Skip to content
Let’s plan the right software for your processes. Call us for a demo or a quote: +90 546 737 48 29

TR EN DE

What is ransomware? The 3-2-1 backup rule

Ransomware is malicious software that encrypts the files on your computer and network and demands a ransom to unlock them. Some attackers also copy the files before encrypting them and threaten to publish them. Paying the ransom does not guarantee that the files will come back. The strongest defence is backups that sit where the attacker cannot reach them and that have been tested to make sure they can be restored.

In brief

  • Ransomware encrypts files; paying the ransom does not guarantee you get them back.
  • The 3-2-1 rule: three copies, two different media, one copy off-site and offline.
  • Updates, two-factor authentication and limited permissions close the routes of infection.
  • During an attack, the first job is to disconnect the affected device from the network.
On this page

Steps to protect yourself

  1. Apply the 3-2-1 backup rule

    3 copies (the original data + 2 backups), 2 different media (e.g. an external drive and the cloud or a backup device), 1 copy in a different location and, if possible, offline. Ransomware can also encrypt a backup drive that stays permanently connected; that is why it matters that at least one backup is disconnected from the network or immutable (cannot be deleted). Include your email in your backups as well.

    Diagram: the 3-2-1 backup rule; three copies, two media, one off-site and offline copy : Enlarge
  2. Close the routes of infection

    • Email: Attachments and links in phishing emails are the most common way in. See How to spot a phishing email.
    • Unpatched software: Do not put off updates for the operating system, browser, servers and network devices.
    • Remote access exposed to the internet: Do not expose services such as remote desktop directly to the internet; use a VPN and two-factor authentication.
    • Weak passwords: Use strong, unique passwords and two-factor authentication.
    • Broad permissions: Users should not do their everyday work with an administrator account; grant only the permissions that are needed on shared folders.
    Diagram: layers of protection; updates, backups, permissions, two-factor authentication, training, security software : Enlarge
  3. What should be done during an attack?

    1. Disconnect the affected device from the network immediately (cable and Wi-Fi); stop the spread.
    2. Tell your IT team or a security specialist; decide together what to do to preserve the evidence.
    3. Check whether the backups have been affected; do not connect a backup to the network until the clean-up is finished.
    4. If personal data has been affected, assess your notification obligation under data protection law (e.g. the GDPR); the GDPR requires a personal data breach to be reported to the competent data protection authority no later than 72 hours after becoming aware of it.
    5. Once the systems have been cleaned, restore from a clean backup and close the way in.
    Flowchart: disconnect from the network, tell a specialist, check the backups, notify, clean and restore : Enlarge

Test your backup

A backup that has never been restored is not a working backup. At regular intervals, restore a few files and, where necessary, a whole system from scratch to test that the backup really opens and how long it takes you to recover. Check the backup reports and error alerts regularly.

A short checklist for small businesses

  • Where are your accounting, customer and project files, and how often are they backed up?
  • Is at least one backup disconnected from the network or immutable?
  • When was the last restore test carried out?
  • Are automatic updates turned on for all computers and servers?
  • Is two-factor authentication turned on for email and remote access accounts?
  • Have employees been briefed about phishing?
  • Are the files and database of your website backed up separately? See Website backup and monitoring.

Frequently asked questions

If I pay the ransom, will I get my files back?

There is no guarantee. Many organisations that paid could not recover all of their files or were targeted again. Seek specialist support and legal advice before deciding.

Does my cloud folder count as a backup?

A synchronised cloud folder can synchronise the encrypted files as well. A service with version history and the ability to recover deleted files helps; even so, keep a separate backup copy.

Is security software enough?

Security software is an important layer, but it is not enough on its own. It should be used together with up-to-date systems, strong authentication, limited permissions and an offline backup.

BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.

Related guides

Let us review the security of your software together

BYK Yazılım supports the websites and software it develops with updates and security. Contact us with your questions.

Contact us Our corporate website service