What is ransomware? The 3-2-1 backup rule
Ransomware is malicious software that encrypts the files on your computer and network and demands a ransom to unlock them. Some attackers also copy the files before encrypting them and threaten to publish them. Paying the ransom does not guarantee that the files will come back. The strongest defence is backups that sit where the attacker cannot reach them and that have been tested to make sure they can be restored.
In brief
- Ransomware encrypts files; paying the ransom does not guarantee you get them back.
- The 3-2-1 rule: three copies, two different media, one copy off-site and offline.
- Updates, two-factor authentication and limited permissions close the routes of infection.
- During an attack, the first job is to disconnect the affected device from the network.
On this page
Steps to protect yourself
-
Apply the 3-2-1 backup rule
3 copies (the original data + 2 backups), 2 different media (e.g. an external drive and the cloud or a backup device), 1 copy in a different location and, if possible, offline. Ransomware can also encrypt a backup drive that stays permanently connected; that is why it matters that at least one backup is disconnected from the network or immutable (cannot be deleted). Include your email in your backups as well.
: Enlarge -
Close the routes of infection
- Email: Attachments and links in phishing emails are the most common way in. See How to spot a phishing email.
- Unpatched software: Do not put off updates for the operating system, browser, servers and network devices.
- Remote access exposed to the internet: Do not expose services such as remote desktop directly to the internet; use a VPN and two-factor authentication.
- Weak passwords: Use strong, unique passwords and two-factor authentication.
- Broad permissions: Users should not do their everyday work with an administrator account; grant only the permissions that are needed on shared folders.
: Enlarge -
What should be done during an attack?
- Disconnect the affected device from the network immediately (cable and Wi-Fi); stop the spread.
- Tell your IT team or a security specialist; decide together what to do to preserve the evidence.
- Check whether the backups have been affected; do not connect a backup to the network until the clean-up is finished.
- If personal data has been affected, assess your notification obligation under data protection law (e.g. the GDPR); the GDPR requires a personal data breach to be reported to the competent data protection authority no later than 72 hours after becoming aware of it.
- Once the systems have been cleaned, restore from a clean backup and close the way in.
: Enlarge
Test your backup
A backup that has never been restored is not a working backup. At regular intervals, restore a few files and, where necessary, a whole system from scratch to test that the backup really opens and how long it takes you to recover. Check the backup reports and error alerts regularly.
A short checklist for small businesses
- Where are your accounting, customer and project files, and how often are they backed up?
- Is at least one backup disconnected from the network or immutable?
- When was the last restore test carried out?
- Are automatic updates turned on for all computers and servers?
- Is two-factor authentication turned on for email and remote access accounts?
- Have employees been briefed about phishing?
- Are the files and database of your website backed up separately? See Website backup and monitoring.
Frequently asked questions
If I pay the ransom, will I get my files back?
There is no guarantee. Many organisations that paid could not recover all of their files or were targeted again. Seek specialist support and legal advice before deciding.
Does my cloud folder count as a backup?
A synchronised cloud folder can synchronise the encrypted files as well. A service with version history and the ability to recover deleted files helps; even so, keep a separate backup copy.
Is security software enough?
Security software is an important layer, but it is not enough on its own. It should be used together with up-to-date systems, strong authentication, limited permissions and an offline backup.
BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.
Related guides
- Website backup and monitoringFile and database backups, restore drills, file integrity, logs and uptime monitoring.
- How to spot a phishing emailThe tell-tale signs of fake emails, how to check links and attachments, and what to do if you clicked.
- What is two-factor authentication and how do you turn it on?Add a second layer of security to your accounts: verification methods and the general route for Google and Microsoft accounts.
- How to create a strong password. What is a password manager?Long passwords that are never reused, passphrases, and how to use a password manager.
Let us review the security of your software together
BYK Yazılım supports the websites and software it develops with updates and security. Contact us with your questions.
Contact us Our corporate website service