I don't know if that's enough to guard against cryptolockers, but it seems enough to me. (Being on Linux also makes me probably a less likely target for cryptolockers, but that's not the case for everyone.)
It would be good to have a second backup in case the backup HDD fails, of course.
Hasn't happened to me yet, but I've crashed my external HDD once, a second backup definitely makes sense.
In that scenario, if your backup drive is writeable from your infected machine, your backups are potentially fucked.
One way to guard against this would be for example a raspberry pi on your network that periodically connects to your (possibly infected) main machine and makes incremental copies over the network to an external HD connected to the Pi. (Meaning the Pi reads and determines what is new, what's is old and how to make the incremental backup.) This of course needs to be coupled to some sort of smart versioning scheme and regular inspection of the backups by the user.