News
15 min read

The 3-2-1 Backup Strategy Against Ransomware: What Mid-Sized Businesses Often Get Wrong

Learn how to protect your business effectively against ransomware extortion with the 3-2-1 backup strategy, offline backups, and immutable storage.

Diagram of the classic 3-2-1 backup method with three data copies on two media types and one off-site copy.
The classic 3-2-1 backup principle spreads data across local media and external storage to absorb hardware failures.

The new threat landscape: Why mid-sized businesses are in the crosshairs

Cyberattacks on German companies hit an alarming record level in 2025. According to a recent analysis by the Google Threat Intelligence Group, the number of affected firms whose sensitive data was published on the dark web rose by a spectacular 92 percent compared to the previous year[1]. That means the threat in Germany is growing more than three times as fast as the European average. If you think hackers are only after the big DAX-listed corporations, you are badly mistaken: a full 96 percent of the published victims in Germany are companies with fewer than 5,000 employees[1]. So mid-sized businesses are no longer on the fringe but squarely at the center of attackers' attention. Just how dangerous this trend can be for your company becomes clear when you look at the typical way ransomware unfolds in a mid-sized business.

Why cybercriminals prefer mid-sized businesses

Mid-sized companies are so attractive to modern hacker groups like SAFEPAY or Qilin for three key reasons[1]. First, the dangerous belief still persists in many executive suites that the company is too small to be of interest to criminals. But attackers scan the internet fully automatically for security gaps. They don't pick their targets by hand; they exploit every open door. Second, the German language no longer offers protection against phishing campaigns. Thanks to advanced, AI-assisted translation tools, forged emails and malware look completely authentic today. Third, mid-sized businesses often serve as an entry point into the supply chains of large corporations[1]. Anyone who manages sensitive customer data or holds direct system access as a supplier becomes the perfect lever for attackers.

Sector or industryShare of ransomware victims
Manufacturing and industrial production23 %
Legal and consulting services14 %
Construction and engineering11 %
Retail10 %

For you as a managing director or IT lead, this means a clear duty to take active precautions. Traditional defense methods are no longer anywhere near enough to fend off highly professional extortion campaigns. The classic 3-2-1 backup rule does form a solid foundation for your defense, but if you don't make your backups completely unreadable to ransomware or never test your recovery processes under real conditions, your protection is worthless when it counts. To monitor your IT infrastructure around the clock and close vulnerabilities proactively, holistic cybersecurity is the only reliable option.

The foundation: How the classic 3-2-1 backup rule works

When it comes to defending against extortion software, your backup is the last and most important line of defense. But mid-sized businesses often operate under a false sense of security. Many managing directors and IT leads rely on outdated processes without realizing how devastating an attack actually plays out. Before you modernize your defenses, you need to master the basics. The classic 3-2-1 backup rule has been the gold-standard minimum for data protection for years. It was developed to prevent data loss from hardware failures or disasters, and it still forms the backbone of any solid IT security architecture today.

The three pillars of classic data protection

The formula behind the 3-2-1 rule is elegantly simple and easy to implement in a company. It distributes your data across different media and locations to drive the probability of simultaneous data loss down to near zero[2]. The principle rests on a clear structure that you should implement for all business-critical systems.

  • Three data copies: In addition to the production data on your workstations or servers, you create at least two more backup copies. That means you have three identical versions of your data at any given time.
  • Two different storage media: Back up your data on different media types. If you store the first backup on a local hard drive, the second should sit on a completely different medium, for example on a Network Attached Storage (NAS) or in cloud storage. This protects you against the failure of a single system type.
  • One off-site copy: At least one of these backup copies must be kept physically or logically outside your own corporate network and location. Traditionally this was done with tapes; today it is usually via an encrypted cloud connection.

This distribution ensures that a local fire, a theft, or a hardware defect doesn't lead to the loss of your entire company data. For classic IT operations, this approach was sufficient for years. But if you rely on this classic structure alone in a mid-sized business today, you are playing Russian roulette with your data. Modern ransomware is built to actively search the local network for backups and to encrypt or delete them first[3]. That's why a plain standard backup without additional protection is no longer safe. You need deeper protection, the kind that modern cybersecurity services provide for your entire network.

The blind spot: Typical backup strategy mistakes in mid-sized businesses

Many managing directors and IT leads in mid-sized businesses lull themselves into a false sense of security because they back up data every day. But a conventional backup no longer automatically protects you today from the consequences of modern extortion software. According to the Bitkom study Wirtschaftsschutz 2025, in nearly one in two ransomware cases the backups were also specifically targeted or encrypted[4]. In the course of an extortion attack, professional attackers deliberately focus on taking out your last line of defense before the actual encryption of your operational systems even begins. To see how such an attack plays out in detail, read our analysis of ransomware in mid-sized businesses, which shows how criminals operate.

The three most fatal data protection mistakes

When attackers break into your corporate network, they specifically hunt for your backup systems. In doing so, they keep running into the same weaknesses in mid-sized businesses, weaknesses that make recovery impossible. If you don't fix these mistakes, your backup stays worthless when it counts.

  • Backups on the same network without physical separation: If your backup servers are directly connected to the regular company network, attackers can spread there without any trouble after the initial breach.
  • Missing write protection and a lack of immutability: If your backup files aren't write-protected or made undeletable by special technologies, the ransomware simply overwrites or deletes your data.
  • Weak access controls and overly broad admin rights: If your IT staff use the same administration accounts for the day-to-day network and the backup infrastructure, attackers take full control of your backups with just one stolen password.

To truly secure your systems, simple protection is no longer enough. You need a well-thought-out security architecture that isolates your data in an undeletable way and monitors it continuously. With professional cybersecurity for mid-sized businesses, you can detect attacks early and prevent criminals from ever reaching your valuable backups.

Making it ransomware-proof: Immutable and offline backups (Immutable & Air Gap)

Ransomware attackers learned long ago that they can only extort a ransom if the victim has no alternative to paying. For managing directors and IT leads in mid-sized businesses, this has long been about the sheer survival of their operation. That's why cybercriminals specifically target backup repositories during a ransomware attack. Statistics show that in 89 % of ransomware cases the backup systems were attacked directly[5]. If your backups sit online and freely accessible on the same network, attackers encrypt or delete them first. Without an uncorruptible copy, your operation faces a standstill. To massively strengthen your IT resilience, you need to rely on two indispensable pillars: immutable storage and physically or logically isolated backups (air gap).

Pillar 1: Immutability (immutable storage) as a digital fortress

Immutable backups (immutable storage) use the WORM principle (Write Once, Read Many). Once a backup has been written, it cannot be changed, overwritten, or deleted by anyone for a predefined period, not even by an administrator with compromised credentials[5]. This logical lock protects your data directly at the storage level. Even if ransomware takes over active administration accounts on the local network, it bounces off the immutable storage areas. This technology enables an extremely fast restore when it counts, because the data stays directly accessible without having to be physically transported.

Pillar 2: The ultimate barrier through air gapping

While immutability protects at the logical level, an air gap provides a physical or logical separation from the rest of the network. A true physical air gap means the backup medium (such as a removable drive or tape) is completely disconnected from the system after the write process and stored offline. Where there is no network connection, malware has no way in. In addition, modern cloud architectures offer a logical air gap: the data is reachable over the internet, but only through highly isolated, separate control channels and strict identity barriers that are fully decoupled from the primary company network.

  • Combination for maximum resilience: Use immutable storage for fast, daily restores and an additional offline backup (air gap) as the ultimate life insurance.
  • Strict rights management: Consistently separate the administration accounts for your IT infrastructure from the credentials for your backup systems.
  • Monitoring and alerting: Integrate your backup infrastructure into continuous security monitoring. With a professional managed service for cybersecurity, unauthorized access attempts stand out immediately, before any damage occurs.
  • Regular recovery tests: A backup is only as good as its restore. Test the real scenario at least once a quarter under real-world conditions.

Blindly relying on simple, unprotected backups is an existential risk in today's threat environment. The combination of immutable storage and an air-gap solution protects you from becoming part of a bitter statistic: after all, 17 % of affected companies were unable to recover their data even after paying a ransom[5]. With robust, multi-layered security measures, you make your company resilient against extortion attempts and keep full control of your business-critical data at all times.

When it counts: Why an untested restore is not a backup

Many companies in the mid-sized segment lull themselves into a false sense of security because their backup systems report a green checkmark every day. But when a ransomware attack actually hits, the bitter reality often surfaces: a backup that was never restored under real conditions is not reliable protection. Statistics show that in a ransomware attack, an average of 41 percent of operational production data is compromised[6]. Of that affected data, on average only 57 percent can be successfully recovered[6]. For the businesses affected, this means a permanent data loss of an average of 18 percent of their entire data set[6]. Anyone who doesn't proactively test their restore on a regular basis risks a total failure of their business-critical processes when it counts.

RTO and RPO: The decisive levers of your recovery strategy

As a managing director or IT lead in a mid-sized business, you need to precisely define how much downtime and data loss your operation can withstand. These requirements are defined through two central metrics that form the foundation of any emergency plan. Many decision-makers know these terms in theory, but have never agreed on them contractually or technically with their IT service providers, let alone validated them. Without clear specifications, any recovery after an incident like a ransomware attack in a mid-sized business is like uncontrolled gambling.

  • Recovery Time Objective (RTO): The RTO describes the maximum time span that may elapse between a system failure and the full restoration of operational readiness. It answers the question: how long can our machines, ERP systems, or email servers stand still before the economic damage becomes existential?
  • Recovery Point Objective (RPO): The RPO defines the maximum acceptable data loss, measured in time. An RPO of four hours means, for example, that the backup cycles must be so tightly spaced that in a disaster case at most the data from the last four working hours is lost.

Another often underestimated risk during recovery is the unintentional reinfection of the systems. An alarming 63 percent of all organizations run the risk of unknowingly reintroducing the malware into their production environment while recovering from a ransomware attack or a major IT outage[6]. Under the enormous time pressure of a standstill, critical steps like scanning the backups in an isolated quarantine environment or sandbox are often skipped. This causes dormant ransomware files to be backed up again directly and reactivated.

Automated recovery tests and the emergency handbook as a safeguard

To eliminate this risk, automated recovery tests are essential. Instead of manual, time-consuming spot checks, backups must be continuously spun up in an isolated environment, checked for consistency, and scanned for malware. This ensures the data is instantly ready to use and clean when it counts. A modern service like Managed IT from CAVRIX takes over this proactive validation and ensures that your backups don't just exist but actually work. This technical safeguard must be complemented by holistic cybersecurity for mid-sized businesses. Together with a clearly defined emergency handbook, this forms your company's life insurance. The document lays out exactly who initiates which steps when it counts, how communication runs, and how the systems are rebuilt in a structured way, so the agreed RTO and RPO targets can actually be met.

Holistic protection: How Managed IT and Cybersecurity strengthen your resilience

A reliable backup is indispensable, but it is only the last line of defense in your security architecture. Once cybercriminals have penetrated your systems, they deliberately try to delete or encrypt your backups too in a staggering 94 percent of cases[7]. To understand how attackers operate, it helps to look at the typical ransomware attack in a mid-sized business, which often develops unnoticed over days or weeks. A mere life ring is therefore not enough. True IT resilience in a mid-sized business requires that you prevent and detect attacks early, before they can cause damage. A well-thought-out concept combines preventive protection with continuous monitoring and keeps your company able to act.

Proactive prevention through automated system maintenance

Most security gaps arise not from sophisticated zero-day exploits, but from unprotected endpoints, missing security updates, and human error. This is where a professional service comes in: with Managed IT from CAVRIX, your entire IT infrastructure is monitored, maintained, and documented automatically. Security-relevant patches are applied immediately, while the system proactively scans for anomalies in the background. This massively reduces your company's attack surface, relieves your internal resources, and ensures your workstations are always up to the latest security standard. That way you take the easiest entry points away from attackers before they can set foot in your network.

24/7 threat detection for the critical moment

Since attacks often happen at night or on weekends, protection during regular office hours is not enough. With the Cybersecurity service, you benefit from seamless monitoring by a Security Operations Center (SOC) that is active around the clock. Modern detection systems analyze suspicious activity in real time and respond immediately to automatically isolate affected systems when it counts. This proactive protection ensures that an isolated security incident doesn't turn into an existential wave of encryption. For managing directors and IT leads in mid-sized businesses, this means the certainty that experts are watching over the security of the digital infrastructure at all times.

  • Prevention: Through automated updates and seamless patch management as part of Managed IT, you close known security gaps early.
  • Early detection: Real-time monitoring through Cybersecurity identifies suspicious behavior and stops attackers before they can cause damage.
  • Compliance assurance: Integrated compliance modules help you meet legal requirements like the NIS2 directive and minimize your liability risks.
  • Emergency rescue: An untouchable backup secured offline or in an immutable way enables a fast restore of your data if all other layers of protection have been breached.

This interplay is complemented by the Compliance service offering, which supports you in meeting legal requirements without additional administrative effort. Through the intuitive Command Center, you keep an eye on your current security status and upcoming tasks at all times. You manage your IT security and your compliance records simply through everyday communication tools like Teams or Slack and receive real-time alerts for critical incidents. With this holistic approach, IT security turns from a tedious obligation into a real competitive advantage that positions your company to be resilient for the future.

Frequently asked questions

What does the classic 3-2-1 backup rule say?

The classic rule says you should keep at least three copies of your data. These should be secured on two different storage media, and one copy of them must be kept at an external location, for example in the cloud or an external data center.

Why is the normal 3-2-1 rule no longer enough against ransomware?

Modern ransomware specifically hunts the network for backup systems and encrypts or deletes them first. If your backups are permanently connected to the network and writable, they get encrypted along with everything else when it counts. That's why backups must be immutable or offline.

What is an immutable backup?

An immutable backup uses the WORM principle (Write Once, Read Many). Once written, backup data cannot be changed, overwritten, or deleted by anyone, not even by administrators with compromised credentials or by malware, for a defined period.

What does air gap mean in the context of data protection?

An air gap refers to the physical or logical separation of the backup medium from the production network. Since there is no direct connection, ransomware cannot access the backup. Examples are offline-stored tapes, removable drives, or logically isolated cloud targets.

How often should my company test the restore?

Recovery tests should be carried out at least quarterly, and for critical systems even monthly. Only this way do you ensure that the backups work flawlessly when it counts and that the planned recovery time (RTO) can actually be met.

Which mid-sized industries are especially affected by ransomware?

According to recent reports, around 23 percent of all ransomware leaks in Germany fall on the manufacturing sector. Service providers like law firms and the construction industry are also increasingly in focus, since they manage highly sensitive data that lends itself perfectly to extortion.

Sources

  1. it-administrator.de
  2. secjur.com
  3. opti9tech.com
  4. graudata.com
  5. veeam.com
  6. veeam.com
  7. sophos.com

Where does your company stand?

30 minutes, free, no commitment. We show you where you stand.