The 3-2-1 Backup Rule: The Gold Standard Against Data Loss
The 3-2-1 backup rule: 3 copies, 2 different media, 1 offsite. For the ransomware age, 3-2-1-1-0 (immutable copy + verification). A rule infographic, a 3-2-1-1-0 reference table, policy building steps and FAQs.
Quick answer: The 3-2-1 backup rule is the global gold standard for protecting your data from loss, summarized by this formula: keep at least 3 copies (1 primary + 2 backups), store these copies on 2 different media types (for example local disk + cloud or tape), and keep at least 1 copy physically offsite/remote (preferably offline). The logic is simple: a single copy is a single point of failure; a single medium type carries a common weakness; a single location can lose everything at once to fire/theft/ransomware. For modern threats (especially ransomware) the rule was extended to 3-2-1-1-0: +1 copy immutable or offline (so ransomware cannot reach it), 0 verification errors (every backup regularly tested and proven restorable). The most important principle is this: an untested backup is not a backup. In a disaster, the only thing of value is a backup you can actually restore.
The most painful kind of data loss is the sentence "I had a backup but it did not work." Backup is an area everyone thinks they are doing, yet it often fails in a crisis. The 3-2-1 rule minimizes this risk with a simple framework tested for decades. This guide explains the rule with world class clarity, together with 3-2-1-1-0 that carries it into the modern ransomware age.
The 3-2-1 rule and its modern addition
The strength of the rule is its simplicity: three numbers close three independent points of failure. The copy count protects against single corruption, media diversity against common weakness, offsite against local disaster. The immutable/offline copy and verification added in the ransomware age adapt the rule to today's threats.
3-2-1-1-0 reference table
| Number | Rule | Why | Example |
|---|---|---|---|
| 3 | At least 3 copies | One copy is a single point of failure | 1 primary + 2 backups |
| 2 | 2 different media | Common media weakness | Disk + cloud/tape |
| 1 | 1 copy offsite | Local disaster (fire, theft) | Remote data center |
| 1 | +1 immutable/offline | Ransomware encrypts the backup | WORM, air gap |
| 0 | 0 verification errors | A broken backup is useless | Regular restore testing |
Steps to build a backup policy
- Decide what and how often to back up. Classify critical data; define your recovery objectives (RTO/RPO).
- Apply 3-2-1. At least three copies, two media, one offsite.
- Add an immutable/offline copy. Ransomware targets your backups too; at least one copy must be unreachable.
- Encrypt. Encrypt backups both in transit and at rest; a stolen backup must be unreadable.
- Test the restore. A real restore drill monthly/quarterly; this is the "0 errors" step.
- Monitor and document. Failed backup jobs must raise alerts; the process must be tied to your business continuity plan.
The only real way to never face the payment decision in a ransomware attack is a tested backup that follows this rule.
Frequently asked questions
Is backing up only to the cloud enough? On its own, no. The cloud is one copy, but 3-2-1 requires multiple copies and media. If your cloud account is compromised or a wrong deletion happens, one copy is not enough; a second medium and an offline copy are needed.
Can ransomware encrypt my backups? Yes, modern ransomware also targets all backups it can reach. That is why the immutable (WORM) or offline (air gapped) copy in 3-2-1-1-0 is critical; the attacker cannot reach it.
How often should I back up? It depends on how fast the data changes and the acceptable loss window (RPO). For critical data daily or even continuous; for less changing data weekly may be fine.
How do I know my backup works? Only by restoring it. Assuming a backup is sound without a regular restore test (the "0" in 3-2-1-1-0) is the most common and most expensive mistake.
Sources
- CISA, Data Backup Options: https://www.cisa.gov
- NIST SP 800 34, Contingency Planning: https://csrc.nist.gov
- US CERT, Ransomware and Backups: https://www.cisa.gov/stopransomware
- ENISA, Backup and Recovery: https://www.enisa.europa.eu
For a 3-2-1 compliant backup architecture, a ransomware resilient immutable copy and restore testing, contact DSET. From our Ankara Hacettepe Teknokent laboratory we provide data recovery, cybersecurity and business continuity services.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.