GUIDE / ADMINISTRATION / IT-PRAXIS

Ransomware-resistant backups for small businesses – 3-2-1-1-0 explained

A backup that the production server can freely delete is not a very trustworthy backup. This guide shows how small businesses can build several protection layers without unnecessary complexity.

PROBLEMANALYSELÖSUNGBETRIEB

3-2-1

Keep three copies, on two different media types, with one copy outside the primary environment.

3-2-1-1-0

Add at least one offline or immutable copy and aim for zero untested backup errors through regular restore tests.

Hyper-V exports

Our free Hyper-V export approach can create an additional copy, but it should not be the only backup generation.

Immutable storage

Immutable backups make it harder for ransomware to encrypt or delete the backup itself.

A NAS is not automatically safe

A NAS on the same network is convenient but not automatically protected from compromised credentials or SMB attacks.

Backup accounts

Backup credentials should have limited privileges. A compromised production server should not automatically have permission to delete every backup.

Restore tests

Successful backup logs are less important than successful restores. Test files, databases and complete VMs regularly.

Conclusion

Good backups are separated, multiple, preferably immutable and demonstrably recoverable.

Praxis-Merksatz: Gute Administration besteht aus nachvollziehbaren Schritten, dokumentierten Änderungen, Backups und einem getesteten Rückweg.
About Sille-Solutions