A backup you've never restored

Complete plan

Attackers go after the backups before encrypting everything else. Three copies on two media, one offline, separate accounts and network, and restores that are tested and timed.

  • 3 min
  • 3-question check
  • English · Français
  • Attestation

You will be able to

  • Apply the three-two-one rule: three copies, two media, one offline
  • Keep backups separate from the usual network and admin accounts
  • Test a restore regularly, from a single file to a whole server, and measure recovery time

The module

3 min
  1. A backup you've never restored 2 min
  2. Knowledge check

    3 questions, pass mark 80 %. Explanations after each answer; you can try again.

  3. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Sources
  • Sophos, The impact of compromised backups on ransomware outcomes, avr. 2024 (2 974 organisations : 94 % de tentatives contre les sauvegardes, 57 % réussies)
  • BleepingComputer, 23 août 2023 : l'hébergeur danois CloudNordic perd la plupart des données clients, sauvegardes chiffrées
  • British Library, Learning lessons from the cyber-attack, 8 mars 2024 (copies présentes, pas d'infrastructure pour restaurer)
  • ANSSI, Sauvegarde des systèmes d'information : les fondamentaux (ANSSI-BP-100 v1.1, 27 nov. 2025) : règle 3-2-1, sauvegarde hors ligne, tests de restauration
  • Directive (UE) 2022/2555 (NIS 2), art. 21(2)(c) ; règlement d'exécution (UE) 2024/2690, annexe, 4.2
  • À retenir : la version classique de la règle 3-2-1 dit « une copie hors site » ; l'ANSSI demande une copie hors ligne, un stockage inaltérable (verrouillage d'objets) hors de portée des comptes de production remplit le même but ; les chiffres Sophos viennent d'une enquête déclarative menée par un éditeur

Version 1 · updated October 5, 2026