When ransomware encrypts your servers, the question is not whether you have backups — it is whether those backups survived the attack and how quickly you can restore from them. Modern ransomware actively looks for backup files and backup servers to destroy them first. A simple rule, applied properly, makes that much harder.
What is the 3-2-1 rule?
- 3 copies of your data: the production data plus two backups.
- 2 different types of storage: for example a backup appliance and cloud storage, so one failure does not take out both.
- 1 copy offsite: away from your main office, so a fire, flood or theft does not destroy everything.
Going further: 3-2-1-1-0
Because of ransomware, many organizations now follow an extended version: one copy that is immutable or offline (it cannot be changed or deleted, even by an administrator account, for a set period), and zero errors when restores are tested.
Define your recovery targets
- RPO (recovery point objective): how much data you can afford to lose — one day, one hour, fifteen minutes? This sets how often you back up.
- RTO (recovery time objective): how long a system can be down before it seriously hurts the business. This sets how you restore — from local storage, the cloud, or a standby system.
Protect the backup system itself
- Use separate credentials for backup systems, protected with multi-factor authentication.
- Keep backup servers off the everyday domain where possible and restrict who can reach them.
- Monitor backup jobs and alert on failures — a backup that silently stopped weeks ago is a common surprise.
Test your restores
A backup is only proven when you restore from it. Schedule regular test restores of files, whole servers and critical applications, and time them against your RTO.
How Thoughts House can help
We design and deploy backup and disaster recovery solutions — on-premises, in the cloud or hybrid — with immutable copies, monitoring and restore testing, for organizations in Dammam and across Saudi Arabia.