3-2-1-1-0: The Two Digits Most Backup Plans Are Missing

Read MoreBack to Blog

3-2-1 backup rule

The 3-2-1 backup rule has been standard guidance for decades, and for good reason. Three copies of data, on two different types of storage, with one copy offsite. It is simple enough to remember and strong enough to survive a failed drive, a flooded server room, or a deleted folder.

It was designed for a world where data was lost by accident. That is no longer the main threat.

Ransomware operators learned years ago that encrypting production data is only half the job. If a clean backup exists, the victim restores and refuses to pay. So attackers now go looking for the backup system first, and they often find it, because backups are usually online, reachable from the network, and managed with credentials an intruder has already collected.

Where the 3-2-1 Backup Rule Stops Short

Under the classic rule, all three copies can be deleted by anyone with sufficient access. Two storage types does not help if both are reachable from a compromised administrator account. One offsite copy does not help if offsite means a cloud target that is mounted and writable.

CISA’s #StopRansomware guidance reflects this directly, emphasizing offline or otherwise isolated backup copies rather than simply distributed ones. The FBI’s 2025 Internet Crime Report logged 3,611 ransomware complaints and identified 63 new ransomware variants during the year, averaging just over five new variants each month. This is an actively developing category, not a static one.

The response is to extend the rule by two digits. Three copies, two media types, one offsite, one immutable or air-gapped, and zero errors on verification.

The First Extra 1: Immutable Backup

An immutable backup cannot be modified, encrypted, or deleted for a defined retention period. Not by an administrator, not by a compromised account, and not by ransomware holding valid credentials. The storage layer refuses the operation.

This is the control that survives the attack pattern described above. When an intruder reaches the backup system and issues delete commands, an immutable copy stays intact. Air-gapped copies achieve a similar outcome by keeping the data physically or logically disconnected.

Xobee holds backup copies in Xobee-owned and managed offsite colocation, which keeps the recovery path operationally separate from the production environment rather than merely in a different building.

The 0: Verified, Not Assumed

The final digit is the one organizations discover last and regret most. Zero means zero errors on automated restore testing.

The cost of discovering this late is well documented. IBM’s Cost of a Data Breach Report put the global average cost of a breach at $4.99 million in 2026, a record high, and recovery time is a substantial component of that total. Every hour spent establishing whether a restore will work is an hour of downtime.

A backup job reporting success confirms that data was written. It does not confirm the data can be read back, that the files are intact, or that a server will actually boot from the image. Plenty of organizations have learned during an outage that their backups had been failing quietly, or completing while capturing nothing useful.

Xobee uses SureBackup to test restores automatically, so recoverability is demonstrated on a schedule rather than assumed until the day it matters. This is the difference between having backups and having a recovery capability.

Microsoft 365 Is Not Backed Up For You

One gap deserves separate mention because it is so widespread. Microsoft does not back up tenant data on a customer’s behalf. Retention policies and recycle bins are not backups, and their windows expire.

Veeam for M365 provides independent backup and granular recovery across Exchange Online, OneDrive, SharePoint, and Teams, covering accidental deletion, malicious deletion, ransomware, and account compromise. Independent copies also survive the loss of the account itself, which retention features inside the tenant cannot promise.

Applying the Standard

  • Three copies: production data plus two backups.
  • Two media types, so a single failure mode cannot take out multiple copies.
  • One copy offsite, protecting against fire, flood, theft, and site-wide outage.
  • One copy immutable or air-gapped, protecting against deletion by an intruder.
  • Zero errors, confirmed by automated restore testing on a schedule.

Backup and recovery is one of the eight areas covered in a cybersecurity risk assessment, and it is where the gap between believed protection and actual protection tends to be widest.

 

FAQs: The 3-2-1 Backup Rule

Is the 3-2-1 backup rule still relevant?

Yes, as a foundation. It handles hardware failure, accidental deletion, and site loss well. It was not designed for an attacker who deliberately targets backup systems, which is why the additional immutable copy and verification step were added.

What makes a backup immutable?

An immutable backup is written so it cannot be altered or deleted for a set retention period, enforced at the storage layer rather than by permissions. Credentials alone cannot override it.

How often should restores be tested?

Automated verification should run continuously as part of the backup process. Manual recovery exercises for critical systems are worth performing at least annually, and after any significant infrastructure change.

Confirm your backups would actually survive a ransomware event. Contact Xobee Networks to request a Cybersecurity Risk Assessment covering backup, immutability, and verified recovery. With 30 years of proven results, Xobee delivers enterprise-grade protection through its managed security offerings so your organization can focus on growth rather than recovery.

Recent Posts

Call Us Today!

Contact us today for a free consultation

Please let us know what service(s) you're interested in and we'll contact you to setup a consultation call or meeting. If you prefer to speak with a live representative, give us a call at (844) 490-2800.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.