Backup advice changes constantly. New tools, new acronyms, new vendors, every single year. But one piece of advice has outlived all of it: keep three copies of your data, on two different kinds of storage, with one copy somewhere else. That is the 3-2-1 rule. A photographer popularized it about twenty years ago, and it is still the backbone of every serious backup plan we build.

The rule is showing its age in one specific way, though. It was written before ransomware crews figured out that the fastest way to get paid is to destroy a company’s backups first, then encrypt everything else. A business can follow 3-2-1 to the letter and still lose everything, because all three copies were reachable from the same network with the same passwords. The fix is not to throw out the rule. The fix is to add two numbers to it.

What 3-2-1 Actually Means

Strip away the jargon and the rule is just organized caution. Any single copy of your data can fail, so you never depend on a single anything. Backup vendor Object First’s research finds that roughly one in three organizations still does not follow the basic rule completely, so it is worth spelling out.

  • Three copies of your data: the live version your team works in, plus two backups. If one backup is corrupted or skipped a night, you still have another.
  • Two different kinds of storage: for example, a backup device in your office plus cloud storage. Two copies sitting on the same equipment can die from the same cause.
  • One copy offsite: fire, flood, theft, or a North Texas tornado can take out your office and the backup drive sitting next to the server. One copy has to live somewhere else entirely.

One clarification, because it trips people up constantly. OneDrive, Dropbox, and Google Drive are sync tools, not backups. If a file gets deleted or encrypted on your laptop, the sync service faithfully copies that damage everywhere within seconds. A backup is a separate historical copy you can roll back to. Sync is convenience. Backup is protection. They are not the same product.

Why the Original Rule Needed an Update

Ransomware changed the target. Attackers who break into a network today rarely encrypt anything right away. They spend days or weeks looking around first, and one of the first things they hunt for is the backup system. Delete the backups, then encrypt production, and the victim has almost no choice left but to negotiate.

The industry knows it, too. In Object First’s 2026 World Backup Day survey, 79 percent of IT leaders named attackers reaching their backups as a primary concern, yet only 58 percent of organizations use immutable storage, the kind that cannot be altered or deleted, across all of their data. In other words, most companies are worried about exactly the gap most companies still have. We saw how far attackers will go in the Stryker cyberattack, and the lesson applies to backups directly: assume an intruder eventually finds everything your admin account can reach.

The Modern Version: 3-2-1-1-0

Backup vendors, Veeam most prominently, now teach an updated standard called 3-2-1-1-0. It keeps everything above and bolts on two requirements.

  • One copy that is immutable or offline: at least one backup must be impossible to change or delete for a set period, even with an administrator password, even for you. If you cannot delete it, neither can an attacker who steals your credentials.
  • Zero errors when you verify: backups get tested and confirmed restorable on a schedule. As Veeam puts it, a backup only matters if you can count on it to restore when it is needed.

Neither addition requires an enterprise budget. Both are the difference between a bad day and a closed business.

The Copy Ransomware Cannot Touch

Immutable is a ten-dollar word for a simple idea: write once, locked for a set window. Modern cloud backup storage can be configured so that once a backup lands, nothing can alter or delete it for, say, 30 days. Not an attacker. Not a rogue employee. Not even your own IT company having a very bad morning. The lock simply does not open early.

The old-school version works too: a copy that is genuinely offline. A rotated drive that gets unplugged and shelved, or tape in a fire safe. Just be honest about the word offline. A USB drive that stays plugged into the server around the clock is online, and anything online can be encrypted. If your offsite copy lives in the cloud, confirm that immutability is actually switched on for your account, not just available on the vendor’s price sheet.

Test a Restore Every Quarter

The zero is the number everyone skips. We have met plenty of businesses with years of nightly backups that nobody had ever tried to restore. That is not a backup plan. That is a hope with a monthly invoice.

Put it on the calendar, quarterly. Restore a random handful of files and open them. Once or twice a year, restore an entire server or mailbox and time it. You are trying to learn two numbers: how long a full recovery takes, and how much recent work you would lose between backups. If the answers turn out to be three days and one day, decide now whether you can live with that, not during the emergency. And if a test fails, that is a win. You found out for free, on a calm Tuesday, instead of during the worst week of your business life.

The Bottom Line

The 3-2-1 rule still wins because it was never really about technology. It is about refusing to trust any single copy, any single device, or any single location. Ransomware simply added two entries to the list of things not to trust: any single network, and any backup you have not tested. Three copies. Two kinds of storage. One offsite. One immutable or offline. Zero errors when you test. If your current setup checks all five boxes, you are in better shape than most businesses your size.

We design, monitor, and test backup systems for small and mid-sized businesses across Denton County, and quarterly restore tests are part of the job, not an upsell. If you are not sure your backups would survive a truly bad week, we will help you find out the easy way. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).