The 3-2-1-1-0 backup rule and what it means in practice
KINNEX Team5 min read
The classic 3-2-1 rule has grown an extension, because attackers now target backups first.
The rule
- 3 copies of your data: the live one and two backups.
- 2 different types of storage, so one failure mode does not take both.
- 1 copy off-site, away from fire, flood and theft.
- 1 copy offline or immutable, which ransomware cannot encrypt or delete.
- 0 errors, proved by regular verification and test restores.
Turning it into a design
Back up to local disk for quick restores, replicate to another site or cloud for disasters, and keep an immutable or air-gapped copy for the worst case. Protect the backup system itself with separate credentials and multi-factor authentication.
What gets missed
- Backing up servers but not SaaS data such as email and files.
- Never testing a restore.
- Backups that share the same login as the main domain.
- Retention too short to go back before an infection began.
- No documentation of the order of restoration.
Set targets
Agree a recovery point objective (how much data you can lose) and a recovery time objective (how long you can be down) for each system. They drive the design and the cost.
Prove it
Run test restores on a schedule, record results and fix failures. A backup that has not been restored is a hope, not a control.