HomeBlogDisaster Recovery

The 3-2-1 Backup Rule Explained, With 3-2-1-1-0 and Immutable Copies

Pixel-art illustration of a robot whisking batter in a sunlit kitchen while following a recipe on a tablet

The 3-2-1 backup rule says to keep three copies of any important data (the original and two backups), store them on two different types of storage, and keep one copy offsite. A 2012 paper for US-CERT, which CISA still hosts, recommends it and credits Peter Krogh's The DAM Book, and the rule holds up today. Ransomware added two requirements, captured in the extended 3-2-1-1-0 rule: one copy that is immutable or offline, and zero errors when restores are tested.

This guide explains each part, shows a design for a small office and ends with a checklist. For the definition of an immutable copy, see our immutable backup glossary entry, and for why Microsoft 365 data needs its own backup, read Microsoft 365 backup and shared responsibility. Our disaster recovery services design, run and test this kind of setup.

What is the 3-2-1 backup rule?

The US-CERT paper Data Backup Options, by Paul Ruggiero and Matthew A. Heckathorn of Carnegie Mellon University, sets it out this way, citing Peter Krogh's The DAM Book (second edition, 2009) as its source:

  • 3: keep three copies of any important file, one primary and two backups.
  • 2: keep the files on two different media types, to protect against different types of hazards.
  • 1: store one copy offsite, outside your home or business facility.

Each number covers a different failure. Three copies mean one failed backup still leaves you a good one. Two media types mean a single fault, such as a failed storage array or a bad firmware update, cannot take out both backups. The offsite copy survives whatever happens to the building: fire, flood, theft or a burst pipe above the server closet.

What counts as a copy, a media type and offsite today?

Part of the ruleCountsDoes not count
A copyAn independent backup with its own version history and retention, restorable without the originalOneDrive or other file sync, RAID and replication, which copy deletions and encryption along with everything else
Two media typesTwo separate storage systems with different failure modes and different credentials, such as a backup appliance and cloud object storage, or disk and tapeTwo folders on the same NAS, or two volumes on one storage array
One offsiteA different building, or a cloud region away from your office, under separate administrative credentialsA second server in the same closet, or a USB drive that never leaves the office

The weak point is usually reachability. A backup on the same network, with the same admin passwords as everything else, is among the first things an attacker looks for and deletes.

What is the 3-2-1-1-0 backup rule?

3-2-1-1-0 extends the original rule, as described in the backup vendor Veeam's best-practice guide. It keeps 3-2-1 and adds two requirements:

  • 1: keep at least one copy on immutable, air-gapped or offline media. Veeam's guidance says that ideally every copy is immutable, with short-term backups locked for at least one to two weeks and long-term retention locked for at least four weeks.
  • 0: zero errors when every backup's recoverability is verified, which in Veeam's products means automated restore tests.

The idea applies to any backup product. The extra 1 answers ransomware; the 0 answers the backup that ran for months but could never be restored.

How do immutable and offline copies stop ransomware?

CISA's #StopRansomware Guide explains the threat: many ransomware variants try to find and delete or encrypt accessible backups, so that restoring is impossible without paying. It recommends offline, encrypted backups of critical data, with their availability and integrity tested regularly.

Immutable storage gives the same protection without carrying drives offsite. In a write once, read many (WORM) store, a backup cannot be changed or deleted until its retention period ends. Microsoft's documentation for immutable Azure Blob storage, for example, says data under a time-based retention policy cannot be modified or deleted by any user, including account administrators. Once the policy is locked it cannot be deleted, and its retention period can be extended but never shortened. Azure Backup's immutable vaults can likewise be locked so the setting cannot be reversed. Other clouds and backup appliances offer equivalents, often called object lock.

CISA adds two cautions: immutable storage does not meet the compliance criteria of certain regulations, and a misconfigured retention lock can impose significant cost, because you keep paying to store everything it holds. Set retention deliberately and test the lock before you rely on it. Immutability protects only the copy, so keep the backup system's own admin accounts separate from your everyday domain and protected with MFA.

What does a 3-2-1 backup setup look like for a small business?

Here is an illustrative design for a 25-person office with one on-site server host running a file server and an accounting database, plus Microsoft 365. It is an example written for this article, not a client's setup.

CopyWhere it livesMedia and protectionProtects against
1. Production dataThe server host and Microsoft 365The originalNothing on its own
2. Local backupA backup appliance or repository on separate hardware, not joined to the domain, with its own admin accountsDisk, with backups every few hours for the database and nightly for filesDeleted files, failed disks and bad updates, with the fastest restores
3. Offsite immutable backupCloud object storage in another region, with a locked retention period of at least 30 daysObject storage with object lock (WORM)Ransomware, loss of the site and a compromised admin account
Microsoft 365 backupA cloud-to-cloud backup service that stores mail, OneDrive, SharePoint and Teams outside the tenantSeparate cloud storage with separate credentialsDeletions, departures and encrypted files syncing up from a laptop

Add the small pieces recoveries depend on: exported configurations for the firewall and switches, a current list of systems in recovery order, and a printed or offline copy of the recovery runbook and the credentials it needs. CISA recommends keeping offline backups and hard copies of IT documentation for exactly this reason.

How often should you test restores?

CISA's guidance is to test backup procedures regularly, and the 0 in 3-2-1-1-0 sets the bar: a backup counts only if it restores. A cadence that works for most small businesses:

  • Daily: check every backup job's result, and fix and re-run failures the same day.
  • Monthly: restore a sample of files and a mailbox, and open them.
  • Quarterly: restore a full server or database to an isolated network, time it and compare the result with its recovery time objective.
  • Yearly: run a full recovery exercise from the offsite immutable copy, with the people who would do it for real.
  • After any major change: a new server, a migration or a new application gets its own restore test.

Record the date, what was restored, from which copy, how long it took and what failed.

What goes on a 3-2-1 backup checklist?

  • Every system and data set the business needs is listed, including Microsoft 365 and other cloud apps.
  • Each has a recovery point objective (how much data you can afford to lose) and a recovery time objective (how long it can be down).
  • Each has three copies: production plus two backups.
  • The two backups sit on different storage systems with different admin credentials.
  • One copy is offsite, in another building or cloud region.
  • At least one copy is immutable or offline, with a retention lock long enough to reach back before an attack.
  • Backup admin accounts are separate from everyday accounts and protected with MFA.
  • Backups are encrypted, and the encryption keys are stored away from the backups.
  • Microsoft 365 has its own backup outside the tenant.
  • Job results are checked daily, and restore tests follow a written schedule.
  • The recovery runbook, system list and key credentials exist offline.
  • Someone outside IT sees the restore test results every quarter.

Who maintains backups, and how do you validate them?

Three roles keep a 3-2-1 setup honest. A backup operator, in house or at your IT provider, checks jobs daily, fixes failures and runs the restore tests. Each system owner agrees that system's recovery targets and signs off its restore tests. An executive reviews a short quarterly report: what was tested, what restored, how long it took and what is still open.

Validation means evidence, not a dashboard of green ticks. Keep a log of every restore test. Check the retention lock on the immutable copy in its policy settings, and confirm in a test that a backup inside its retention period cannot be deleted. At least once a year, restore from the offsite copy onto clean hardware or a clean cloud environment, because that is the path you would take after ransomware.

How does NetSys help with backups?

We set a recovery time objective and a recovery point objective with each system's owner, keep offline and immutable backup copies, and add cloud failover where downtime costs the most. As managed backup, we run the backup jobs, check them daily and test restores on a schedule, recording the scenario, what restored and the measured time. Microsoft 365 gets independent cloud-to-cloud backup alongside server and application recovery. Every NetSys client hit by ransomware has fully recovered, and agreements run month to month.

Book a call with an engineer to map your current backups against 3-2-1-1-0 and find the copy that is missing.

Frequently asked questions

What does a 3-2-1 backup checklist cover?

The systems and data to protect, recovery targets for each, the three copies and where they live, the two storage types, the offsite copy, the immutable or offline copy and its retention lock, backup credentials and encryption, Microsoft 365, the daily checks, the restore test schedule and the offline runbook.

Who maintains a 3-2-1 backup setup?

A backup operator who checks jobs daily and runs restore tests, system owners who set recovery targets and sign off the tests, and an executive who reviews the results quarterly. In a small business the operator is usually your IT provider.

How do we validate that our backups work?

Restore from them on a schedule and record the results: sample files monthly, a full system quarterly and a full exercise from the offsite immutable copy every year. Check that the retention lock holds, and treat any failed restore as an incident to fix.

Does cloud storage count as the offsite copy?

Yes, if it is a true backup in a location away from your office, under credentials separate from your production systems, and ideally immutable. A synced folder does not count, because it mirrors deletions and encryption.

Is Microsoft 365 or OneDrive a backup?

No. Microsoft 365 holds your primary copy of mail and files, and its recycle bins and retention settings are not restore points you control. A separate backup stored outside the tenant counts as one of your copies; the Microsoft 365 data itself does not.

Is the 3-2-1 rule still enough?

The structure is, but on its own it no longer stops ransomware, because attackers delete every backup they can reach. Add the two pieces in 3-2-1-1-0: one immutable or offline copy, and restore tests that prove zero errors.

Sources and further reading

Disaster Recovery

Discuss disaster recovery for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.