Updated: September 16th 2026

The 3-2-1 backup rule says you keep three copies of your data, on two different types of storage media, with one copy stored off-site. It has been the baseline for backup design since photographer Peter Krogh popularized it in the late 2000s, and it still holds. A backup setup that doesn’t meet it isn’t a strategy.

It is also incomplete. The rule was written to protect against hardware failure, human error and a building you can no longer get into. It was not written for an attacker who steals admin credentials, finds the backup repository and deletes it before encrypting production. That is now the standard ransomware playbook, which is why the rule grew two more digits: one copy that is immutable or offline, and zero errors when you verify that the backups actually restore.

That version is 3-2-1-1-0. This article explains what each of the five numbers requires in practice, and why the last two are the ones that decide whether you recover.

The Backup Paradox: Your Greatest Asset Is Now Your Biggest Target

Most organizations dramatically underestimate how exposed their backup systems actually are to ransomware attacks.

Traditional backup strategies focused on protection against hardware failures, accidental deletions, and natural disasters. Those threats still exist, but they’ve been overshadowed by a much more aggressive danger – threat actors who actively hunt for your backup repositories.

Why do ransomware attacks target backups? Because backups are the last line of defense. If attackers can compromise them, they’ve effectively removed your ability to recover without paying. It’s that simple.

In our October 29th webinar, “IT Resilience in Action,” Opti9’s VP of Sales Cory MacDonell and Pellera’s VP of Cybersecurity Sales Tony Petcou walked through exactly how modern ransomware campaigns operate. The pattern is consistent: gain initial access, move laterally through the network, escalate privileges, and then – before encrypting production data – locate and neutralize backup systems.

This isn’t opportunistic cybercrime. It’s methodical, well-funded, and increasingly automated. Ransomware-as-a-Service platforms have industrialized these attacks, making sophisticated backup targeting techniques available to a much broader range of threat actors.

The question isn’t whether your backups are a target. They already are. The question is whether your backup strategy can withstand a determined ransomware attack.

Breaking Down the 3-2-1-1-0 Backup Strategy

The 3-2-1-1-0 framework isn’t just another IT acronym – it’s a multi-layered defense strategy designed specifically to counter modern ransomware tactics. Each number represents a critical layer of protection, and skipping even one significantly increases your risk.

Here’s what each component means and why it matters:

3 Copies of Your Data

You need three separate copies of every critical workload: your production data plus two backups. This isn’t redundancy for redundancy’s sake. Multiple copies ensure that if one backup becomes corrupted or compromised, you have alternatives.

Think of it as the difference between having one spare tire versus two. If that single spare is flat when you need it, you’re stranded.

2 Different Media Types

Your backup copies should exist on at least two different types of storage media. This might mean disk and tape, or on-premises storage and cloud object storage. The key is diversity.

Why does this matter? Because different media types have different vulnerability profiles. A ransomware variant that can encrypt network-attached disk storage may not be able to touch air-gapped tape or properly configured cloud object storage. By diversifying media, you’re forcing attackers to compromise multiple systems with different security controls.

1 Copy Off-Site

At least one backup copy must be stored in a geographically separate location from your primary data center. This protects against site-wide disasters—fires, floods, extended power outages—but it also creates distance between your production environment and your recovery capabilities.

For ransomware protection, off-site storage is critical because attackers who gain access to your primary network shouldn’t automatically have access to geographically separated backup repositories. This separation buys you recovery options even if your main facility is completely compromised.

1 Copy Offline or Immutable

This is where modern backup strategies diverge sharply from older approaches. You need at least one backup copy that is either completely offline (air-gapped) or stored with immutability enabled.

Immutable storage means that once data is written, it cannot be modified or deleted – not by administrators, not by applications, and critically, not by ransomware. Even if attackers gain domain admin credentials and move through your network with elevated privileges, they cannot destroy immutable backups.

Air-gapped backups take this concept further by being physically or logically disconnected from your network entirely. Tape libraries that are robotically managed, or cloud storage that’s only accessible through tightly controlled APIs, serve this purpose.

During the webinar, MacDonell emphasized that immutability and air-gapping have become non-negotiable requirements for ransomware protection. “Tools like air-gapping, insider protection, and immutability are becoming more and more prevalent when it comes to backup,” he noted. “Cybersecurity attackers know that backups exist, so their goal is to get money out of you, and they do that by eliminating your recovery options.”

Organizations that skip this layer often discover—too late—that attackers moved quietly through their environment for weeks, identifying backup systems and positioning themselves to strike everything simultaneously. Immutable Veeam backups and air-gapped storage provide critical protection against these coordinated attacks.

0 Errors in Backup Verification

The final component is often the most overlooked: zero errors in your backup and recovery verification process. It’s not enough to run backups. You need to continuously verify that those backups are actually recoverable.

How many organizations discover during a ransomware incident that their backups haven’t been working properly for months? Far too many. Backup jobs that report “successful” but are missing critical data, incremental backups with broken chains, or recovery processes that fail when actually tested—these are catastrophic discoveries during an emergency.

The “0” in 3-2-1-1-0 demands regular testing and validation. This includes automated backup verification, periodic recovery drills, and—critically—testing your recovery processes in isolated environments to ensure you’re not restoring compromised data back into production.

As MacDonell explained in the webinar, rapid recovery isn’t just about speed—it’s about confidence. “You need to make sure that when you do recover them, that they’re not also infected. How do you quickly get back up? How do you validate that the data is intact? How do you validate that the attackers are no longer around? Those are all part of that rapid recovery data protection strategy.”

This is where Disaster Recovery as a Service (DRaaS) becomes essential—providing not just backup capabilities but tested, validated recovery processes that work when you need them most.

Is the 3-2-1 backup rule still enough?

Search any IT forum for the 3-2-1 rule and you’ll find the same argument running through the threads: the rule is out of date. It predates cloud storage, it predates ransomware-as-a-service, and “two media types” reads oddly when most organizations now back up to disk and to a cloud bucket rather than to tape.

The argument is half right.

The three original digits still hold, and the people arguing about them are mostly arguing about interpretation. “Two media types” was never really about tape versus disk. It was about not letting every copy share a single failure mode, and a local disk array plus cloud object storage satisfies that as well as disk plus tape ever did. “One off-site” means what it always meant. Three copies is still the minimum that survives one copy failing while you restore from another.

What the rule was never designed for is an adversary. 3-2-1 assumes the threats are accidental: a failed drive, a deleted file, a flood. None of those care where your backups are. A ransomware operator does. The attack chain described earlier in this article, access, lateral movement, privilege escalation, then backups before production, runs straight through a 3-2-1 setup if all three copies are reachable from a compromised domain admin account. They get deleted together.

That is the gap the two added digits close. The extra 1 requires a copy the attacker cannot alter or delete even with full privileges, either because it is immutable or because it is offline. The 0 requires proof that the backups restore cleanly, because a backup job that has been silently failing for months is not a copy, and a restore that brings the attacker’s foothold back with it is not a recovery.

So the honest answer is that 3-2-1 is still the floor, and it is no longer the standard. If your backups meet 3-2-1 and nothing more, you are protected against everything except the one threat that targets backups on purpose.

Why Each Layer Matters: What Happens When You Skip One

Understanding the framework is one thing. Understanding why each layer is essential is what drives implementation. Let’s look at what happens when organizations cut corners:

Skip the third copy: You’re vulnerable to simultaneous corruption of your primary and secondary backups. This happens more often than you’d think—particularly with backup solutions that use the same underlying storage infrastructure for multiple backup targets.

Skip diverse media: Ransomware that encrypts your disk-based backups can often reach all disk-based copies if they’re on the same network. Media diversity forces attackers to develop multiple compromise paths.

Skip off-site storage: Site-wide disasters—or attackers who gain physical access to your facility—can eliminate both production and backup systems. Off-site copies protect against these scenarios.

Skip immutability/air-gapping: This is the most dangerous omission. Without immutable or offline copies, attackers who gain elevated privileges can systematically delete every backup they can access. You’re left with no recovery options except paying the ransom or accepting total data loss.

Skip verification: You only discover your backups don’t work when you desperately need them. By then, it’s too late to fix the problem.

Each layer compounds the protection provided by the others. This isn’t about redundancy – it’s about defense in depth against attackers who are specifically targeting backup infrastructure.

Immutability and air-gapping: the digit that separates 3-2-1 from 3-2-1-1-0

If there’s one takeaway from the rise in backup-targeted ransomware, it’s this: immutability and air-gapping are no longer optional features. They’re fundamental requirements for ransomware protection.

Traditional backup systems operated on the assumption that IT administrators had legitimate reasons to delete old backups—managing storage capacity, implementing retention policies, or removing data for compliance reasons. These systems were designed to make data management flexible.

But that flexibility became a liability the moment attackers realized they could abuse it. If an administrator can delete backups, so can an attacker with stolen admin credentials. And modern ransomware often gains domain admin access specifically to ensure it can reach backup systems.

Immutable storage solves this problem by implementing write-once-read-many (WORM) controls at the storage layer. Once backup data is written with immutability enabled, it cannot be altered or deleted until the retention period expires – regardless of who attempts the operation. Veeam’s immutable backup repositories provide exactly this protection.

During the webinar, Petcou emphasized the importance of understanding your attack surface: “When we can get in early and start to advise and consult, it’s asking questions and getting the client to start to show us where the pain exists. Many times, it’s about understanding what data do you have? What do you consider crown jewels? And then figuring out who are the people that have access to it.”

Immutability addresses the “who has access” question by removing delete capabilities entirely during the retention window. Even compromised privileged accounts cannot eliminate immutable backups.

Air-gapping takes a different approach by creating complete logical or physical separation between production environments and backup storage. An air-gapped backup repository might be:

  • Tape media stored offline in a physically secure location
  • Cloud object storage accessed only through restricted APIs with time-delayed delete capabilities
  • Backup infrastructure on completely isolated networks with no persistent connections to production systems

The key principle is that attackers moving through your production network cannot directly reach air-gapped backups. This creates a recovery option that remains available even if your entire production environment is compromised.

Many organizations are now implementing both immutability and air-gapping in combination. Immutable backups on cloud object storage that’s only accessible through tightly controlled API calls, for example, provides multiple layers of ransomware protection. Even if attackers compromise the backup management interface, they cannot reach the underlying immutable storage.

Beyond Backup: Building a Complete Data Protection Strategy

The 3-2-1-1-0 framework is essential, but it’s only part of a complete data protection strategy. Modern ransomware protection requires integration between backup systems and broader cybersecurity controls.

This is where partnerships like the one between Opti9 and Pellera become critical. Backup and disaster recovery expertise needs to combine with proactive threat detection, security monitoring, and incident response capabilities.

Petcou outlined Pellera’s approach during the webinar: “It’s advise, implement, manage. We call it that AIM strategy. We don’t want to wait until there is a problem. We are best when we can get in early, start to understand use cases, build a roadmap.”

That proactive approach is essential because backup systems don’t exist in isolation. They’re part of a broader IT infrastructure that includes identity management, network security, endpoint protection, and security monitoring. An effective ransomware defense requires all these components to work together.

Key elements of this integrated approach include:

Identity and access management: Implementing least-privilege access controls ensures that even if attackers compromise one set of credentials, they can’t automatically reach backup systems. Multi-factor authentication, privileged access management, and regular access reviews are all critical.

Network segmentation: Backup infrastructure should be isolated from production networks wherever possible. Attackers who compromise a user workstation or production server shouldn’t automatically have network access to backup systems.

Security monitoring: You need continuous monitoring for anomalous activity around backup systems. Unusual access patterns, unexpected deletion attempts, or API calls from unauthorized sources should trigger immediate investigation.

Regular testing: Your disaster recovery plan needs to be tested regularly in realistic scenarios. Tabletop exercises, isolated recovery tests, and full DR failover drills all serve different purposes, but they’re all necessary to ensure your backup strategy actually works under pressure.

Third-party risk management: As Petcou emphasized in the webinar, third-party integrations are a major blind spot. “Third party is a big red flag for me—just understanding who you have, what are their policies. Because a lot of times your businesses are going down because of somebody they’re doing business with.”

The organizations that recover successfully from ransomware attacks aren’t the ones with the most sophisticated backup technology. They’re the ones that have integrated their backup systems into a comprehensive, tested, continuously improved data protection strategy.

What inadequate backup protection actually costs

The number to hold on to from the webinar is 22 days: the average time to resolution for a ransomware incident, according to data MacDonell shared during the session. For a mid-market organization that is three weeks of interrupted revenue, staff who can’t work, and clients asking questions you can’t yet answer. In regulated industries like legal and financial services, it also means reporting obligations and the possibility of regulatory scrutiny on top of the operational damage.

Paying the ransom doesn’t shorten the problem. The same webinar cited that 69% of organizations that paid were attacked again. A payment buys a decryption key of uncertain quality and marks you as an organization that pays.

Getting back online is only worth anything if what you restore is clean. As MacDonell put it: “You need to make sure that when you’re leveraging your disaster recovery protection strategy and going back online, that they are clean – that you’re not just recovering to the same issues.”

Davis Wright Tremaine, a global law firm, chose Opti9 for disaster recovery for exactly this reason. 

Assessing your backup strategy against 3-2-1-1-0

Most organizations built their backup systems years ago and have not revisited the design since. If yours predates immutable storage, start with an honest read of where you are:

  • How many copies of your critical data actually exist right now?
  • Are they on different storage types, or is everything on the same array?
  • Is at least one copy in a different location?
  • Can any copy be deleted by someone holding a domain admin account? If yes, you do not have an immutable or offline copy.
  • When did you last restore a full system, not a single file, and did it work?
  • How long would recovery take if the whole production environment were compromised?

Then work through the gaps in this order.

Start with immutability. If you change one thing, make it this. Adding an immutable backup target protects against the most common ransomware pattern, which is deleting backups before encrypting production. Veeam supports this through hardened repositories and immutable object storage.

Test a real restore. Schedule it, run it in an isolated environment, and time it. A restore test is the only way to satisfy the 0 in 3-2-1-1-0, and it usually surfaces the chain breaks and missing data that backup job reports hide.

Set your RTO and RPO per system. Not every workload needs the same protection. Knowing your recovery time objective (RTO) and recovery point objective (RPO) for each tier-one system tells you how often to back up, how long to retain, and what recovery architecture you actually need.

Check who can reach your backups. Review third-party integrations and vendor access into your environment. As Petcou noted in the webinar, “a lot of times your businesses are going down because of somebody they’re doing business with.”

Write the runbook down. Documented, tested recovery procedures with named owners and decision points. “We have backups” and “we have a tested runbook” are very different levels of readiness.

If your team doesn’t have the time or the depth to do this properly, that is the normal situation for a 50 to 150 person organization with one or two IT people, and it is what managed backup and disaster recovery services exist for.

Why Opti9 and Veeam for the 3-2-1-1-0 backup rule

Implementing the 3-2-1-1-0 strategy isn’t just about following a framework—it requires backup infrastructure specifically designed to defend against modern ransomware tactics.

Opti9 is Veeam’s largest Cloud Service Provider in Canada and second-largest in North America. That partnership isn’t incidental—Veeam’s platform is purpose-built to support immutability, air-gapping, and rapid recovery capabilities that the 3-2-1-1-0 strategy demands.

Key capabilities of Opti9’s Veeam-powered Backup as a Service include:

Immutable backup repositories: Veeam supports multiple forms of immutability, including Linux hardened repositories and object storage with immutability enabled. Once backup data is written to an immutable repository, it cannot be altered or deleted until the retention period expires—even by administrators with full privileges. This provides critical ransomware protection for your backup data.

Air-gapped backups: Veeam Cloud Connect and tape integration support true air-gapped backup architectures where backup data is logically or physically isolated from production networks—making it impossible for ransomware to reach.

Instant recovery: When you do need to recover from a ransomware attack, Veeam’s instant VM recovery capabilities can have systems running from backup storage in minutes while full restoration completes in the background. This dramatically reduces your RTO and gets your business operational faster.

Built-in verification: Veeam includes SureBackup and SureReplica technologies that automatically verify backup recoverability by performing test recoveries in isolated environments. This addresses the “0” in 3-2-1-1-0—ensuring zero errors in backup verification.

Ransomware detection: Veeam can detect anomalies in backup data that may indicate ransomware activity, including unusual file type changes or entropy analysis that suggests encryption.

Opti9’s infrastructure adds additional protection layers:

  • SOC 2 Type II certified data centers with physical security controls
  • Geographic diversity across 11 global data centers supporting true off-site backup requirements for ransomware resilience
  • 99.99% uptime SLA ensuring backup systems remain available when you need them
  • Compliance certifications (including HIPAA, PCI-DSS, and others) for regulated industries
  • 24/7 support and disaster recovery assistance for ransomware incidents

MacDonell emphasized during the webinar that this combination of technology and expertise is what enables rapid recovery from ransomware attacks: “We’ve got to be at the forefront of what it all is, otherwise our reputation goes sideways. So we’re kind of moving into the reactive rapid recovery piece.”

That commitment translates into backup systems that are designed from the ground up to withstand ransomware attacks—not just recover from hardware failures. Organizations also need to protect SaaS applications like Microsoft 365, where Microsoft’s shared responsibility model means you’re accountable for backing up your own data.

The bottom line on the 3-2-1 backup rule

The 3-2-1 rule is still right. Three copies, two media types, one off-site is the floor for any backup strategy, and it has been for well over a decade. What changed is the threat. Attackers now go after backups first, and a strategy designed for hardware failure has no answer to that on its own.

3-2-1-1-0 is the same rule with that answer built in: one copy nobody can delete, and zero doubt that the backups restore. Organizations running it on Veeam immutable repositories with tested recovery can get through a ransomware incident without paying and without weeks of downtime.

If you cannot say with confidence which of the five numbers your current setup meets, that is the place to start.

Post authors:

Similar Posts

Need more advice about growing
your Cloud Business?

Visit the Opti9 partner portal to learn more about our programs, and support on offer to help you succeed. 

Don’t Risk Losing Your Critical Data

Data loss can happen to any business at any time. Our backup specialists will ensure your data is properly protected with reliable, tested backup solutions that give you peace of mind.