Skip to content

Cybersecurity 3-2-1 backup rule

A Copy Is Not a Backup

When you open your computer and click on OneDrive or Dropbox, do you enter a separate username and password? For most people the answer is no. That convenience has a name - Single Sign-On. And if ransomware hits, it may be the reason your backup is gone too.

Illustration for the article: A Copy Is Not a Backup
When you open your computer and click on OneDrive or Dropbox, do you enter a separate username and password? For most people the answer is no. That convenience has a name - Single Sign-On. And if ransomware hits, it may be the reason your backup is gone too.

Let me ask you something.

When you open your computer in the morning and click on your email – do you have to enter a separate username and password to get in? What about when you open Dropbox or OneDrive – does it ask you to log in again with different credentials?

For most people the answer is no. You signed into your computer once and everything opened. That convenience has a name: Single Sign-On. SSO.

And if your business ever gets hit by ransomware, that convenience may be the reason your “backup” is gone too.

Cloud Storage Is Not a Backup

This is one of the most common and most dangerous misconceptions I see in small and mid-sized businesses: the belief that because their files are in Dropbox, OneDrive, Google Drive, or a similar cloud storage platform, they are backed up.

They are not.

Cloud storage that comes bundled with your email platform or enabled through a company device policy is a file sharing tool. It exists to let people access documents from multiple devices, collaborate with colleagues, and move files between locations. It is genuinely useful for all of those things.

It is not a disaster recovery solution. And the difference between those two things becomes catastrophic the moment something goes wrong.

What Actually Happens When Ransomware Hits

I want to be clear that I am drawing on research, industry knowledge, and conversations with people who have been through this – not personal firsthand experience with a ransomware event. But the picture that emerges from all of that is consistent enough to be worth understanding.

When ransomware hits a business, the instinct is to think about the infected computer. Wipe it, reimage it, move on. But that is not how modern ransomware works. Attackers are not going after the operating system on one PC – they are going after the data that keeps the business running. The files. The records. The systems. Because that is where the leverage is.

Here is what that means in practice:

Everything connected is suspect. In a ransomware environment, you have to treat every connected source as a potential point of infection until it has been cleared and verified. That means communication tools, messaging apps, servers, shared drives – all of it is potentially compromised until proven otherwise. You cannot assume anything attached to the network is clean.

The cloud sync works against you. This is where the SSO problem becomes real. If ransomware encrypted the files on your local machine, and those files were syncing to OneDrive or Dropbox through the same account you used to log into your computer – the encrypted versions sync too. The cloud now has a copy of the encrypted, unusable files, potentially overwriting the clean versions that were there before. Your backup just became another copy of the damage.

You have to plan as though you are getting nothing back. This is the mindset shift that matters most. Not as a worst-case scenario – as the baseline assumption. If you plan for total loss and you end up recovering something, that is a bonus. If you plan for a partial recovery and you end up with nothing, that is a crisis with no floor.

The SSO Problem Explained

Let me come back to the sign-on question from the beginning, because this is the moment where the cloud storage misconception usually breaks open for business owners.

You sign into your computer with your email address and password. That same account – that same set of credentials – is attached to your email, your OneDrive or Google Drive, your calendar, your contacts, and potentially other business applications that are configured to use the same login.

If an attacker gets into that account, they do not just have your email. They have access to everything that account touches. The cloud storage you thought was safely separate is accessed through the exact same door the attacker just walked through.

Stay Ahead of Technology Risk

Practical, no-jargon insights on cybersecurity, resilience, and IT strategy - built for business leaders, not engineers.

A synced drive connected to a compromised account is not a backup. It is another surface of the same attack.

The 3-2-1 Rule – In Plain Language

The standard that actually protects businesses from total data loss is called the 3-2-1 backup rule. It is not complicated. Here is how I explain it to business owners:

3 total copies of your data.
Your working files, plus two additional copies. Not one. Three.

2 different types of media.
Do not keep all three copies on the same type of storage. A local server and a cloud backup service use different media. A hard drive and a tape backup use different media. The logic is simple: if one type of storage fails or gets compromised, the other type still has a copy.

1 copy off-site.
This is the one most businesses skip – and the one that matters most when something goes wrong at the physical location.

Here is how I make this real for business owners: most of you have a safe at home or a safe deposit box at the bank. You use it for important documents, insurance records, things you cannot afford to lose. I ask your IT team to make two copies of your critical business data every few weeks and either drop one at the bank or take one home and put it in that safe. It does not have to be complicated. It just has to be somewhere that ransomware cannot reach – physically disconnected, off the network, in someone else’s hands.

That is what an air gap means. The backup that survives is the one the attacker could not get to because it was never connected to begin with.

What a Real Backup Actually Requires

A purpose-built backup solution – as opposed to a file sync tool – does several things that Dropbox and OneDrive do not:

It keeps versioned copies of your data, meaning it can restore files from before the encryption happened, not just the most recent version. It stores those copies in a separate environment with separate credentials, so a compromised SSO account does not touch it. It is monitored and verified, so someone knows whether the backup is actually running and whether a restore would actually work. And it is tested – because a backup you have never practiced restoring from is not a backup. It is a hope.

The SOC 2 certified, encrypted, purpose-built off-site storage that lives in someone else’s data center – that is what the third copy in the 3-2-1 rule looks like. It is not the same thing as the Dropbox folder on your taskbar.

The Question Worth Asking Today

If ransomware hit your business tonight and you woke up tomorrow with no access to any system connected to your network – where is the copy of your data that survives that?

Not the synced copy. Not the cloud folder connected to your email account. The copy that was never on the network. The one with its own credentials. The one in the bank or in the safe or in a purpose-built off-site facility with a recovery process you have actually tested.

If you cannot answer that question immediately, you do not have a backup. You have copies.

And copies are not the same thing.

Kelly Hansen is the author of The IT Dilemma: Why Good Businesses Fail During Cyberattacks, Outages, and Technology Disasters – and How to Prevent It. Have a question about your own environment? Reach out: Contact, or connect with me on LinkedIn.

Key Takeaways

  • Cloud storage that came with your email is a file sharing tool — not a disaster recovery solution
  • If ransomware encrypted files syncing to OneDrive the encrypted versions sync too — your backup just became another copy of the damage
  • A synced drive connected to a compromised SSO account is not a backup — it is another surface of the same attack
  • The backup that survives is the one the attacker could not get to because it was never connected to begin with
  • A backup you have never practiced restoring from is not a backup — it is a hope