What the 3-2-1-1-0 rule actually says
The 3-2-1-1-0 rule is a data-protection formula for how many copies of your data to keep, on what kind of media, and how to prove they actually work:
- 3 copies of your data — the production copy plus at least two backups.
- 2 different media or storage platforms, so a single technology failure or vendor outage cannot destroy every copy at once.
- 1 copy stored offsite, geographically separated from the primary site.
- 1 additional copy that is immutable or air-gapped — unreachable or unmodifiable even by an attacker with administrative credentials.
- 0 errors: every backup verified and every restore tested, not just assumed to work.
It reads as a natural progression, but the two extra digits — the second "1" and the "0" — were not part of the original formula. They were bolted on years later, in direct response to ransomware learning to target backups specifically. Understanding why they were added explains more about modern backup strategy than the checklist alone.
Where the rule came from
The "3-2-1" part of the name predates ransomware entirely. Photographer Peter Krogh coined the phrase in his 2006 book The DAM Book: Digital Asset Management for Photographers, distilling a set of practices he observed among IT professionals into a formula simple enough for working photographers — who were suddenly responsible for irreplaceable digital archives but were not systems administrators — to actually follow. Krogh did not invent the underlying idea of redundant, offsite copies; he gave it a memorable name. The rule was later formally credited to him in a 2012 US-CERT publication on data backup options, by which point it had already become the default recommendation across enterprise IT, and it remains a baseline endorsed by both CISA and NIST today.
The original 3-2-1 rule was designed for the threats of its era: disk failure, fire, flood, theft, and accidental deletion. Its core assumption was that no single physical event could plausibly destroy three copies of data spread across two media types and two locations. For roughly a decade, that assumption held.
Why 3-2-1 alone stopped being enough
The assumption broke when ransomware operators started treating backup infrastructure as a primary target rather than an obstacle to route around. Three copies on two media types with one offsite still fully satisfies 3-2-1 even if all three copies are reachable from the same set of compromised production credentials — which is exactly the scenario modern ransomware groups look for.
The scale of the shift is stark. Veeam's 2025 Ransomware Trends report found that 89% of ransomware victims had their backup repositories directly targeted during the attack, out of 1,300 organizations surveyed. Sophos's 2025 State of Ransomware report recorded the lowest backup-recovery rate in the six years the survey has run: only 54% of organizations were able to use backups to restore their data, and among those who ended up paying more than the attacker's original ransom demand, 38% cited failed or malfunctioning backups as a direct cause.
Three geographically separate copies do nothing to stop an attacker who already has the credentials to delete all three. That gap is precisely what the two extra digits were designed to close.
The extra "1": one copy attackers genuinely cannot reach
The additional "1" requires at least one copy that is immutable — protected from modification or deletion for a defined retention period, typically through object lock on cloud storage, Write Once Read Many (WORM) hardware, or a hardened repository with retention enforced at the storage layer — or air-gapped, meaning it has no standing network path from production at all.
This is a stricter requirement than it first appears. Two cloud regions from the same provider, both reachable with the same administrative account, do not satisfy it — geographic separation without credential separation is not real protection against an attacker who already has domain admin. Genuine implementations typically combine cloud-based immutable storage, for fast recovery, with a deeper offline or air-gapped copy for the worst-case scenario where even the immutable tier's management plane has been compromised.
CISA's ransomware guidance is explicit that offline, encrypted backups should be treated as the last line of defense specifically because they sit outside the blast radius that a compromised identity can reach.
The "0": proving the backup actually works
The "0" is the operational half of the rule, and the one organizations skip most often. It demands zero unverified backups — every backup checked for integrity, every restore path periodically tested end-to-end, not just monitored for a green "job succeeded" notification.
The gap between backup jobs that report success and restores that actually work is large and well documented. A 2025 industry survey found that 62% of organizations fail to perform regular backup-and-restore testing exercises, and 37% could not recover within their required recovery time objective specifically because backups were missing or had never been validated. When restores are attempted without proper integrity and malware scanning, an estimated 63% of organizations risk reintroducing the same infection that caused the outage in the first place — turning a recovery attempt into a second incident.
The "0" exists because a backup that has never been restored is not a control — it is an assumption. Verification, done on a schedule and measured against realistic recovery-time targets, is what converts that assumption into a fact you can rely on during an actual incident.
Common mistakes when implementing 3-2-1-1-0
- Counting two cloud regions as "two media." Media-type diversity means genuinely different storage technologies or platforms, not two instances of the same object store.
- Treating the extra "1" as satisfied by any offsite copy. Offsite addresses geography; immutable or air-gapped addresses credential compromise. A rule-compliant offsite copy that shares an identity plane with production does not close the gap that motivated adding the digit.
- Skipping the "0" because backup jobs report green. A successful backup job confirms data was written. It does not confirm the data is restorable, application-consistent, or free of the malware that will necessitate the restore.
- Applying the rule uniformly regardless of data criticality. Tier-one systems generally warrant more frequent verification and shorter RTOs than archival data; a single retention and testing policy across an entire estate usually under-protects the systems that matter most and over-spends on the ones that don't.
Is 3-2-1-1-0 still enough in 2026?
For most organizations, implementing 3-2-1-1-0 correctly — with the extra "1" and "0" genuinely enforced, not just checked off — closes the majority of the gap that let ransomware start targeting backups in the first place. It remains a sound operational baseline, and CISA and NIST both continue to endorse it as one.
Where it falls short is architecture: 3-2-1-1-0 answers "how many copies, where, and in what state," but says nothing about the access governance, network segmentation, and continuous monitoring that determine whether those copies stay that way under attack. That is the gap BackupSec's own Fibonacci Rule of Backup Security (5-3-2-1-1-0) is built to close, by adding five foundational security principles beneath the same copy-count formula. For an organization just getting 3-2-1-1-0 fully and verifiably in place, though, that is a next step — not a prerequisite.
Where BackupSec Comes In
At BackupSec, we help enterprise teams verify that their 3-2-1-1-0 implementation is real — not just documented — by making backup security observable, advisable, and provable.
Our approach combines three layers:
- ZeroMON delivers continuous observability over the entire backup estate — Veeam-ready monitoring with real-time job tracking, automated security checks, forensic audit trails for configuration drift, and one-click compliance reports. This is the layer that turns the rule's "0 errors" requirement from a hope into evidence.
- ZeroTAM provides dedicated expert advisory for backup architecture, immutability configuration, and ransomware recovery planning — the human layer most enterprises need to confirm their extra "1" is genuinely isolated, not just geographically distant.
- ZeroPEN pentests your backup infrastructure the way a real adversary would — targeting management planes, access controls, and immutability settings — and then runs actual restore scenarios to prove you can recover cleanly, completely, and within your stated RTO.
BackupSec is deployed on-premise, connects to your backup applications through read-only API access, and never moves backup data outside your environment.
Talk to BackupSec about your backup security posture →
Want to see how your own environment measures up? Score it with the free Backup Security Assessment.
