Home / Blog / Backups That Were Not Backups
Business · blog post

Sync, retention and the 3-2-1 rule, written from the bench the disks reach once a plan has been leaned on

The most useful question anyone in a small firm can be asked about their backup is not what it costs or which product it runs on. It is whether somebody has recently taken a real file out of it, opened it, and found what they expected to find. Until that has happened the whole arrangement is an assumption with a schedule attached, and the assumptions come apart in a short list of predictable ways.

Begin at the end: rehearse the restore

Pick an ordinary Wednesday. Choose a folder that would genuinely hurt to lose, restore it to a machine that is not the one it came from, open three files at random, and time the whole exercise with a watch. Write the minutes down. That single hour finds more holes than any amount of reading about backup strategy, because it exercises the parts nobody thinks about: whether the console still accepts the password, whether anyone remembers which job holds what, whether the restore lands somewhere you can actually use it.

The rehearsal also produces the two numbers that ought to govern every decision after it. How much work could the firm afford to lose — an hour, a day, a week? That sets how often copies are taken. And how long could the firm afford to be stopped — an afternoon, two days, a fortnight? That sets how fast they have to come back. They are different questions with different price tags, and in most small firms neither has ever been written on paper.

The second number is where the arithmetic gets uncomfortable. Restoring one document is quick and everybody has done it. Bringing back four terabytes over the same link is a different exercise entirely: divide the volume by the speed the connection genuinely sustains rather than the one on the tariff, and read the answer in days. If the sum says eleven days and the business says two, the plan is already wrong, and no number of green ticks in the morning report will say so.

Sync is a mirror, and mirrors copy mistakes at full speed

This is the most common misunderstanding that reaches this bench, and it is easy to see how it happens. A synchronisation service exists to make every copy identical as quickly as it can. That is the product working correctly. The consequence is that a deletion is a change, an encryption run is a change, and a file that has quietly corrupted is a change — so all three arrive on every other machine within minutes, faithfully, exactly as designed.

None of that makes those services worthless. They are genuinely useful and they have saved a great many people from a dropped laptop. But a mirror answers the question of what happens when a device is lost. It does not answer what happens when the content itself goes wrong, and the second question is the one that empties a firm's files.

Two figures decide how much protection you are actually getting from one: how many days of previous versions it keeps, and how long a full restore through that interface takes for the volume you hold. Find both out this week rather than on the morning you need them, because the interface that restores one file in three seconds sometimes restores four hundred thousand of them at a pace that has to be measured in days.

Versions are the part you are actually paying for

Corruption rarely arrives with an announcement. A database develops a fault in March. A shared drawing library starts producing files that open with pieces missing. In a small firm that gets noticed in May, when somebody goes back to a project they have not touched since the spring — and by then a fourteen-day history has been overwritten eleven times and every copy in existence contains the problem. The backup did exactly what it was told to do throughout.

Retention is the least examined setting in the whole arrangement and it decides whether that category of fault is survivable. Look up the actual figure, in days, for each copy you keep, rather than assuming, because the defaults on several popular products are shorter than people imagine. Then ask an honest question: how long could something plausibly go unnoticed here? If the answer is longer than the retention, you are one quiet fault away from having a complete set of broken copies.

The remedy is cheap. One copy taken monthly and kept for a year costs very little and closes the whole category, because it outlives the noticing. It does not need to be fast or clever. It needs to exist, and it needs to be old.

Three copies, two kinds of media, one somewhere else — and where it bends

The 3-2-1 idea is worth knowing because it is short enough to remember under pressure: three copies of anything that matters, held on two different kinds of media, with one of them somewhere the building's problems cannot reach. Most small firms believe they are doing it. In practice it bends in three places, and each bend is invisible until the day it matters.

The copies are not really separate. Copy two is a second folder on the same machine, or an internal disk in the same tower, or a share on the same server. One power supply, one lightning strike, one ransomware run, one theft. The off-site copy is not off-site. A second NAS in the loft above the same office, or a portable disk that lives in the boot of a car parked outside the building, both sit inside the fire, the flood and the burglary you were insuring against. Somewhere else has to mean a different postcode.

The two kinds of media are the same kind. Two identical disks from the same order, out of the same batch, fitted on the same afternoon and driven identically since are not diversity in any useful sense. Add one line to whatever you already do, though, and a surprising amount of this is answered at once: a copy that cannot be altered or deleted for a fixed number of days. It is the single most useful thing a small firm can add in 2026, because the modern version of this disaster starts with an intruder holding administrator credentials deleting the backups first and encrypting afterwards.

What nobody ever copies: the system, the keys and the licences

Somebody copies the data folders every night and it works perfectly. Then the server dies, and it emerges that the practice management system will not run without its database engine, its configuration, its certificates, its licence keys and the precise version it was installed with — none of which were ever in scope, because none of them lived in the data folders.

Restoring the documents takes an afternoon. Rebuilding the thing that opens them takes a fortnight of chasing suppliers for keys and installers, several of which are for versions nobody supports any more. The firm has every byte it owns and can use none of it, which is a peculiar and expensive kind of failure and far more common than it sounds.

The same trap catches encryption. Backups that leave the building ought to be encrypted, and then the key lives on the server that died, or in the head of somebody who left in January, and the copies are perfect and unreadable. Put the key somewhere the same event cannot reach: a sealed envelope in the safe, a password manager with more than one administrator, a note filed with the insurance documents. A key stored only on the system it protects is not a key. Try the whole thing as one sentence — if this unit burned down tonight, what exactly would we need in order to be working again, and is every part of it somewhere else?

Scope drift, or the job that still protects the firm you were in 2019

This is the failure found most often on the bench and it is nobody's fault in particular. A backup was configured properly, years ago, by somebody who knew what they were doing. It has run without complaint ever since and it is still copying exactly the folders it was pointed at. Meanwhile the firm added a second server, moved the drawings onto a new share, put the accounts package in a virtual machine, and let the design team keep project files on their own laptops because the network share was slow.

None of that is in the job. The report is green every morning and has been for six years, and each year it protects a smaller share of the business. It is discovered at the only moment it can be discovered — during a restore, when the folder that mattered turns out never to have been in scope.

The fix is an afternoon and a list. Write down every place data is created: every server, every share, every laptop holding something that exists nowhere else, every cloud service holding records you would need after an incident. Check each line against what the job actually covers. Then put a note in the diary to do it again next year, because scope drifts quietly and it never drifts back.

The first hour after it has failed, and what the disks cost

When the copies turn out to be no good, the first hour matters more than the plan ever did. Stop every scheduled job you own — backups, snapshots, replication and sync clients alike — because those are the mechanisms most likely to write a broken version over the last good one, and they will do it precisely on schedule. Stop writing to the affected storage and take the applications off it. Then write down the timeline while it is fresh, because that sequence of events gets asked about repeatedly and memory of it degrades within days.

After that it becomes a hardware question, and the bands are published. Anything with more than one member in it — array, NAS, server, SAN — opens at £500 + VAT and climbs as the members do. One drive or one SSD, NVMe included, is £300 + VAT. Cards, sticks and pen drives are £250 + VAT. Recorder disks are £400 + VAT, and so is an encrypted volume for which a key exists. Criminally encrypted media is charged on those same hardware rungs, £300 + VAT a drive and from £500 + VAT an array, because the bench does identical physical work either way. It is never billed as forensic. The diagnostic is free, closes 2 working days after booking in, and gives you one written figure that then stays put. Logical faults carry no fix, no fee; the four exclusions are electronic and mechanical failures, chip level work, DVR jobs and forensic jobs.

A NAS travels whole with its disks in their bays. A server or a bare array sends member disks only, each labelled with its bay order and a photograph of the front panel in the box, tracked and insured to Oxford Data Recovery, John Eccles House, Oxford Science Park, Robert Robinson Avenue, Littlemore, Oxford OX4 4GP. Reception takes drop-offs Mon–Fri 9:00am–5:30pm and the run from Coventry is about fifty-five miles of M40, roughly an hour. Nobody collects and there is no counter in Coventry. Alongside this page sit disaster recovery in Coventry for the business version of that first hour, server data recovery, NAS recovery, ransomware recovery and data recovery cost. The freephone is 0800 689 0668.

Nothing on this page is for sale, which is rather the point. This is a recovery bench with no backup product, no contract and no subscription — just the disks that turn up after an arrangement has been tested properly for the first time. That is an unusually clear view of which ones hold and which ones do not.

// what people ask about this one

Common questions

Because the bench sees the results. Every week something arrives here because a copy that was believed in turned out to be shorter, older, narrower or less readable than anybody thought. There is no product to steer you towards and no contract at the end of it, which makes this a reasonable place to read an honest list of how these arrangements fail. Anyone selling you continuity planning is doing a different and genuinely useful job.
It is a mirror, and a mirror is not the same thing. Its purpose is to make every copy identical quickly, so a deletion, an encryption run or a quietly corrupted file replicates to every other machine within minutes. Two numbers tell you how much cover you actually have: how many days of previous versions the service keeps, and how long a full restore of everything you hold would genuinely take through that interface.
No, and this catches out a lot of firms. Fire, flood, theft and a lightning strike on the incoming supply do not distinguish between the box in the office and the box in the loft above it. The same applies to a portable disk that lives in a car parked outside. Off-site has to mean far enough away that one event cannot reach both, which in practice means a different postcode.
Longer than it would take somebody here to notice a problem. That is the only sensible way to set it. If a corrupted drawing library or a database fault could go unremarked for two months, a fortnight of retention guarantees that every copy you hold contains the fault by the time anybody looks. One monthly copy kept for a year costs very little and closes the entire category.
No. Parity covers one event, a disk dying, and nothing else. A deletion is written faithfully across every member at once. Ransomware encrypts your files and the array then protects the encrypted versions with the same care. Fire, theft, flood, a controller writing corruption and a power cut in the middle of a write all sit outside what RAID was designed to handle.
No, and nobody should be selling it to you as one. Media full of criminally encrypted files carries the price those disks would have carried had they simply failed: £300 + VAT for one drive, from £500 + VAT for a server, NAS or array. What £800 + VAT buys is a deliberate investigation with a written report, commissioned when an insurer, a regulator or a court needs to know how an intrusion happened. Getting files back is a recovery and is charged as one.
It is priced on the published bands like anything else. Multi-disk work — arrays, NAS units, SANs, servers — opens at £500 + VAT and grows with the member count. A lone drive or SSD is £300 + VAT and a card or stick £250 + VAT. Looking at them is free, closes 2 working days after Oxford books the disks in, and ends in a written figure agreed before any chargeable work starts.

Rather put it in front of an engineer?

Oxford charges nothing to examine it, and that closes 2 working days from the moment it is booked in. Whatever figure comes out of it is written down and stays there: £250 + VAT a card or stick, £300 + VAT one drive or SSD.