Updated: July 15, 2026
3-2-1-1-0 is the modern evolution of the classic 3-2-1 backup rule.
It means: 3 copies, on 2 media types, with 1 offsite, 1 offline or immutable, and 0 recovery errors.
The extra "1" and "0" were added to survive ransomware, which now targets backups first.
It turns backup from a copy you hold into a recovery you have verified.
The 3-2-1 backup rule is older than most of the data it protects. For decades it was sound advice: keep enough copies, in enough places, and you would survive a failed disk or a fire.
Then ransomware rewrote the threat, and two more digits got added.
The result, 3-2-1-1-0, is the version worth knowing now, because it closes the two gaps that the classic rule left open. Here it is, in three minutes.
The 3-2-1-1-0 backup rule is a best-practice framework for protecting data so it can be reliably recovered, even from a ransomware attack. Each digit is a requirement. The table breaks it down.
| Digit | What It Means | Why It Matters |
|---|---|---|
| 3 | Keep at least 3 copies of your data | One primary and two backups, so no single loss is fatal |
| 2 | On 2 different types of media or storage | A fault in one storage type does not take out all copies |
| 1 | Keep 1 copy offsite | A local disaster (fire, flood) cannot destroy everything |
| 1 | Keep 1 copy offline, air-gapped or immutable | An attacker who reaches your network cannot alter or delete it |
| 0 | Verify 0 errors in recovery | Test restores, so the backups actually work when needed |
The classic 3-2-1 rule covered the first three digits: three copies, on two media types, with one offsite. It was designed for accidental data loss, a failed drive, a deleted file, a site disaster, and for that it worked well for years. What it never anticipated was an adversary who would deliberately hunt down and destroy the backups themselves.
Because ransomware attacks the backups first. In the Sophos State of Ransomware 2025 study, 94% of attacks attempted to compromise their victims' backups, and 57% succeeded. If your backups are reachable from your network, they can be encrypted or deleted alongside your production data, and the classic 3-2-1 rule offers no defence against that. So two requirements were added: an offline or immutable copy the attacker cannot touch, and a verification step that proves the recovery actually works.
It adds a copy an attacker cannot reach. An offline or air-gapped copy is physically or logically isolated from your network, and an immutable copy cannot be altered or deleted once written, even by someone with admin credentials. This is the single most important addition for surviving ransomware, because it guarantees that at least one clean copy exists no matter what happens to the rest. Without it, "we have backups" can quietly become "we had backups".
It means your recovery has been tested, and it works. A backup that has never been restored is a hope, not a safeguard. The "0" requires you to verify your backups by actually running test restores and confirming zero errors, so you know, in advance, that recovery will succeed rather than discovering a corrupt or incomplete backup during a real crisis. It is the difference between a backup and a recovery.
You build it into the architecture, not the intention. Keep three copies across two media types, with one offsite for disaster protection, one immutable or air-gapped for ransomware protection, and a scheduled testing regime that verifies recoveries with zero errors. Modern backup platforms and managed services, including disaster recovery as a service (DRaaS), can deliver much of this, but the discipline, especially the offline copy and the regular testing, is what makes the rule real rather than a poster on the wall.
The 3-2-1-1-0 rule is simple to state and easy to get wrong in practice, usually by skipping the immutable copy or the testing. Designing backups that genuinely meet it, immutable, isolated and verified, is where a data-protection partner earns its place.
Proactive Data Systems designs and runs data protection and cyber recovery for Indian enterprises, built around recovery you can prove, across Veeam, Veritas, Rubrik, ExaGrid and Dell EMC. We are a Cisco Preferred Cloud and AI Partner, Dell Platinum Partner and NetApp Preferred Partner, with 35 years in enterprise IT, more than 1,500 organisations served, and a 24/7 service desk in India. To check your backups against the rule, you can ask Proactive for a cyber-recovery readiness assessment
Sources: Ransomware targeting of backups (94% of attacks attempted, 57% succeeded): Sophos State of Ransomware 2025.
We'll get back to you shortly.