The modern 3-2-1-1-0 backup rule
Backup & DR · 1 min
Articles by Luís Carvalho
The 3-2-1-1-0 rule enhances traditional backup strategies with immutability and recovery validation. Learn best practices to protect data against ransomware.

TL;DR
- 3 copies · 2 media types · 1 offsite location · 1 immutable copy · 0 verified errors
- Immutability is one of the most effective measures to protect data recovery after a ransomware attack
- Regular recovery tests are fundamental
- Technologies like S3 Object Lock, Veeam Hardened Repository, and immutable storage help reinforce data resilience
The updated rule
The 3-2-1-1-0 rule represents an evolution of traditional backup strategies. It consists of maintaining three copies of data, using two distinct types of media, ensuring one copy is offsite, preserving an immutable or air-gapped copy, and validating that there are zero errors in recovery tests. This approach is currently one of the most recommended to increase resilience against data loss and [ransomware attacks](/en/solutions/cybersecurity-mesh).
The importance of immutability
Immutability, through technologies such as S3 Object Lock, Veeam Hardened Repository, or immutable storage solutions, helps prevent unauthorized alterations or deletions of backups. However, protection does not end with copy creation. Regular recovery tests remain essential to ensure that data can be restored when needed. A backup that has never been validated may not offer the [expected protection](/en/services/backup-disaster-recovery) at the critical moment.
Backup Audit in 5 days
We test your restores and show you where you are truly exposed.
Related
- Backup & Disaster Recovery
- Datacenter
- Monitoring Systems