Three, two, one — and what it actually costs
The rule is quoted everywhere and implemented almost nowhere, because the second half is inconvenient and the third half costs money.
11 July 20263 min readadmin
Three copies of the data, on two different kinds of media, with one of them off site. It is repeated so often that it has stopped being advice and become a slogan, and the slogan is easier to agree with than to implement.
What each number is actually for
Three copies means the live data plus two backups. Not the live data plus one backup — the point is that discovering a corrupt backup should not be the same event as needing it.
Two media is the one that gets quietly dropped. Two copies on the same NAS is one media type; so is two folders on the same disk. The purpose is to avoid a single failure mode taking both: a controller fault, a firmware bug, a filesystem problem, or a ransomware process that walks every mounted share.
One off site is the one that costs money, and it is the only one that survives the building.
The honest costs
Off-site is where the arithmetic gets uncomfortable, and it is worth doing openly rather than discovering it later.
Cloud storage is cheap to write and expensive to read. Most object storage charges little to store and meaningfully more to retrieve — and a restore is, by definition, retrieving all of it at once. The monthly cost is not the number that matters; the number that matters is what a full restore costs, and it is worth asking the provider that question before signing.
Bandwidth is the real constraint. Over a 100 Mbps upload, a terabyte takes roughly a day at full line rate, which you will not get. The first seed is the painful one, and if the initial upload cannot complete in a reasonable window then the whole plan needs rethinking rather than starting and hoping.
Rotated disks are not obsolete. For many small businesses, two external drives rotated weekly to somebody's house is a legitimate off-site copy: cheap, fast to restore from, and offline between rotations, which is a genuine defence against ransomware. Its weakness is that it depends on a person remembering, which is why the rotation needs to be somebody's named job rather than a good intention.
The property that is missing from the rule
The rule was written before ransomware, and it does not say anything about immutability. A backup the live system can write to is a backup the live system can encrypt.
Whatever the media, at least one copy should be unreachable from the production environment: offline between rotations, or held under a retention lock the production credentials cannot lift. That is the property that decides whether a backup survives a bad week, and it is not implied by any of the three numbers.
Then test it
Restore something on a schedule. Not a test-restore of a test file into a test folder — a real file that somebody would actually ask for, restored the way it would be on the day. Time it, and write the time down. That number is the recovery estimate; everything else is a guess.