Data Protection

Implement a 3-2-1 Backup Strategy

Protect critical data against ransomware and disasters with a tested backup and recovery program.

Content review: 2026-09-30 · Estimated effort: Medium

Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.

Before you start

Before starting: agree acceptable data loss (RPO) and downtime (RTO). Confirm what your cloud provider backs up and what remains your responsibility.

Put it into practice

  1. Start with the most important service and available backup capabilities. Include data, configurations, and recovery dependencies.
  2. For Microsoft 365, list the recovery path for each important workload. SharePoint and OneDrive version history and Recycle Bin can recover some file changes or deletions, depending on permissions and retention settings. Check those settings in your tenant and test with synthetic content; do not mistake native recovery for a separate backup or assume it covers Exchange and whole-service recovery.
  3. Use 3-2-1 as a planning pattern: three copies, two storage types, one off-site. Keep an offline or appropriately immutable copy; immutability and being offline are different protections.
  4. Separate backup administrator access, use MFA where supported, and encrypt sensitive backups. Verify deletion permissions and retention. Keep recovery keys accessible to authorized responders during an outage.
  5. Assign someone to review failures on a schedule consistent with your recovery objectives. Repeat restoration tests after important changes and on an agreed schedule.
  6. Verify: restore a representative sample safely, open restored files or start the service, check integrity, and record recovery time and the recovered data point.

Fictional example: test one restore before relying on it

An invented small team wants to check a project-folder backup. This is an illustrative exercise, not a lab result or a customer story.

  1. Prerequisites: obtain approval, choose a non-sensitive test folder, confirm access to the backup and a separate restore destination, and agree what acceptable recovery time and data loss mean for this service. For this fictional exercise only, assume a four-hour data-loss target and one-business-day recovery target; real targets must come from the service owner.
  2. Create two synthetic files, such as a text note and an Excel workbook with invented entries, and let the normal backup process capture them. Record the backup time and expected contents. Do not delete or overwrite the working originals to run this exercise.
  3. Restore the selected files into the separate destination. Open them, compare their contents with the originals, check access permissions, and record how long recovery took and which backup point was recovered. Compare the recovered data point with the acceptable data loss agreed before the test; a readable restore can still miss that target.
  4. If the restore fails or permissions are wrong, keep the originals and backup intact, record the failure, and investigate with the backup owner. Correct the cause and repeat the test before treating recovery as demonstrated.
  5. After verification, remove only the temporary restored test copies through the normal approved process. Preserve the result record. A file restore does not demonstrate full-service recovery; plan a separate authorized exercise for configurations and dependencies.

Make a start

Tools and templates

Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-30; check current vendor terms before choosing.

Start without another software subscription

For files, use File History where suitable or consider the free restic tool below if the team can operate command-line backups. Test actual restoration.

Where this stops: Storage, off-site copies, administration and recovery support still have costs. Neither option is a complete Microsoft 365 backup service or proof of full application recovery.

See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.

SharePoint and OneDrive native file recovery

Available within eligible Microsoft 365 subscriptions; check your tenant settings

For an approved synthetic file in a test library, review version history and the site Recycle Bin. Confirm who can restore it, what actually returns, and the applicable retention and version limits before relying on the path.

Limits: The Recycle Bin and version history are not an independent backup. Items can expire or be purged, and this does not restore an entire Microsoft 365 tenant or Exchange workload. Avoid altering real business files for a test.

Your information: Files and recovery records stay in your Microsoft 365 tenant. Use synthetic content and keep permissions restricted; do not upload tenant exports to this website.

Official instructions: SharePoint and OneDrive native file recovery ↗

restic: optional command-line file backups

Free open source software; storage and operation are your responsibility

An administrator comfortable with command-line tools can follow the official manual, choose approved storage and test a small synthetic file set. Restore to a separate destination before using it for important files.

Limits: Requires scheduling, monitoring, retention planning and secure recovery-password management. Not a complete Microsoft 365 or application-aware recovery solution. Do not remove existing backups until the replacement is proven.

Your information: Encrypted backups go to your selected repository. Protect repository credentials and the recovery password separately; losing required secrets can prevent restoration. Remote storage providers still process stored backup data.

Official instructions: restic: optional command-line file backups ↗

Windows File History

Included Windows feature; backup storage must be supplied

For a supported Windows PC, choose an approved external drive or network location under Control Panel > System and Security > File History. Restore a synthetic sample to a different location.

Limits: Protects selected files/libraries, not an entire service or Microsoft 365 tenant. An attached drive is not an offline or immutable backup. This is one component, not a complete business recovery solution.

Your information: Files are copied to your chosen drive or network destination. Apply access restrictions and review any cloud synchronization of that destination.

Official instructions: Windows File History ↗

Download a working template

Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.

Fictional worked example

Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.

A team rehearses restoring a project folder containing only synthetic test files.

Use the Backup restoration test record template.

What to enter before testing

Service or test set
EXAMPLE: synthetic project folder
Acceptable data loss
Fictional exercise target: four hours; agree real targets with the service owner
Acceptable downtime
Fictional exercise target: one business day
Separate restore destination reference
Approved test folder, separate from originals
Actual recovery time
Not measured
Contents and permissions check
Not tested

How to verify

Confirm approval, recovery objectives and backup access. Capture known synthetic files in the normal backup, then restore to the separate destination. Compare contents and permissions, record the recovered data point and measure elapsed time. Preserve the originals.

If the result is unexpected

If files are missing, unreadable or incorrectly accessible, keep originals and backups intact, record the failure and investigate with the backup owner. Retest after correction. A file restore does not demonstrate recovery of a whole application or Microsoft 365 tenant.

Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.

Sources and review approach

Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.

  • NIST CSF 2.0: PR.DS-11: backup protection and testing
  • NIST CSF 2.0: RC.RP-03: integrity of recovery assets
How this guidance is prepared