The 3 2 1 rule
The classic rule is to keep three copies of the data, on two different types of storage, with one copy off site. Because attackers now target backups first, it is often extended: one copy offline or immutable (it cannot be changed or deleted, even by an administrator), and zero errors when restores are tested.
What to back up
Servers and databases, but also SaaS data. Microsoft 365, Google Workspace and most SaaS providers work under a shared responsibility model: they keep the service running, but recovering data deleted by mistake or by an attacker is often limited and is largely the customer's responsibility.
How often and how fast
Backup frequency should follow the RPO defined in the business continuity plan, and the restore process must meet the RTO. A backup that has never been restored is an assumption, not a guarantee.
Protecting the backups
Backups should be encrypted, stored with separate credentials protected by MFA, and monitored for unusual deletions. During a ransomware attack, they are often the difference between recovering in days and paying a ransom.
Where it shows up in compliance
ISO 27001 requires backups to be made and tested according to a backup policy (Annex A 8.13). The ENS, NIS2 and DORA also require backup and recovery measures.




