Blog

Backups that work when it counts: the 3-2-1 rule for mid-sized companies

Managed Hosting

You don't have a backup just because a job runs every night. You have one once you can restore a working state from it within an acceptable time. Many companies discover the difference only when it is too late: after ransomware, a failed storage system or a customer folder deleted by mistake. A few clear rules prevent that.

Why backups need rethinking

The biggest threat used to be a failed hard drive, and a second copy on another disk took care of it. Today ransomware is the more realistic scenario, and attackers deliberately go after backups as well. If your backups are reachable with the same credentials as your production systems, you can lose both at once.

Then there are the mundane causes, which are at least as common. An update corrupts a database. A fire or water damage hits the server room. Or someone simply deletes the wrong folder.

The 3-2-1 rule

The proven rule of thumb for resilient backups is short:

  • 3 copies of your data: the original plus two backups.
  • 2 different storage media or systems, so a single fault cannot hit every copy.
  • 1 copy at a separate location, physically apart from the original.

The idea behind it: no single event may destroy all copies at the same time. A NAS in the same room as the server may satisfy the first two points. It will not survive a fire, though, and it offers no protection against an attacker already moving through your network.

The extension: 3-2-1-1-0

Many practitioners now add two more digits. One copy should be stored offline or immutable, so that it cannot be deleted or encrypted even with valid credentials. The zero stands for zero errors on verification: every backup is tested to confirm it can actually be restored.

Two figures you should define

Before anyone talks about technology, management should answer two questions.

  • RPO (recovery point objective): how much data can you afford to lose? With a nightly backup, that means up to 24 hours of work. Perhaps acceptable for a day of bookkeeping, far less so for an online shop.
  • RTO (recovery time objective): how long may a system be down before it is running again? The question here is not whether a backup exists, but how long the restore takes.

Both values differ from system to system. Your ERP usually needs tighter targets than an archive of old project data. Record them once per system and you have the basis for every further conversation with your IT team or service provider.

What data protection and bookkeeping rules require

No law prescribes a specific backup method. The requirements do come from several directions, though.

  • GDPR: Article 32 requires appropriate technical and organisational measures. These explicitly include the ability to restore the availability of and access to personal data promptly after an incident, and a process for regularly testing the effectiveness of those measures. A backup that has never been tested hardly meets that standard.
  • GoBD: under Germany's principles for proper electronic bookkeeping (GoBD), records subject to retention must be protected against loss. If they can no longer be produced because they were not adequately secured, the tax authorities regard the bookkeeping as formally deficient. Backup procedures therefore belong in your process documentation, which we covered in our article on GoBD-compliant document filing.
  • Data processing: if an external provider holds your backups, you need a data processing agreement under Article 28 GDPR (Auftragsverarbeitungsvertrag, AVV). You should also know which country the copies are stored in.
  • NIS2: for companies within the scope of the EU NIS2 Directive, backup management and disaster recovery are explicitly listed among the required risk management measures.

Common weak spots

  • The backup sits in the same network and is reachable with the same admin rights.
  • Data is backed up but never restored, so nobody knows whether the backup is complete until it is needed.
  • Error messages from the backup job land in a mailbox nobody reads.
  • Cloud services are assumed to be "backed up anyway". Whether and for how long individual deleted data can be recovered depends on your contract, and it is worth checking.
  • All the knowledge rests with one person. When they are on holiday, nobody knows how the restore works.

Why a German location matters

The off-site copy required by the 3-2-1 rule has to live somewhere. With a German provider and data centres in Germany, your data stays within the scope of the GDPR, the contract is governed by German law, and in an emergency you speak to people who know your environment. For HR, customer and accounting data in particular, that spares you many questions about transfers to third countries.

How we handle it at dream-soft

In dream-soft managed hosting, backups are part of standard operations, not an add-on.

  • Daily backups of your systems.
  • Regular restore tests to confirm that a backup can actually be recovered when it counts.
  • Geo-redundancy: the servers run in the ISO-certified NTT data centre in Frankfurt am Main, and the backups are kept at a second location in Germany.
  • Round-the-clock monitoring, so failed jobs and anomalies do not go unnoticed.
  • GDPR-compliant operation with a data processing agreement and an average support response time of under 30 minutes.

Our business software dCM runs on the same infrastructure, with hosting, updates and backups included in the monthly plan. On top of that, dCM can automatically mirror incoming and outgoing invoices to your own WebDAV target such as Nextcloud. That does not replace a backup, but it gives you one more copy of your documents under your own control.

Conclusion

A good backup strategy depends less on expensive technology than on clear decisions. How much data loss is tolerable? How quickly do you need to be up and running again? Where does the off-site copy live? And when was a restore last tested? If you cannot answer that last question off the top of your head, that is exactly where to start.

Note: This article provides general information about backups, the GDPR and the GoBD. It does not constitute legal advice.

All posts

When was your backup last tested?

We'll review your current backup setup and show you what operation with daily backups, restore tests and geo-redundant storage in Germany could look like for your systems, with no strings attached.