Backup and Disaster Recovery: The 3-2-1 Rule Every Small Business Should Follow
Ask most small business owners if they have backups and the answer is yes. Ask when someone last tested a full restore, and the room goes quiet. That gap is where disasters turn into permanent losses — and it is entirely avoidable with a simple, decades-proven rule.
The 3-2-1 rule, plainly
The 3-2-1 rule is the baseline every business should meet:
- 3 copies of your data — the live version plus two backups. One copy is not a backup; it is a single point of failure.
- 2 different types of media — for example, a local backup appliance and cloud storage. If one storage type fails or is compromised, the other survives.
- 1 copy offsite — physically separate from your office. A fire, flood, theft, or ransomware outbreak that hits your building should not be able to reach every copy of your data.
Many teams now extend this to 3-2-1-1-0: add one immutable or offline copy that cannot be altered or deleted, and aim for zero errors on your restore tests. In a world of ransomware that deliberately hunts and encrypts backups, the immutable copy is what saves you.
Why backups fail when you need them
Backups do not usually fail because nobody set them up. They fail in quieter ways:
- Nobody tested the restore. A backup job that reports "success" every night can still be unrecoverable — corrupt files, a missing database, an incomplete image. You only discover this during a real emergency, which is the worst possible time.
- Everything is in one place. Local-only backups get encrypted right alongside production when ransomware hits, or burn up in the same fire.
- No immutable copy. If an attacker with admin access can delete your backups, they will — before they trigger the ransom.
- Silent gaps. A new server, application, or cloud service gets added and never makes it into the backup scope. Nobody notices until it is gone.
RTO and RPO, without the jargon
Two simple questions drive every disaster recovery plan:
- RTO (Recovery Time Objective): how long can you afford to be down? An hour? A day? A week?
- RPO (Recovery Point Objective): how much data can you afford to lose? If you back up once a day and go down at 4 p.m., you could lose a full day of work.
There are no universally "right" numbers — only the ones your business can actually tolerate. A busy medical or legal office may need an RTO of hours and an RPO of minutes; a smaller operation might live with more. The point is to decide these on purpose and build backups to match, rather than hope.
Backup vs. BCDR — they are not the same
Plain backup is a copy of your data. Business Continuity and Disaster Recovery (BCDR) is a plan for keeping the business running when something breaks. BCDR answers the harder questions: if your main server dies Monday morning, how fast can staff get working again, where do they work from, and in what order do systems come back? Backup is a component of BCDR — a necessary one, but not the whole plan.
The one habit that matters most: test your restores
If you do nothing else after reading this, schedule regular test restores. A backup you have never restored is a theory, not a safety net. Recovering real files and full systems on a routine schedule is the only way to know your plan works before you are betting the business on it.
Equal Tech Solutions designs and manages backup and disaster recovery for small and mid-sized businesses — 3-2-1 done right, immutable offsite copies, sensible RTO and RPO targets, and restores we test so you do not have to find out the hard way.
If you are not certain your backups would bring you back after a fire or a ransomware hit, that uncertainty is worth resolving now. Equal Tech Solutions serves Chattanooga, Cleveland, and the Southeast US. Contact Equal Tech Solutions for a straight review of your backup and recovery plan.

