Home›Guides›IT backup

IT backup

How many backups should you keep?

Two things need counting: the number of copies, so that one remains if a medium burns or is erased, and the number of dates, so you can go back to before the error. A single, very recent copy fails on both counts; the 3-2-1 rule and one month of daily history cover most SMEs.

Updated October 20263 min read6 sources cited

Key points

  • 3 copies (production + 2 backups), on 2 different media, including 1 offline: this is the rule of the ANSSI, France’s national cybersecurity agency.
  • Add an immutable copy if the offline copy is infrequent or hard to maintain.
  • As for dates: around 30 daily restore points, then a few weekly or monthly ones.
  • Two disks in the same NAS count as a single copy.
  • The right figure: from how many independent media can you restore a file from twenty days ago?

The number of copies: 3-2-1, then a frozen copy

The 3-2-1 rule remains the minimum worth teaching. The ANSSI puts it as follows:

  • 3 copies of the data: the original and two backups.
  • 2 different media, so that a single fault does not take them out together.
  • 1 offline copy, on a medium disconnected from any information system.

Many presentations replace “offline” with “off-site”. Both are useful and must not be confused: an off-site copy remains reachable by an attacker if it is online with the same credentials. The ANSSI accepts an online off-site copy under certain conditions, but considers the offline copy essential, even if it is made less often.

Since ransomware began encrypting reachable backups as well, the rule has been extended with:

  • 1 immutable or offline copy that the everyday administrator cannot delete;
  • 0 unnoticed errors: failed jobs trigger an alert, and a restore is attempted.

Two disks in the same NAS count as a single risk: theft, fire, compromised administrator account. So do two providers in the same building, if fire is the scenario you are planning for.

The number of dates

A single copy, overwritten every night, is not a history. On the day the nightly copy already contains the corrupted file, there is nothing left to restore.

For an SME, a common and sufficient set is:

  • one restore point per day for 30 days;
  • one restore point per week for 8 to 12 weeks, if errors are discovered late;
  • one restore point per month for the archive of documents that must be retained.

That amounts to around thirty daily versions, not thirty full copies: incremental backups store only the changes. The number of versions is decided with the RPO and the detection time, not with a magic number. For reference, Mandiant measured a median of 14 days between an intrusion and its detection in 2025.

Summary

QuestionMinimum answerWhy
How many copies?3 (production + 2 backups)Survive the loss of a medium
On how many media?2 different typesAvoid a common fault
How many offline or immutable?At least 1Withstand a stolen administrator account
How many dates?Around 30 daily, then spaced outGo back to before an intrusion discovered late
How many tests?At least one per quarterProve that the copy can be restored

When you need more

  • Continuous data entry (point of sale, patient records, production): several restore points a day, otherwise the “latest backup” may be up to 24 hours old.
  • An obligation to prove an old document: this is not one more backup, it is immutable archiving of the documents concerned.
  • High file turnover: the history weighs more. Measure a real week before fixing the volume you purchase.

When you have too many

Hundreds of restore points that have never been restored, on a local disk that anyone can erase, give a false sense of security. The criterion is not the number displayed in the console. It is: “from how many independent media can I restore a file from twenty days ago?” CERT-MU recommends regular restore tests: check that backups work by actually restoring data. For personal data, the Data Protection Act 2017 (section 31) also requires security measures to be tested regularly.

At WeDoBack

Each backup is stored outside the production network, encrypted and replicated across several servers. The client sets the retention within the limits of the volume. The IMMUTABLE offer adds a copy that no one can modify or delete for the chosen period, up to ten years. Backup monitoring runs 24/7 and reports any backup that did not complete. The number of useful dates therefore depends on the volume ordered and the frequency set, not on a hidden quota of “N backups”.

Frequently asked questions

Do thirty versions take up thirty times the volume?

No. With incremental backups, only the changes are stored after the first full copy. A thirty-day history often weighs two to four times the usable volume, depending on how often files change.

Is an offline copy really necessary if I have a cloud backup?

The ANSSI considers it essential, even if it is made less often than the others, and regards it as more robust than an online copy. If you cannot maintain a media rotation, an immutable online copy, which no one can delete for a fixed period, is the compromise the same guide considers.

How many copies for Microsoft 365?

The same logic applies: the data in Microsoft 365, plus at least one copy outside the tenant, under different credentials. The Exchange Online recycle bin (14 days by default, 30 at most) is not an independent copy.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.