive that is always connected is just another victim.

Back up the things everyone forgets

  • Microsoft 365 itself. Email, SharePoint, and Teams data live under retention policies, not backup. Deleted items eventually purge, and a compromised admin account can empty things fast. Third-party M365 backup is cheap and fills the gap.
  • Your accounting file. QuickBooks and other line-of-business data often live on one computer that everyone forgot about.
  • The things that are not files. Website, DNS settings, router and firewall configs, the password manager vault export. Losing these turns a bad day into a bad month.

A backup is a restore you have not tested yet

The only backup that counts is one you have restored from. Once a quarter, pick a file and restore it. Once a year, do a bigger drill: restore a whole folder or spin up the server image, and time it. That time is your real recovery speed, and it is the number to compare against what an outage costs you per hour, which our free downtime cost calculator will estimate in about a minute.

Assign the job to a person by name. Backups that belong to everybody belong to nobody, and the failure email that nobody reads is a genre classic in incident reports. This is also a core piece of the preparation stage in our ransomware survival plan: the businesses that decline to pay ransoms are the ones holding restorable backups.

Key Takeaways

  • Sync services replicate mistakes and ransomware as faithfully as they replicate good data. They are not backup.
  • 3-2-1: three copies, on two different kinds of storage, with one offsite.
  • Backups need their own credentials and either immutability or real offline time, or ransomware will delete them first.
  • Microsoft 365 data needs its own backup; retention policies are not the same thing.
  • Test restores quarterly and assign the job to a named person. An untested backup is a hope, not a plan.

Not sure whether your current setup would actually survive a bad week? Take the free cyber-risk self assessment, or request a consultation and we will review your backup posture in plain English.


LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.

Scroll to Top