Skip to content

Backup

The 3-2-1-1-0 Rule: Why Your Backup Probably Doesn't Qualify

The backup rule grew two digits for the ransomware era. Most business backups quietly fail the new ones.

Allatoona Managed ITFebruary 4, 20265 min read

The rule you may already know

For years the standard was 3-2-1: three copies of your data, on two different types of media, with one copy off-site. It was good guidance, and it is still the foundation. But ransomware changed the threat, so the rule grew two more digits.

The two digits ransomware added

The modern standard is 3-2-1-1-0. The last two are the ones most businesses miss:

  • 3 — three copies of your data
  • 2 — on two different types of media
  • 1 — with one copy off-site
  • 1 — and one copy immutable or air-gapped, so ransomware cannot alter or delete it
  • 0 — with zero errors verified on your most recent restore test

Why most backups fail the last two

Plenty of businesses hit 3-2-1. Far fewer have an immutable copy — one an attacker who gets into your network cannot simply encrypt or delete along with everything else. And almost none can claim the zero: a recent, verified, error-free restore test.

That final zero is the whole point. A backup you have never restored is an unverified assumption. The 3-2-1-1-0 rule exists to force the question everyone avoids: have you actually proven you can get your data back?

How we meet it

We keep an immutable off-site copy that ransomware cannot touch, and we test the restore every quarter with a written report — the '0' made concrete. If your current backup cannot show you a recent successful restore, it does not qualify, and that is worth fixing before you find out the hard way.

Next step

Find out what is actually exposed — free, and no obligation

A 30-minute assessment of your backup, security and support gaps, with a written summary you keep whether or not you hire us.