The modern 3-2-1-1-0 backup rule

Backup & DR · 1 min

Articles by Luís Carvalho

The 3-2-1-1-0 rule enhances traditional backup strategies with immutability and recovery validation. Learn best practices to protect data against ransomware.

The modern 3-2-1-1-0 backup rule

TL;DR

The updated rule

The 3-2-1-1-0 rule represents an evolution of traditional backup strategies. It consists of maintaining three copies of data, using two distinct types of media, ensuring one copy is offsite, preserving an immutable or air-gapped copy, and validating that there are zero errors in recovery tests. This approach is currently one of the most recommended to increase resilience against data loss and [ransomware attacks](/en/solutions/cybersecurity-mesh).

The importance of immutability

Immutability, through technologies such as S3 Object Lock, Veeam Hardened Repository, or immutable storage solutions, helps prevent unauthorized alterations or deletions of backups. However, protection does not end with copy creation. Regular recovery tests remain essential to ensure that data can be restored when needed. A backup that has never been validated may not offer the [expected protection](/en/services/backup-disaster-recovery) at the critical moment.

Backup Audit in 5 days

We test your restores and show you where you are truly exposed.

Related

References

  1. Veeam Data Protection Trends Report
  2. IBM Cost of a Data Breach Report
  3. ENISA Threat Landscape
  4. NIST SP 800-209 Security Guidelines for Storage Infrastructure