The 3 2 1 1 0 Backup Strategy Explained

The 3-2-1 backup strategy has been the industry standard for so long that the new variant (the 3-2-1-1-0) sounds like a typo. It is not. The extra numbers serve as the answer to the ransomware variant that the 3-2-1 was…

Dark cinematic editorial image for The 3 2 1 1 0 Backup Strategy Explained - abstract cyan digital composition, hacker aesthetic, no text no logos

4 MIN READ

The 3-2-1 backup strategy has been the industry standard for so long that the newer variant, the 3-2-1-1-0, sounds like a typo. It is not. The two extra numbers are the answer to a ransomware variant the original 3-2-1 was never designed to handle, the kind that targets the backup the same way it targets the production system, the one the original rule quietly assumed the attacker would not reach. The honest framing matters here, because the strategy your team certified last year is the same strategy the ransomware operator read about last year.

What follows is the working version of the field guide. The shorter version is what the ops lead actually has time to read.

What 3-2-1 was for

Three copies of the production data, living in three places, was the original idea. Production, backup, offsite, the three copies protected against the single point of failure that any one of those environments could become. The disk dies, the offsite saves you. The site floods, the offsite saves you.

Two media for the backup meant the copy lived on two different types of storage, the disk and the tape, or the disk and the cloud, so a media failure on one could not take the backup with it. The disk crashes, the tape restores. The cloud goes down, the disk is still local.

One offsite was the third number, and the one most enterprises skipped because offsite was expensive to maintain. The site burns, the offsite is the only thing that comes back online. Skip the offsite and the strategy is just 3-2 with extra steps.

What 3-2-1-1-0 adds

The fourth number, the one immutable, is the part that actually defeats modern ransomware. At least one of the copies sits immutable, the copy that cannot be modified and cannot be deleted inside the retention window, the kind of storage that AWS S3 Object Lock, Azure Blob Immutable Blob Policy, and Google Cloud Bucket Lock all provide. The immutable copy is the one the attacker cannot touch, the one you restore from when everything else has been encrypted.

The fifth number, the zero, is the verification half. The backup that has not been restored counts as a backup that does not exist. The strategy requires the backup admin to verify, test, and run the recovery drill that proves the data the backup claims to hold can actually be brought back. No recovery drill, no zero, no 3-2-1-1-0.

How to land the strategy

Start with the immutable copy. AWS S3 Object Lock, Azure Blob Immutable Blob Policy, and Google Cloud Bucket Lock are the three most common options. Most enterprises can turn this on in an afternoon and pay a few hundred dollars a month for the storage. The immutable copy that gets turned on now becomes the copy the backup admin will need when the breach lands.

Run the recovery drill every quarter. Pick a non critical workload, take the production backup, restore it to an isolated environment, prove that the data is there and the application starts. The drill that finds the broken backup before the breach is the drill that makes the zero mean anything. Skip the drill, the zero is a number on a slide.

Document the recovery time. Recovery time matters because the executive team cannot fund what they cannot measure. Hours to recover, target in hours, actual in hours. The backup admins who have those three numbers ready for the next budget cycle hold the line on the 3-2-1-1-0 when the next cost cutting review comes around. The backup admins who do not have the numbers lose the immutable copy in the next round of cuts.

Abstract 3-2-1-1-0 backup as glowing cyan concentric rings on a dark navy surface, dramatic chiaroscuro lighting from above.
The 3-2-1-1-0 in 2026: 3 things the original covered, 2 things the new numbers add, 3 moves to land the strategy.

The bottom line

The 3-2-1 was the right rule for a different threat. The 3-2-1-1-0 is the rule for ransomware that targets the backup the same way it targets production. The backup admin that has the five numbers holds the line. The backup admin that still has the three numbers is one wiper away from finding out which one they are.


Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading