← Back to News

Backup is not just backup: the 3-2-1 principle in practice

“We have a backup.” — that’s a sentence you’ll hear in most practices today, fortunately. What it actually means varies enormously. Sometimes it’s a USB stick carried into another room once a week. Sometimes a NAS under the reception desk. Sometimes a cloud where no one knows whether the data will ever come back. A backup is only as good as it can be restored when it matters. The BSI has been recommending a simple principle for years: 3-2-1.

What 3-2-1 means

  • 3 copies of your data exist in total (the original plus two backups).
  • 2 different media are used (e.g. a NAS disk and an encrypted cloud copy — not twice the same kind).
  • 1 copy lives physically off site — protected from fire, water, theft and ransomware.

It sounds dry. But it’s worded precisely, because the most common real losses — fire, water damage, targeted theft, ransomware — wipe out all the backup copies at the same location at the same time.

Why a NAS on its own is not a backup

A network-attached storage in the server cabinet is great — fast, comfortable, local. But:

  • If the power line takes a hit, server and NAS are dead together.
  • If ransomware hits the server, it usually hits the NAS too, because the NAS is reachable to the server as a network drive.
  • If the practice burns, server and NAS burn.

A NAS is a secondary storage solution — and a good first step. But it does not replace the off-site backup. That’s exactly what the “1” in 3-2-1 addresses.

The 3-2-1 backup rule is recommended by Germany’s Federal Office for Information Security (BSI) as an effective protection against ransomware and hardware failure.

What the BSI says

The BSI IT Baseline Protection module “CON.3 backup concept” provides the framework: regular backups, a redundant data set, short-term recovery of operations after a loss. The implementation notes explicitly mention separating backups from the production system and protecting backup media against unauthorised access. For private individuals too, the BSI now recommends the 3-2-1 logic.

Special case: medical practices and §75b SGB V

For statutory health insurance physicians in Germany, the IT security guideline under §75b SGB V comes on top. It regulates retention periods for patient data, requires backups to be encrypted, and demands that backup strategies are documented. In practice:

  • Store backups encrypted — not just in transit, but at rest on the medium.
  • Honour retention periods (for medical documentation typically 10 years, in special cases longer).
  • Document the backup and restore processes in writing — as part of your IT security concept.

The often-forgotten piece: the restore test

This is where most practices fail when the worst happens: the backup ran every night. But no one tested in the last twelve months whether it can actually be restored. We see it regularly — and it is alarming. Our recommendation:

  1. Quarterly we restore a state from a backup — to an isolated system, without touching the production system.
  2. Document the result: what was tested, how long it took, what worked, what didn’t.
  3. On anomalies: adjust the strategy, retest.

A restore test per quarter is a laughably small effort compared to the risk — and the difference between “we had a backup” and “we’re back online in two hours”.

How we set this up

As part of our Backup-as-a-Service we build the off-site component on our own Synology systems in Germany, end-to-end encrypted. Locally — depending on size and need — we use a NAS or a second storage unit next to the server. Restore tests are carried out and documented quarterly under managed-service contracts. Day-to-day practice life isn’t affected — the backup runs at night.

Minimum standard for every practice

If you take nothing else from this article, take this:

  • At least three data copies (original + two backups).
  • At least one of them off site (not in the same room, not in the same fire compartment).
  • All backups encrypted.
  • Test restore at least once a quarter.

That’s not too much to ask — and it can be the difference between a bad morning and a shuttered practice.

Sources

  1. BSI: IT Baseline Protection Compendium, module CON.3 backup concept. bsi.bund.de · PDF
  2. BSI: Implementation notes for module CON.3 backup concept. bsi.bund.de · PDF
  3. Datenschutz und Gesundheit: 3-2-1 backup strategy — Essential data protection for medical practices. datenschutzundgesundheit.de

Related articles

Backup that holds up when it matters.

Our Backup-as-a-Service on our own Synology systems in Germany — with documented restore tests.

Visit the cloud page