There is a single measure that turns a catastrophic cyberattack into a merely bad day: a backup that works. When ransomware encrypts all of your files, the question is no longer how to prevent it, but whether you can get back on your feet without paying.

The 3-2-1 rule is the standard that answers this question. It is simple to understand, and many businesses believe they apply it when they are actually missing the very element that matters most.

The 3-2-1 rule at a glance

The 3-2-1 rule applied to an SME. The third point is the one most often missing, and it is the one that protects against ransomware.

Why does this rule exist?

Each number answers a specific way of losing everything. It is not an arbitrary recipe, it is a response to three different failure modes.

Three copies answer hardware failure. A hard drive fails without warning. If your only backup sits on that drive and it dies on the same day your server does too, you have nothing left. Redundancy covers this risk.

Two different media answer systemic failure. Two drives bought on the same day, of the same model, age in the same way and often fail within a few weeks of each other. Above all, two copies stored in the same building disappear together in the event of a fire, water damage or theft.

One offsite copy answers cyberattack and disaster. This is the decisive point, and the one that SMEs neglect the most.

The mistake that cancels out everything else

Ransomware does not only encrypt the computer it infects. It actively seeks out everything reachable from that machine: network drives, servers, connected external disks, shared folders, and often synchronised cloud spaces.

A backup that stays permanently plugged in is not a backup

The external drive left connected to the server "so the backup happens on its own" will be encrypted along with everything else. On the morning of the attack, the business discovers that its backups are just as unusable as its files. A copy must be disconnected, or stored with a third party with protection against deletion.

The same logic applies to synchronisation tools. OneDrive, Dropbox and Google Drive faithfully copy whatever happens on your machine. If your files are encrypted locally, the encrypted version travels up to the cloud and overwrites the good one. These services generally keep a version history, which can sometimes save the situation, but it is limited in time and does not amount to a backup strategy.

What the Swiss situation shows

Ransomware remains a constant threat for Swiss organisations. In the second half of 2025, 57 ransomware-related incidents were reported directly to the National Cyber Security Centre, with the Akira variant being the most widespread in the country.

These figures only count reported cases. Many SMEs report nothing, whether out of unawareness or for fear of reputational damage. The real scale is therefore higher.

What matters to an owner is not the number of attacks, but their consequence. A business whose backups work is back up within days. A business with no usable backup faces a choice no business owner wants to make: pay a ransom with no guarantee of recovering anything, or lose its history.

How do you put the rule into practice?

Here is a realistic setup for an SME with five to fifty employees. If your headcount falls outside this range, our action plan by company size shows where to place backups in your order of priorities.

CopyWhereFrequencyRole
Copy 1Your working data, on the server or the workstationsContinuousThe original
Copy 2External drive or NAS, on your premisesDaily, automaticFast restore after a failure or deletion
Copy 3Online backup service, or a drive stored elsewhereDaily or weeklyProtection against ransomware, fire, theft

Three requirements matter just as much as the number of copies.

Automation. A backup that depends on someone remembering to plug in a drive on Friday evening eventually stops happening. Anything that relies on human memory sooner or later fails.

Monitoring. Set up an alert for failures. The most common scenario is not the absence of a backup, it is a backup that fails silently for months without anyone noticing.

Immutability, if your provider offers it. Some plans let you lock backups for a set period: even an attacker who has your credentials cannot modify or delete them. This is currently the best protection available, and it is becoming more widespread.

The test that beats every audit

Once a year, ask for a full restore of an important folder, and time the operation. This checks three things at once: that the backup exists, that it is usable, and how long your business would remain at a standstill. Many owners discover at this point that the restore would take several days.

This timing exercise has a use that goes beyond the technical side: it gives you the real recovery time your business would have to meet. It is one of the elements recorded in an incident response plan, the one- to two-page document that describes who does what on the day files stop opening.

What about data protection?

Backups are not merely a good technical practice. Data protection law requires appropriate measures to ensure the security of personal data, and availability is part of that: permanently losing your clients’ data is a breach of their protection, not just an internal problem.

Two points of caution accompany this obligation. Your backups contain personal data, so they must be encrypted and access to them restricted. And if your backup provider is based abroad, that transfer must rest on a valid legal basis. These requirements are detailed in our article on FADP obligations for SMEs.

To gauge your overall level of protection, the cyber check-up devotes several questions to backups and testing them. The other priority measures are grouped in the Best practices pillar.