A ransomware attack does not ask for permission. It encrypts your files, locks your servers and leaves you with a single question on screen: pay, or lose everything? The only answer that does not make you a hostage is a backup that truly works. And the gold standard, recognised in the industry for decades, is the 3-2-1 rule.
What the 3-2-1 rule means
- 3 copies of the data — the original plus two backups. Redundancy means a single failure does not leave you without data.
- 2 different types of media — for example local disk plus cloud, or NAS plus tape. That way a problem specific to one media type does not affect both copies.
- 1 copy in another location (off-site) — physically separate from your premises. If you have a fire, flood or theft, the external copy survives.
The logic is simple: no single event — hardware failure, attack, physical disaster — can destroy all copies at once, because they are diversified in number, type and location.
From 3-2-1 to 3-2-1-0
Modern ransomware forced an upgrade of the classic rule. The variant we implement is 3-2-1-0:
- 0 errors on verification — each backup is automatically tested for integrity and for actual restore capability. A backup that has not been tested is not a backup, it is a hope.
In addition, we recommend at least one immutable or air-gapped copy: data that cannot be modified or deleted within a predefined time window, not even by an administrator with full rights. Precisely because modern attackers seek out and encrypt backups before hitting production.
The most common backup mistakes
- 1Backup on the same server / same network as production — ransomware encrypts it too.
- 2Backup that has never been restore-tested — you discover it is corrupt exactly when you need it.
- 3A single copy, in the cloud, without immutability — a compromised account deletes everything.
- 4Backups without monitoring — they fail silently for weeks and no one notices.
- 5No documented recovery plan — you have the data, but no one knows in what order to bring services back.
The two parameters you must define: RPO and RTO
Before choosing the technology, answer two business questions:
- RPO (Recovery Point Objective): how much data can you afford to lose? If you back up once a day, in the worst case you lose a day of work. For some companies that is acceptable, for others it is a disaster.
- RTO (Recovery Time Objective): how quickly must you be operational again? An hour? A day? The answer dictates the architecture and cost of the solution.
These two figures turn backup from an abstract technical expense into a clear business decision.
How we implement the backup strategy
In our IT infrastructure projects we design the 3-2-1-0 strategy with proven tools — Veeam, Acronis or cloud-native solutions — chosen according to your existing stack. We then configure daily verification, monthly reports and a tested recovery plan, not just an assumed one. Backup thus becomes a measurable guarantee, not a box ticked out of habit.
There is no such thing as "backup that is too expensive" — only the recovery cost you are willing to pay. It is always cheaper than a ransom.
Conclusion
The 3-2-1 rule is not textbook theory — it is the best insurance policy a company can have against ransomware and disasters. The key is to apply it fully — including the testing and immutability parts — and to tie it to real business objectives (RPO/RTO). The rest is just discipline.