RAID is not a backup: the 3-2-1 rule for companies

By Ing. Hani Hussein, B.Sc. · updated on · 5 min read

"We have a RAID, our data is safe." I hear this sentence regularly, usually shortly before data is lost. A RAID protects against exactly one event: the failure of a disk. It does not help against deletion, encryption by ransomware, theft, fire or a faulty controller. This guide explains what makes a real backup.

What RAID can and cannot do

A RAID mirrors or distributes data across several disks so operations continue when one disk fails. That is important for availability, but every change is written to all disks immediately. If an employee accidentally deletes a folder or a trojan encrypts the files, it happens on all disks at the same time. The RAID has then done exactly what it was built for.

Add to that risks a RAID does not cover at all: a faulty controller, a lightning strike, water damage, theft of the device or an error during a rebuild in which a second disk fails. A RAID is an availability tool, not a backup.

The 3-2-1 rule

The rule is old, but it works:

  • 3 copies of your data: the original plus two backups
  • 2 different media or systems, for example NAS and cloud storage, so one fault does not hit both
  • 1 copy off site, so that fire, theft or water damage do not destroy everything

Modern addition: one copy should be immutable (snapshots or immutable storage) so that ransomware with access to the network cannot encrypt the backup as well.

What a backup really needs

  • Automatic: backups that someone has to start manually get forgotten
  • Versioned: several states over weeks, not just the last copy, otherwise an error is backed up as well
  • Encrypted: especially with cloud storage and external disks
  • Separated from the network or immutable: ransomware specifically searches for reachable backups
  • Monitored: an error message must reach someone who reacts
  • Tested: perform a real restore at least quarterly and note how long it takes

Typical mistakes from practice

The external disk is permanently attached to the server and gets encrypted along with everything else during a ransomware attack. The backup has been failing for months, but the message lands in a mailbox nobody reads. Cloud synchronisation is considered a backup but syncs the encryption too. And the classic: nobody has ever tried to restore anything.

Recommendation for small businesses

A NAS with snapshots as the first backup layer, plus an encrypted, versioned backup to cloud storage or to a second NAS at another location, for example with Restic, Borg or the backup software of the NAS vendor. Servers are additionally backed up as a whole (Proxmox Backup Server, Veeam) so they run again within hours instead of days after a failure. And a calendar entry for the quarterly restore test.

Frequently asked questions

Is OneDrive or Google Drive enough as a backup?

No. Synchronised cloud storage transfers deletions and encryption immediately. It offers a recycle bin and versions, but no independent, controlled backup. A separate backup of cloud data is mandatory.

How long should backups be kept?

Daily states for two to four weeks, weekly for a few months, monthly for a year. For accounting data, statutory retention periods of seven years apply additionally.

What does a proper backup cost?

For a small business: a NAS from about €600, cloud storage from a few euros per terabyte and month, plus the setup. I offer NAS setup with backup concept from €290.

Need help implementing this? I implement it for you, remotely or on site in Vienna, at a fixed price or based on effort. Send request →

Ready to discuss your project?

Describe your project in a few sentences. You will receive an assessment with effort and price within one business day.