The 3-2-1-1-0 backup rule and what it means in practice

KINNEX Team5 min read


The classic 3-2-1 rule has grown an extension, because attackers now target backups first.

The rule

  • 3 copies of your data: the live one and two backups.
  • 2 different types of storage, so one failure mode does not take both.
  • 1 copy off-site, away from fire, flood and theft.
  • 1 copy offline or immutable, which ransomware cannot encrypt or delete.
  • 0 errors, proved by regular verification and test restores.

Turning it into a design

Back up to local disk for quick restores, replicate to another site or cloud for disasters, and keep an immutable or air-gapped copy for the worst case. Protect the backup system itself with separate credentials and multi-factor authentication.

What gets missed

  • Backing up servers but not SaaS data such as email and files.
  • Never testing a restore.
  • Backups that share the same login as the main domain.
  • Retention too short to go back before an infection began.
  • No documentation of the order of restoration.

Set targets

Agree a recovery point objective (how much data you can lose) and a recovery time objective (how long you can be down) for each system. They drive the design and the cost.

Prove it

Run test restores on a schedule, record results and fix failures. A backup that has not been restored is a hope, not a control.

Bring us the site, the challenge or the target outcome

Book an infrastructure assessment, or reach KINNEX directly by phone or WhatsApp.