Ransomware hit a small Lagos accounting firm and encrypted every file on the office laptop — including the “backup” folder sitting right there on the same drive. One infection, zero recoverable copies, because a second folder on the same machine was never actually a backup.
The 3-2-1 Rule, Explained Simply
CISA’s own guidance is specific: three copies of important files, on two different types of storage, with one copy kept off-site. For a small business, that’s realistically the working laptop, an encrypted external drive, and a protected cloud or genuinely off-site copy — three separate points of failure, not one drive wearing three hats.
What to Protect First, in Order
- Accounting and tax records
- Customer and supplier contacts
- Contracts and invoices
- Product and inventory data
- Website and creative files
- Account-recovery information itself
Keep One Copy Genuinely Isolated
A drive permanently plugged into an infected computer gets encrypted right along with everything else — that Lagos accounting firm learned this the hard way. Disconnect the backup drive after each scheduled backup where practical, or use a cloud service with protected version history and real access controls instead.
Encrypt Anything Sensitive
A backup creates a brand new privacy risk if it’s ever stolen. Encrypt sensitive data, restrict who can access it, and store recovery keys somewhere separate and controlled — not taped to the drive itself.
Test the Restore, Not Just the Backup
Every month or quarter, actually restore a sample file to a different location and open it. Write down the date, who did it, and what happened. A backup job marked “successful” can still produce a corrupted or incomplete file — you only find out by actually testing, not by trusting the green checkmark.
Keep multiple, genuinely independent copies. Test the restoration, not just the backup schedule. The goal was never to say a backup exists — it’s to actually get the business running again when the original is gone.

