Use the 3-2-1 rule
- 3 copies of important data: the working copy plus two backups.
- 2 different types of storage, such as local storage and a reputable cloud backup.
- 1 copy off-site or isolated so theft, fire, or ransomware cannot reach everything.
Know what matters
List documents, photos, accounting data, customer records, email, website files, device configurations, and any application databases. Also record how software and accounts would be recovered. Prioritize the data that would stop operations.
Automate it
People forget manual copies. Use scheduled backups with notifications when a job fails. Protect the backup account with a unique password and MFA. Keep at least one versioned or immutable copy that ordinary users and infected computers cannot erase.
Test restores, not just backups
Every month, restore a few files to a separate location and open them. Quarterly, rehearse recovery of a critical application or device. Record how long it takes and who has the recovery keys.
Cloud sync is not enough by itself
Services that sync files can also sync accidental deletions or encrypted ransomware files. Version history helps, but confirm its retention period and add a separate backup for critical data.