SMB backups & DR: the 3-2-1 rule without illusions
“We back everything up” is the line that usually precedes bad news: the copy sits on the same disk, one admin knows the cloud password, and nobody has tried a restore in two years. For an office of 30–150 people, losing accounting, mail, or the website for a day is not an IT inconvenience — it stops sales and payroll workflows.
Below is a frame for SMB CEOs and IT admins: the 3-2-1 rule, RPO/RTO without jargon, a RUB cost range, and a checklist you can forward to a vendor in one email.

A backup without a restore test is insurance you never opened
The 3-2-1 rule in plain language
3 — three copies of the data: the live system plus two backups.
2 — at least two different storage types: not two partitions on one disk, and not a “Backup” folder next to the ERP.
1 — at least one copy offsite: another DC, another cloud, or offline media in a safe — so fire, theft, or ransomware in the office cannot wipe everything at once.

3 copies · 2 storage types · 1 offsite
This is not about a software brand. It is about eliminating a single point of failure (one disk, one cloud account, one admin) that kills a “nice backup” on incident day.
Backup ≠ disaster recovery
- Backup — a file or snapshot you can restore a database, disk, or mailbox from.
- DR (disaster recovery) — the agreement and procedure: within how many hours the business takes orders again, who brings services up, which stand, in what order (ERP → site → mail).
You can copy databases perfectly every night and still be down for three days without a stand, licenses, DNS, and someone with rights. The opposite mistake — “we have a cluster” with no offsite copy — burns both nodes in the same room together.
Two numbers without which backup is meaningless
RPO — how much data you can afford to lose. “No more than one hour of sales work” means copies more often than nightly, or continuous replication for critical systems.
RTO — how soon the business must run again. “By lunch tomorrow” and “within two hours” imply different budgets for hardware, people, and hosting contracts.
Write RPO/RTO for three systems: accounting / ERP, website or customer cabinet, files and mail. Everything else is secondary. Without numbers, a vendor sells “backup as a service” and you buy a feeling of calm.
Three maturity levels for SMBs
- “Folder on disk” — a copy next to the original. Helps with accidental file deletes. Does not help against ransomware, server theft, or fire.
- “Cloud without a test” — nightly backup to S3 / object storage / the hoster. Closer to 3-2-1, but if you never restore, day X reveals a corrupt archive, a wrong password, or a missing CRM database.
- “3-2-1 + restore drill” — two backup copies on different media, one offsite, quarterly stand restore with a written protocol. That is the minimum adult level for SMBs.
Most companies of 30–150 people sit between levels one and two. Jumping to three is cheaper than it looks: you rarely need “bank grade” — you need a test calendar and a second media type.
What it costs in RUB
Downtime without recovery — an hour of site or ERP outage often costs 50–200+k RUB in lost revenue and payroll (depends on turnover); a full day reaches hundreds of thousands to millions plus broken deals. Same logic as in our downtime cost breakdown.
A solid SMB 3-2-1 setup — launch and configuration often 80–400k RUB (data volume, ERP, site, mail) plus offsite storage 3–25k RUB/month.
Quarterly restore drill — half a day of engineer time; cheaper than any “surprise Sunday” with a dead database.

One lost day often costs more than a year of proper offsite storage
Account separately for ransomware: if the “backup” is reachable with the same domain rights as the infected server, an attacker can wipe originals and copies. Offsite storage plus limited delete rights on archives is part of 3-2-1 — not paranoia.
What to back up first
- Accounting databases (1C and equivalents) and configurations.
- Website / customer cabinet / CRM — code + DB + uploads.
- File shares with contracts and scans.
- Mail and calendars — if deals live there.
- Access secrets: not in the same world-readable archive, but in a password manager with a successor.
Access infrastructure (VPN, keys) must survive an admin change — see corporate VPN risks and private VPN: restoring a server is not the same as being safe if keys and offboarding are unclear.
Red flags
- “We have a backup” — but no restore for over a year.
- Copy on the same disk / same NAS as the ERP.
- One person knows the cloud password; they go on leave — no plan B.
- Archive misses CRM DB / site uploads / mail — only the “system disk”.
- No retention window: yesterday’s backup is overwritten, corruption noticed a week later.
- Vendor contract has no RPO/RTO — see the CEO IT contract checklist.
3-2-1 and DR checklist for SMBs

Seven gates: any red item means the backup is not ready for an incident
- RPO and RTO written for ERP, site/cabinet, files, and mail.
- Three copies: live plus two backups.
- Backups on two different storage types (not two folders on one disk).
- An offsite copy outside the office / primary DC.
- Delete rights on archives limited; ransomware cannot reach every copy.
- Quarterly restore drill on a stand with date and owner.
- IT/hosting contract: what is backed up, retention, who restores in an incident.
Bottom line
SMB backups and DR are not a nightly-copy checkbox. They are the 3-2-1 rule, two numbers (RPO/RTO), and regular proof that a copy can bring the business back. A cheap backup without a restore test costs more than a proper setup — the bill shows up on incident day.
Need a review of your current setup or a 3-2-1 rollout for your systems — request a backup & DR audit. Ongoing infrastructure care lives under DevOps services.
Related services
Executive questions on backups and DR
Three copies of the data (production plus two backups), at least two different storage types or media, and at least one copy offsite (another cloud, DC, or offline media). It is not a checkbox in an admin panel — it is the minimum insurance against disk failure, fire, ransomware, and human error.
A backup is a copy you can restore files or a database from. DR is the plan and setup so the business runs again within an agreed time: who brings services up, which staging site, in what order, and what “done” means. Without a restore test, a backup often fails on the day of an incident.
RPO is how much data you can afford to lose (for example, no more than one hour of work). RTO is how many hours or days until the business must run again after an outage. Those two numbers drive backup frequency and the recovery budget; without them, “we back up every night” is a guess, not a decision.
An hour of website or accounting downtime often costs tens to hundreds of thousands of RUB in revenue and payroll; a full day without the database can reach hundreds of thousands to millions plus deal slip and reputation damage. Building and testing 3-2-1 is usually cheaper than one such incident. Price downtime the same way as in our downtime-cost guide.
At least once a quarter, run a restore drill on a separate stand: bring up a copy of the database or files, sign into accounting or the site, check a checksum or a fresh record. A green status in a panel without a restore test is false calm. Record the test date and who ran it.
Want to apply this in practice?
Tell us about your system — we’ll propose a work plan and the metrics worth fixing in an SLA/SLO.
Related articles
Security in 2026: Why VPNs are Obsolete and You Need Zero Trust
Traditional VPNs can no longer cope with modern threats. We explain why corporate networks must transition to Zero Trust Architecture (ZTA).
Read ArticleHow NineLab Built a Corporate SD-WAN Platform
Experience building a reliable and secure network infrastructure: VLESS/Reality encryption, load balancing, fault tolerance, and 900 Mbit/s on a standard VDS.
Read ArticleCorporate VPN: Why Public Services Are Dangerous
Corporate VPN vs consumer VPNs: data-leak and compliance risks of public clients, control over keys and logging, and why a dedicated, auditable stack matters for remote work in 2026.
Read ArticleComplete DDoS Protection: L3, L4, and L7 Attacks
DDoS across OSI layers: how L3, L4, and L7 attacks differ, why a single appliance is rarely enough, and how to combine scrubbing, WAF, and app architecture for resilient services.
Read Article