Protecting your business data is not just good practice. For many organisations it decides whether they survive an incident. Accidental deletion, hardware failure, software bugs, fire, flood and ransomware all threaten the information you depend on. This guide explains how modern backup works and how to design a strategy that actually restores when you need it.
Key takeaways
- Decide your RTO (how fast you must recover) and RPO (how much data you can afford to lose) before choosing technology.
- Follow the 3-2-1-1-0 rule: 3 copies, 2 media types, 1 offsite, 1 offline or immutable, 0 errors on test restores.
- Combine fast disk backups for day-to-day restores with offline tape or immutable storage for ransomware protection.
- Test restores regularly. A backup you have never restored is only a hope.
What is data backup?
Data backup is the process of making copies of your data so that it can be restored if the original is lost, damaged or encrypted. Backups run on a schedule, are stored in one or more locations separate from the original, and are kept for a set retention period.
You can build your own backup system from existing infrastructure (backup software, disk, tape and cloud), or use a managed Backup as a Service (BaaS) offering. Either way, the principles below apply.
Types of backup
| Type | What is copied | Backup speed | Restore speed | Storage used |
|---|---|---|---|---|
| Full | Everything, every time | Slowest | Fastest: one set to restore | Highest |
| Incremental | Changes since the last backup of any type | Fastest | Slower: needs the full backup plus every incremental | Lowest |
| Differential | Changes since the last full backup | Medium, and grows during the week | Medium: full plus the latest differential | Medium |
| Synthetic full | A new full backup built from the last full and later incrementals | Fast (no need to read production data again) | Fast | Medium |
Most modern backup software uses a forever-incremental approach with periodic synthetic fulls. This keeps the load on production systems low while keeping restores quick.
Other methods you will come across
- Snapshots: near-instant, point-in-time copies taken by a storage array or hypervisor. They are great for quick rollback, but they are not a backup on their own because they live on the same system as the data.
- Replication: continuously copies data to a second system or site. It gives excellent RPO, but it also replicates deletions and corruption, so it needs to be paired with point-in-time backups.
- Continuous data protection (CDP): journals every write so you can recover to almost any moment.
RTO and RPO: the two numbers that matter
Recovery Time Objective (RTO)
How long a system can be down before the impact becomes unacceptable. An RTO of 4 hours means the service must be running again within 4 hours of an incident.
Recovery Point Objective (RPO)
How much data, measured in time, you can afford to lose. An RPO of 24 hours means a nightly backup is enough. An RPO of 15 minutes needs far more frequent protection.
Set RTO and RPO per system, with the business. Your order processing platform might need an RTO of an hour and an RPO of minutes. A file archive might tolerate several days. These targets decide what technology you need, and how much it costs.
The 3-2-1-1-0 rule
The classic 3-2-1 rule has been extended to deal with ransomware:
- 3 copies of your data (production plus two backups)
- 2 different types of storage media, such as disk and tape
- 1 copy offsite
- 1 copy offline, air-gapped or immutable
- 0 errors, confirmed by automated verification and regular test restores
LTO tape covers several of these at once. It is a different media type, easy to move offsite, offline once ejected, and it can be made immutable with WORM cartridges.
Backup storage media compared
| Medium | Strengths | Weaknesses | Best role |
|---|---|---|---|
| Disk / backup appliance | Fast backup and restore, deduplication, instant VM recovery | Online, so exposed to ransomware unless hardened. Higher cost per TB | First-tier backups and day-to-day restores |
| LTO tape | Lowest cost per TB, offline air gap, 30-year life, portable, low power | Sequential access, slower to restore individual files | Offline copy, long-term retention, archive |
| Cloud object storage | Offsite by default, elastic, object lock for immutability | Ongoing cost, egress fees, restore time limited by bandwidth | Offsite copy, smaller data sets |
| Removable disk / USB | Cheap and simple | Fragile, easy to lose, poor at scale | Very small businesses only |
Restoring many terabytes from the cloud can take days over a typical business connection. Tape, on the other hand, can be driven or couriered back and restored locally at full speed. That is why most mid-sized and large organisations keep tape in the mix. See the benefits of LTO tape.
Making backups efficient
- Compression: reduces backup size. LTO drives compress in hardware at full speed.
- Deduplication: stores each unique block once. This is very effective for virtual machines and repeated full backups on disk.
- Encryption: protects data in flight and at rest. Use LTO drive encryption (AES-256) for tapes that leave the building, and manage the keys carefully.
- Staging: back up to disk first, then copy to tape. This keeps tape drives streaming at full speed and lets you restore recent data quickly.
Backing up different types of data
Files and file systems
File-level backup lets you restore individual files and folders. Image-level backup captures the whole volume for fast full recovery. Most tools can do both. For very large file systems, look at incremental-forever approaches and change tracking, so you don’t have to rescan millions of files every night.
Databases
Databases must be backed up in a consistent state. Use application-aware backups, or the database’s own tools (such as RMAN for Oracle, mysqldump or physical backups for MySQL, and native SQL Server backups), combined with transaction log backups for point-in-time recovery. For critical databases, pair backups with replication (for example Oracle Data Guard or MySQL replication) to meet tight RTOs.
Virtual machines
Hypervisor-level backup (VMware, Hyper-V, Proxmox) captures whole VMs efficiently using changed-block tracking, and enables instant recovery from backup storage.
SaaS applications
Microsoft 365, Google Workspace and Salesforce do not provide full backups for you. Protect them with a dedicated service such as Keepit.
Managing and testing backups
- Monitor every job and act on failures the same day.
- Test restores regularly: individual files monthly and a full system at least once a year.
- Document the recovery process so someone other than the backup administrator can follow it.
- Review retention periods against legal, regulatory and business requirements.
- Keep backup systems on separate credentials, with multi-factor authentication, away from your main domain.
Backup and disaster recovery
Backup is one part of disaster recovery. DR planning also covers where you will run systems, who does what, and in which order services come back. If ransomware is your main concern, read how tape protects against ransomware.
Our storage team can review your RTO/RPO, retention and media mix, and recommend improvements.