Backup policy template (3-2-1-1-0)
A backup policy answers six questions in writing: what is backed up, how often (RPO), how fast it must come back (RTO), where the copies live (3-2-1-1-0: three copies, two media, one offsite, one immutable, zero errors on test), how long copies are kept, and who verifies it. Fill the bracketed values in the template and it becomes a real policy.
Scope
Systems covered by this policy. Anything not listed is explicitly not backed up, and the client has acknowledged that in writing.
- File server / shared data: [server names]
- Line-of-business applications and their databases: [list]
- Microsoft 365 / Google Workspace (mail, drives, sites): [tenancy]
- Workstations: [all / named machines only / not covered]
- Configuration that would be slow to rebuild: firewall configs, DNS zones, licence keys
Objectives per system
RPO: how much data loss is acceptable. RTO: how long restoration may take. Set them per system and get the client to sign them; they will have opinions after an incident, so collect them before.
- [System]: RPO [4 hours], RTO [8 hours]
- [System]: RPO [24 hours], RTO [2 business days]
Copies (3-2-1-1-0)
- 3 copies: production plus two backups
- 2 media: [local NAS/appliance] plus [cloud object storage]
- 1 offsite: [cloud region / rotated media location]
- 1 immutable or offline: [object lock with N-day retention / air-gapped rotation]; backup credentials stored nowhere on the client network
- 0 errors: every test restore verified and logged
Schedule and retention
- Backup schedule: [nightly full / hourly incremental, per system]
- Retention: [30] daily, [12] weekly, [12] monthly; longer where regulation demands
- Job failures alert to [destination] and are actioned within [1 business day]
Testing
- File-level restore test: monthly, rotating through systems
- Full restore of one critical system: quarterly, timed against its RTO
- Results logged where the client can see them
Roles
- Backup administration and monitoring: [MSP]
- Restore authorisation for whole systems: [named client contact]
- Policy review: [annually] or after any material infrastructure change
Verification is the habit that makes this real.
Moorfox will not run your backups, but it watches everything around them: disk health, the machines that quietly stopped checking in, and a security score that flags the unprotected. The same continuous-verification habit this policy asks of your backups.