The rule you may already know
For years the standard was 3-2-1: three copies of your data, on two different types of media, with one copy off-site. It was good guidance, and it is still the foundation. But ransomware changed the threat, so the rule grew two more digits.
The two digits ransomware added
The modern standard is 3-2-1-1-0. The last two are the ones most businesses miss:
- 3 — three copies of your data
- 2 — on two different types of media
- 1 — with one copy off-site
- 1 — and one copy immutable or air-gapped, so ransomware cannot alter or delete it
- 0 — with zero errors verified on your most recent restore test
Why most backups fail the last two
Plenty of businesses hit 3-2-1. Far fewer have an immutable copy — one an attacker who gets into your network cannot simply encrypt or delete along with everything else. And almost none can claim the zero: a recent, verified, error-free restore test.
That final zero is the whole point. A backup you have never restored is an unverified assumption. The 3-2-1-1-0 rule exists to force the question everyone avoids: have you actually proven you can get your data back?
How we meet it
We keep an immutable off-site copy that ransomware cannot touch, and we test the restore every quarter with a written report — the '0' made concrete. If your current backup cannot show you a recent successful restore, it does not qualify, and that is worth fixing before you find out the hard way.