Data Backup Strategies That Survive Real Failures

External hard drives for data backup
Photo via Pexels

Backup exists for four scenarios: hardware failure, human error, malicious encryption, and site loss. A strategy that handles one does not necessarily handle the others, which is why single-method approaches tend to disappoint.

The most common discovery during an actual incident is that backups existed but could not be restored — corrupted, incomplete, missing a critical system, or requiring credentials stored only on the encrypted server.

The 3-2-1 rule, updated

Three copies of data, on two different media types, with one copy off-site. This has been standard guidance for decades and remains sound.

The modern addition addresses ransomware: at least one copy should be immutable or air-gapped. Attackers routinely seek out and encrypt connected backups before triggering the main payload, and cloud sync propagates encryption to the cloud copy.

Immutable storage — write-once, cannot be deleted or altered for a defined retention period — is now widely available from cloud providers and is the practical answer.

Define RPO and RTO before choosing tools

Recovery point objective is how much data you can afford to lose, measured in time. Nightly backups mean up to 24 hours of loss. Recovery time objective is how long you can afford to be down.

These two numbers determine the architecture and the cost. An RPO of 15 minutes requires continuous replication; an RPO of 24 hours does not. An RTO of two hours requires standby infrastructure; an RTO of three days allows rebuilding from backup.

Establish these with the people who run the business rather than deciding technically. The answers are frequently more demanding than IT assumes and more expensive than management expects, and that conversation is better held in advance.

What gets missed

Cloud SaaS data. Microsoft 365 and Google Workspace operate a shared responsibility model — they ensure service availability, not recovery of your data from your own mistakes. Retention periods for deleted items are limited, and third-party SaaS backup exists for this reason.

Endpoint devices. Laptops holding local files that were never synced are a routine gap, particularly with remote workers.

Configuration and infrastructure. Firewall rules, server configurations, DNS records and application settings are often not backed up, and rebuilding them from memory during an incident extends downtime substantially.

Encryption keys and credentials. Backups protected by keys stored only on the compromised system are unrecoverable. Store recovery credentials separately and offline.

Testing is the part that matters

An untested backup is a hypothesis. Schedule restore tests quarterly at minimum: restore actual files to a separate location, verify integrity, and time the process.

At least annually, test a fuller scenario — restoring a critical system end to end. This surfaces dependencies nobody documented, such as an application that requires a licence server, or a database that needs a specific version to restore into.

Record the actual time taken. That figure, not the theoretical one, is your recovery time objective, and it is commonly several times longer than assumed.

Retention and documentation

Retention should reflect both operational needs and any regulatory or contractual obligations. A common pattern is daily backups retained for a few weeks, weekly for a few months, monthly for a year or more.

Longer retention also protects against slow-burn problems: corruption or malicious changes discovered weeks later, where recent backups all contain the problem.

Document the restore procedure in a form accessible without the systems being restored — printed, or stored in a separate service. A runbook stored only on the encrypted file server is a recurring and entirely avoidable failure.

Article Was Generated By AI.

This article is general information only and does not constitute professional advice. Circumstances vary, and you should consult a qualified professional before making decisions based on this content.