A successful ransomware attack can paralyse an SME for several days to several weeks — the European cybersecurity agency ENISA ranks ransomware as one of the major threats facing European organisations1. The determining factor is not prevention — which can be circumvented — but the quality of the backup and restoration procedure. The 3-2-1-1 rule, recommended by the US CISA and by ANSSI in its anti-ransomware guides2, remains the best compass available today.
The 3-2-1-1 Rule, Clearly Explained
- 3 copies of your data (the original + 2 backups)
- on 2 different media types (disk + tape, or disk + cloud)
- with 1 offsite copy (geographically remote)
This rule, formulated by photographer Peter Krogh twenty years ago, remains relevant: it protects against three distinct families of risk — hardware failure, local disaster, and targeted attack.
Why It Is No Longer Sufficient on Its Own
Modern ransomware has evolved. It no longer simply encrypts production data: it actively hunts for backups before triggering encryption. The attacker typically gains access several weeks before the attack, using that time to:
- Map your infrastructure
- Identify your administrator accounts
- Locate and delete your backups
- Exfiltrate sensitive data (double extortion)
This is why the 3-2-1-1 rule has evolved into 3-2-1-1-0:
- 1 additional immutable copy (impossible to modify or delete)
- 0 errors during restoration tests (systematic verification)
Immutability in Practice
An immutable backup is a copy that cannot be overwritten, encrypted, or deleted for a defined period — even by an administrator with the appropriate rights.
Three approaches predominate:
1. Object Storage with Locking (S3 Object Lock, Azure Blob Immutable, and equivalents)
The current standard. The copy is locked for N days (typically 30 to 90), even against a compromised root account.
2. Magnetic Tape (LTO)
A long-standing method, still effective: a tape removed from the robot and stored offsite is physically unreachable by the attacker.
3. Hardened Backup Appliance
A hardware safe with a locked OS, without SSH access or administration API from the production network.
Restoration Tests: Non-Negotiable
An untested backup is an imaginary backup. We have supported businesses that believed they had been backing up for years — only to discover, on the day it mattered, that their backup was corrupted, incomplete, or entirely empty.
The ideal test is quarterly and covers:
- A complete folder restored to an isolated environment
- A complete database brought back up
- A full server restored (at least once a year)
The measured restoration time becomes your actual RTO (Recovery Time Objective). It is this figure, not the one promised by your service provider, that counts.
RTO and RPO: The Two Key Indicators
Every backup plan must set two explicit objectives:
- RTO (Recovery Time Objective): how much downtime is acceptable before systems are back up?
- RPO (Recovery Point Objective): how much data loss is acceptable?
For a law firm, a typical RPO is 1 hour (backups every hour). For an industrial SME, 4 hours is often acceptable. These values drive the entire upstream architecture.
The Cost of a Serious Backup Strategy — Indicative Figures
For an SME with 20 to 50 workstations, a file server, and a business application, here are the indicative figures we observe in managed services (to be adjusted according to data volumes, target RTO/RPO, and retention period):
- Local backup + immutable cloud backup: typically £170–£340/month ex. VAT
- Quarterly restoration tests: included in the Pro managed services package
- Annual consistency audit: 1 to 2 engineer days
This should be weighed against the cost of prolonged business interruption following a ransomware attack — lost revenue, unproductive salaries, crisis communications, CNIL notification — which can rapidly amount to tens of thousands of pounds for an SME, not counting reputational damage. The exact cost depends on daily turnover and the duration of the outage; a personalised quotation remains the only way to obtain a reliable estimate for your specific situation.
What We Deploy for Our Clients
- Local backup on a dedicated appliance (short RTO)
- Immutable cloud backup with a sovereign hosting provider (controlled RPO)
- Weekly rotation of an offline copy for critical organisations
- Quarterly restoration tests, fully documented
- Monthly reporting on backup consistency
All included within the managed services package, with no hidden costs.
Going Further
Our Cybersecurity offering covers the full spectrum: audit, EDR, MFA, immutable backups, and BCP/DRP.
Request your free preliminary assessment to evaluate your backup strategy in 15 questions.
Sources
Transparency note: we have removed all statistics that cannot be publicly verified (for example, the myth that "60% of SMEs close within six months of a ransomware attack", whose original source is untraceable and whose methodology is contested). If any claim strikes you as doubtful, write to us — we will correct or remove it.
Footnotes
-
ENISA, Threat Landscape (annual report). Ransomware regularly features among the major threats identified. See enisa.europa.eu. ↩
-
ANSSI, Guide pour anticiper et gérer une attaque par rançongiciel (cert.ssi.gouv.fr); CISA, Ransomware Guide (cisa.gov). Both explicitly recommend the 3-2-1-1 rule (and its evolution to 3-2-1-1-0), as well as the implementation of immutable copies and regular restoration tests. ↩
Keywords
- Sauvegarde
- Ransomware
- PRA
- Immuabilité