Quick answer: The 3-2-1 backup rule is the global gold standard for protecting your data from loss, summarized by this formula: keep at least 3 copies (1 primary + 2 backups), store these copies on 2 different media types (for example local disk + cloud or tape), and keep at least 1 copy physically offsite/remote (preferably offline). The logic is simple: a single copy is a single point of failure; a single medium type carries a common weakness; a single location can lose everything at once to fire/theft/ransomware. For modern threats (especially ransomware) the rule was extended to 3-2-1-1-0: +1 copy immutable or offline (so ransomware cannot reach it), 0 verification errors (every backup regularly tested and proven restorable). The most important principle is this: an untested backup is not a backup. In a disaster, the only thing of value is a backup you can actually restore.

The most painful kind of data loss is the sentence "I had a backup but it did not work." Backup is an area everyone thinks they are doing, yet it often fails in a crisis. The 3-2-1 rule minimizes this risk with a simple framework tested for decades. This guide explains the rule with world class clarity, together with 3-2-1-1-0 that carries it into the modern ransomware age.

The 3-2-1 rule and its modern addition

3 · 2 · 1 BACKUP RULE 3COPIES 3 copies total(1 primary + 2 backups) 2MEDIA 2 different media(disk + cloud/tape) 1OFFSITE 1 copy offsite(offline/remote) Modern add: +1 immutable/offline, 0 verification errors (3-2-1-1-0) An untested backup is not a backup; restore must be tested regularly.

The strength of the rule is its simplicity: three numbers close three independent points of failure. The copy count protects against single corruption, media diversity against common weakness, offsite against local disaster. The immutable/offline copy and verification added in the ransomware age adapt the rule to today's threats.

3-2-1-1-0 reference table

Number Rule Why Example
3 At least 3 copies One copy is a single point of failure 1 primary + 2 backups
2 2 different media Common media weakness Disk + cloud/tape
1 1 copy offsite Local disaster (fire, theft) Remote data center
1 +1 immutable/offline Ransomware encrypts the backup WORM, air gap
0 0 verification errors A broken backup is useless Regular restore testing

Steps to build a backup policy

  1. Decide what and how often to back up. Classify critical data; define your recovery objectives (RTO/RPO).
  2. Apply 3-2-1. At least three copies, two media, one offsite.
  3. Add an immutable/offline copy. Ransomware targets your backups too; at least one copy must be unreachable.
  4. Encrypt. Encrypt backups both in transit and at rest; a stolen backup must be unreadable.
  5. Test the restore. A real restore drill monthly/quarterly; this is the "0 errors" step.
  6. Monitor and document. Failed backup jobs must raise alerts; the process must be tied to your business continuity plan.

The only real way to never face the payment decision in a ransomware attack is a tested backup that follows this rule.

Frequently asked questions

Is backing up only to the cloud enough? On its own, no. The cloud is one copy, but 3-2-1 requires multiple copies and media. If your cloud account is compromised or a wrong deletion happens, one copy is not enough; a second medium and an offline copy are needed.

Can ransomware encrypt my backups? Yes, modern ransomware also targets all backups it can reach. That is why the immutable (WORM) or offline (air gapped) copy in 3-2-1-1-0 is critical; the attacker cannot reach it.

How often should I back up? It depends on how fast the data changes and the acceptable loss window (RPO). For critical data daily or even continuous; for less changing data weekly may be fine.

How do I know my backup works? Only by restoring it. Assuming a backup is sound without a regular restore test (the "0" in 3-2-1-1-0) is the most common and most expensive mistake.

Sources

For a 3-2-1 compliant backup architecture, a ransomware resilient immutable copy and restore testing, contact DSET. From our Ankara Hacettepe Teknokent laboratory we provide data recovery, cybersecurity and business continuity services.