Ransomware and the 3-2-1 Rule: Why We Have Backups Isn't Enough

Ransomware is now involved in the vast majority of small business breaches. Here is how a modern attack actually works, and the concrete backup strategy that lets you tell the attackers no.

Picture this. You come in on a Monday, pour your coffee, and open your laptop. Every file has a weird new extension. Instead of your quarterly spreadsheet, there is a text document on your desktop with a countdown timer and an amount in Bitcoin. Your accounting software will not open. Your customer database is gibberish. And somewhere, a stranger is deciding how much your business is worth to you.

That is ransomware, and if you run a small business, it is very likely coming for you specifically. According to the 2025 Verizon Data Breach Investigations Report, ransomware showed up in 44% of all breaches, up sharply from 32% the year before. But here is the number that should make you sit up: 88% of breaches at small and medium businesses now involve ransomware, compared to just 39% at large enterprises. You are not too small to be a target. You are the preferred target.

Let me walk you through what ransomware actually is, how a modern attack really unfolds against a business like yours, and the one defense that matters most when everything else fails. Because it will, occasionally, fail.

What ransomware actually is

Ransomware is malicious software (malware) that sneaks onto your computers and encrypts your files. Encryption means it scrambles your data using a secret key, turning readable documents into meaningless noise. The only way to unscramble it is with that key, and the attackers hold the key hostage. They demand a payment, usually in cryptocurrency because it is hard to trace, in exchange for giving it back.

Think of it like a burglar who breaks into your office, puts everything you own into a safe with an unbreakable lock, and then slides a note under the door: pay me and I will tell you the combination. Except the burglar also photographed every file on the way in, which matters more than you would think. We will get to that.

The reason this business model exploded is simple economics: it is profitable, low-risk for the criminal, and it scales. The FBI's 2024 Internet Crime Report logged 3,156 ransomware complaints and called ransomware the most pervasive threat to critical infrastructure, part of a record $16.6 billion in reported cybercrime losses that year. And those are only the incidents people reported.

Why small businesses are the target

Let me be real with you. Attackers are not choosing you out of spite. They are choosing you because the math works.

A big enterprise has a security team, monitored networks, tested backups, and lawyers. You probably have one person who is "good with computers" and a lot of trust. That gap is the whole business plan. Small businesses hold genuinely valuable data (customer records, payment details, health information) but defend it with a fraction of the resources. You are the soft target with real assets in the safe.

The costs are not small-business-sized either. IBM's 2025 Cost of a Data Breach Report put the average extortion or ransomware incident at $5.08 million globally. Sophos found that the average recovery cost, not counting the ransom, is now around $1.53 million. For a small business, a number like that is not a bad quarter. It is the end.

How a modern attack actually unfolds

Most people imagine ransomware as a single dramatic moment: click a bad link, screen locks up, done. The reality is slower, quieter, and much scarier. A modern attack has stages, and the encryption you eventually see is the last one, not the first.

Stage 1: Getting in the door

The attacker needs a way in. The two most common front doors are phishing (a fake email that tricks someone into entering their password or opening a malicious attachment) and stolen credentials (a valid username and password the attacker bought or guessed). If you want to understand how cheap and easy the second option has become, read up on credential stuffing, where criminals take passwords leaked in old breaches and try them against your accounts on the assumption that people reuse them. Spoiler: people reuse them.

Often the entry point looks mundane: an email that appears to come from a vendor or the boss, the same playbook behind business email compromise, a scam that has cost businesses billions. One click, one reused password, and the attacker is standing inside your network wearing a legitimate employee's badge.

Stage 2: Looking around and spreading

Here is the part most articles skip. The attacker does not encrypt anything yet. First they explore. This is called lateral movement, which just means quietly hopping from the one computer they compromised to other machines, servers, and accounts. They are mapping your business: where the important files live, where the backups are, who the administrators are.

This phase can last days or weeks. They are patient because patience pays. They especially want to find your backups, so they can neutralize your escape route before they spring the trap.

Stage 3: Stealing the data (this is the twist)

Before encrypting anything, modern attackers copy your data and send it to themselves. This is called data exfiltration. Remember the burglar who photographed your files on the way in? This is that.

Why bother, if they are about to lock you out anyway? Because it gives them a second form of leverage, and this is the shift that made ransomware so much nastier. It is called double extortion: pay us to unlock your files, and pay us again (or instead) so we do not publish your customer data, financials, and emails on the internet. Suddenly your good backups are only half a solution. You can restore your files, but the attacker still has your data and a website where they threaten to leak it.

Stage 4: The encryption and the demand

Only now, once they have your data and have sabotaged your backups, do they trigger the encryption. Everything locks at once, usually overnight or over a weekend when nobody is watching. You arrive to the countdown timer.

And then the real clock starts, because the ransom is not the expensive part. The downtime is. The average ransomware attack now causes around 24 days of downtime. Picture your business frozen for three-plus weeks: no invoicing, no fulfillment, no payroll, no customer service. That is the real weapon.

Why "we have backups" so often fails

This is the heart of it, so slow down here.

Almost everyone says the same thing when I bring up ransomware: "We're fine, we have backups." I believe you have backups. I do not believe they will save you, and here is the cold data on why. Sophos found that 94% of ransomware victims said the attackers tried to compromise their backups during the attack, and 57% of those attempts succeeded. Remember stage 2, all that patient exploring? Finding your backups is the point of it.

The reason it works is painfully simple. Most small businesses keep their backups connected to the same network as everything else: a backup drive plugged into the server, or a backup app syncing to a cloud folder that is always logged in. If the attacker can reach that backup from an infected machine, so can the ransomware. Your backups get encrypted right alongside your live data. You had a spare key, but you left it hanging on the same hook as the original.

The consequences are brutal. Sophos found recovery costs were eight times higher when backups were compromised ($3 million versus $375,000), and victims with wrecked backups were nearly twice as likely to pay. That is a big reason nearly half of ransomware victims still end up paying the ransom. "We have backups" and "we have backups that survived an attack and actually restore" are two completely different sentences.

The 3-2-1 backup rule (done properly)

So how do you make backups that actually survive? There is a simple, decades-old rule that still works, and if you take one thing from this article, take this: the 3-2-1 rule.

  • 3 copies of your data. The live version you work on every day, plus two backups. Not one. One backup means one thing goes wrong and you are done.
  • 2 different types of media. Do not keep both backups in the same place or format. For example, one copy on a local backup device and one in the cloud. Different media means a single failure (a dead drive, a compromised cloud login) cannot take out everything at once.
  • 1 copy offsite and, crucially, offline. At least one backup must live somewhere the attacker cannot reach from your network. This is the copy that saves you.

That last "1" is where the discipline lives. Two ideas make it bulletproof:

Air-gapped means the backup is physically or logically disconnected from your network. If it is not plugged in and not logged in, ransomware on your network simply cannot touch it. An external drive you connect only during the backup, then unplug and lock in a drawer, is a low-tech air gap that genuinely works.

Immutable means write-once, change-never. An immutable backup can be created but not modified or deleted for a set period, even by someone with the admin password. This matters because attackers often steal admin credentials (see the theme here) and delete backups the "legitimate" way. Many reputable cloud backup services now offer immutable storage as a checkbox. Turn it on.

Do this and the whole attack falls apart on your end. They encrypt your live systems, you wipe the machines, and restore from the offline copy they never got to touch. You get to say no.

The step everyone skips: test the restore

Here is the uncomfortable truth. A backup you have never restored is not a backup. It is a hope. Plenty of businesses discover during a crisis that their backups had been silently failing for months, or that a critical database was never included.

Test your restores on a schedule: actually pull files back from each backup and confirm they open and are current. Do it quarterly at minimum. The middle of a ransomware attack is the worst possible time to learn your backups do not work.

The supporting cast (keep them out in the first place)

Great backups are your parachute, but you would rather the plane not catch fire. A few defenses stop most attacks before they start, and none require an IT department:

  1. Multi-factor authentication (MFA) everywhere. MFA means logging in requires your password plus a second proof, like a code from an app on your phone. Since stolen passwords are the top entry point, MFA is the single highest-value thing you can turn on today, and it makes a stolen password alone useless.
  2. Patch your software. "Patching" just means installing updates, and those boring update prompts fix the exact security holes attackers exploit. Turn on automatic updates for your operating system, browsers, and apps.
  3. EDR (Endpoint Detection and Response). Think of this as antivirus that grew up. Instead of just matching known viruses, EDR watches for suspicious behavior (like a program suddenly encrypting thousands of files) and can stop an attack mid-motion.
  4. Email filtering. Since phishing is the other main entry point, a good email filter that quarantines malicious messages and attachments removes a huge chunk of your risk before anyone can click.
  5. Lock down your network's front doors. Attackers also probe weaknesses in the plumbing of the internet itself, which is why DNS security is worth understanding as another layer that can block connections to known-malicious servers.

If layering all of this feels like a lot to manage alone, this is exactly the kind of thing a small business cybersecurity partner handles day to day, so you can run your business instead of your firewall.

A realistic scenario

Meet Dana, who runs a 12-person dental practice. An office manager gets an email that looks like it is from the practice's billing vendor, asking her to log in to "review an invoice." She does. The page was fake; her password is now stolen.

For nine days, nothing seems wrong. Behind the scenes, the attacker logs in with that password, moves from her computer to the practice server, finds the patient database and the backup drive plugged into that server, and quietly copies six years of records to their own systems. On a Friday night, they trigger the encryption. Saturday morning, the on-call dentist finds every system locked and a demand for $180,000, with a threat to publish patient health data.

Two versions of Monday. In version one, Dana's only backup was that drive plugged into the server. It is encrypted too, so she is looking at weeks of downtime, a six-figure recovery bill, a data-leak threat, and regulators asking hard questions. In version two, Dana had an immutable cloud backup and a rotating offline drive in a safe. She still has the ugly data-leak problem to manage, but her systems are restored by Tuesday and she owes the attacker nothing for her files. Same attack. The only difference was one offline, immutable copy.

Your action plan

Here is exactly what to do, in order. Start at the top.

  1. Turn on MFA today for email, banking, accounting software, and any cloud tools. This is free and it is your biggest single win.
  2. Set up 3-2-1 backups this week. Three copies, two media types, and at least one that is offline or immutable and not reachable from your network.
  3. Run a test restore this month. Pull real files back and confirm they open and are current. Put a recurring quarterly reminder on the calendar.
  4. Turn on automatic updates across every device and application.
  5. Add EDR and email filtering. Both have affordable small-business options; pick reputable ones and switch them on.
  6. Write a one-page plan. Who do you call, in what order, if it happens? CISA's free #StopRansomware guidance is a solid starting template, and a short list beats blind panic at 2 a.m.

You do not need to do all six by Friday. But do number one and number two now, because they are the difference between a bad week and a closed business.

Ransomware is one of the biggest threats facing small businesses right now, but it is not unbeatable. You now know how the attack works, why ordinary backups quietly fail, and the exact 3-2-1 setup that lets you look a ransom demand in the eye and delete the email.