Ask anyone whether they have backups — the answer is almost always "yes". Ask when they last tried to restore from one — and the room goes quiet. The gap between "we have a copy" and "we would survive losing our data" is enormous, and that gap is exactly what this rule is about.
The rule itself
It's simple. Three copies of your data: the working one plus two backups. Two different media: for example, a server and a separate disk or storage box — so one failure can't take everything. One copy off-site: in another building, another city, or protected cloud storage. Fire, flood, theft, or ransomware that reached everything on the network — that's what the "one" is for.
Mistake #1: the copy sits next to the original
A second folder on the same disk, an external drive permanently plugged into the server, a "backup" to the computer next door — all of it disappears together with the original. Ransomware deliberately hunts for backups on the network and encrypts them first. A real backup is either physically disconnected or stored where an attacker inside your network can't reach.
Mistake #2: nobody ever tests a restore
A backup you've never restored from is a lottery ticket. The disk may have been failing for months, the archive may be corrupted, a scheduling error may have silently stopped the copies. The rule is simple: restores must be tested periodically. We automate this — the system itself verifies that the backup ran and that data actually comes back from it.
Mistake #3: it all depends on one person
If backups are "Volodymyr's job every Friday", then when Volodymyr goes on holiday, so do your backups. Backup must be automatic, with an alert when something goes wrong — not when someone remembers to check.
What it costs
Less than you'd think: open-source tools are free, a separate disk or storage box is a one-time purchase, setup is a few hours of an engineer's work. Compare that with the price of losing five years of your customer database or accounting — and the question "do we need this" answers itself.
Not sure your copies would survive a real disaster? Get in touch — we'll review your backup scheme and tell you honestly where it would break.