A complete implementation guide for the 3-2-1 backup rule and its modern extensions (3-2-1-1-0). This guide covers the fundamentals of backup strategy, on-site and off-site backup design, cloud backup, air-gapped backups, immutable storage, and ransomware protection -- all vendor-neutral with practical examples you can implement immediately.
Whether you are an IT administrator protecting a single server, an MSP managing dozens of client environments, or a compliance officer ensuring your backup program meets regulatory requirements, this guide provides a structured approach to building a resilient backup strategy.
- The 3-2-1 Rule Explained
- The Modern Extension: 3-2-1-1-0
- Backup Types
- On-Site Backup Design
- Off-Site Backup Design
- Cloud Backup
- Air-Gapped Backups
- Immutable Backups
- Ransomware-Resilient Backup Architecture
- Backup Schedule Templates
- Testing and Verification
- Retention Policy Guide
- Compliance Requirements
- Implementation Checklist
The 3-2-1 backup rule is the foundational principle of data protection:
- 3 copies of your data (1 primary + 2 backups)
- 2 different storage media types (e.g., disk + tape, NAS + cloud)
- 1 copy stored off-site (geographically separate from primary)
The probability of losing data decreases exponentially with each independent copy:
| Scenario | Single Copy | 3-2-1 |
|---|---|---|
| Single disk failure | Data lost | 2 copies remain |
| Site disaster (fire, flood) | Data lost | Off-site copy survives |
| Storage system corruption | Data lost | Different media type likely unaffected |
| Simultaneous failure of all 3 | Extremely unlikely | Probability decreases to near zero when copies are independent |
| What People Think Is 3-2-1 | Why It Is Not |
|---|---|
| 3 copies on the same NAS (RAID + snapshots) | Same device = single point of failure |
| Primary + backup NAS + replica NAS (all on-site) | No off-site copy |
| Primary + 2 cloud backups in the same region | Same media type, same region risk |
| Primary + backup + sync to cloud folder | Sync is not backup (deletions and ransomware sync too) |
The threat landscape has evolved, and so should your backup strategy. The 3-2-1-1-0 rule adds:
- 3 copies of your data
- 2 different media types
- 1 off-site copy
- 1 air-gapped or immutable copy (protection against ransomware)
- 0 errors after backup verification (every backup is tested)
The additional "1" addresses the ransomware threat where attackers specifically target backup systems. An air-gapped or immutable copy cannot be reached or modified by ransomware that has compromised your network.
The "0" addresses the silent failure problem: backups that appear successful but contain corrupted or unrestorable data. Every backup should be verified.
Copies all selected data regardless of changes. This is the baseline.
| Pros | Cons |
|---|---|
| Fastest restore (single backup set) | Longest backup window |
| Simplest recovery process | Largest storage consumption |
| Self-contained | Highest network bandwidth usage |
Best for: Weekly baseline, monthly archive, critical systems where restore speed is paramount.
Copies only data that has changed since the last backup of any type (full or incremental).
| Pros | Cons |
|---|---|
| Fastest backup window | Restore requires full + all incrementals in chain |
| Lowest storage usage | Break in chain = data loss for that period |
| Lowest bandwidth usage | Longer restore time |
Best for: Daily backups between weekly fulls, environments with large data sets and limited backup windows.
Copies all data that has changed since the last full backup.
| Pros | Cons |
|---|---|
| Restore requires only full + latest differential | Grows larger each day since last full |
| Faster restore than incremental chains | More storage than incremental |
| Simpler restore process | Larger backup window than incremental |
Best for: Environments that need a balance between backup speed and restore speed.
A point-in-time copy of a storage volume, usually at the block level.
| Pros | Cons |
|---|---|
| Near-instant creation | Usually on same storage system (not a true backup alone) |
| Minimal performance impact | Storage overhead increases over time |
| Granular recovery (individual files) | Not a substitute for off-site backup |
Best for: Quick recovery from accidental deletion, pre-change protection, complementing (not replacing) traditional backups.
Captures every change to data in real time (or near real time).
| Pros | Cons |
|---|---|
| RPO of seconds to minutes | Higher cost and complexity |
| Granular point-in-time recovery | Significant storage and I/O overhead |
| Ideal for databases | Requires specialized software |
Best for: Tier 1 mission-critical systems where any data loss is unacceptable (financial databases, transaction systems).
On-site backups provide fast recovery for common failure scenarios (accidental deletion, disk failure, application errors).
Production Storage
|
v
Local Backup Appliance or NAS
|
+-- Disk-based backup repository (primary local backup)
+-- Snapshots (for rapid file-level recovery)
+-- Replication to second on-site device (if budget allows)
| Factor | Guideline |
|---|---|
| Storage capacity | 3x the source data size (to accommodate retention and growth) |
| Network bandwidth | Dedicated backup VLAN; 1 Gbps minimum, 10 Gbps for large environments |
| Deduplication ratio | Expect 5:1 to 20:1 depending on data type |
| RAID level | RAID 6 or RAID 10 for backup targets |
- Backup repositories must be on a separate VLAN from production
- Backup admin accounts must use unique credentials (not domain admin)
- MFA on backup console access
- Encrypt backups at rest (AES-256)
- Restrict SMB/NFS access to backup servers only
Off-site backups protect against site-level disasters (fire, flood, tornado, earthquake).
| Method | RTO | Cost | Complexity | Best For |
|---|---|---|---|---|
| Cloud backup | 4-24+ hours |
|
Low-Medium | Most organizations |
| Tape rotation to vault | 24-72 hours | $ | Medium | Large data, compliance (legal retention) |
| Replication to second site | 1-4 hours | $$$$ | High | Organizations with two data centers |
| Managed off-site backup (BaaS) | 4-12 hours | $$ | Low | Organizations without dedicated IT |
| Removable media rotation | 24-48 hours | $ | Low | Small environments |
- Minimum: 50 miles from primary site (to survive regional events)
- Recommended: Different geographic region (different weather patterns, utility grids, earthquake zones)
- Maximum: Consider data sovereignty laws if crossing national borders
| Factor | What to Evaluate |
|---|---|
| Encryption | Encrypt before upload (client-side). Do not rely solely on cloud provider encryption. |
| Bandwidth | Calculate initial seed upload time. A 10 TB seed over 100 Mbps takes approximately 9 days. |
| Egress costs | Cloud providers charge for data download. Factor restore costs into your budget. |
| Storage tiers | Use hot storage for recent backups, cold/archive for long-term (cheaper but slower retrieval). |
| Compliance | Verify the cloud provider meets your regulatory requirements (FedRAMP, HIPAA BAA, SOC 2). |
| Restore speed | Test restore speed. Large restores from cloud can take days without expedited delivery options. |
| Vendor lock-in | Ensure you can export data in a standard format. Avoid proprietary backup formats without export tools. |
| Tier | Retrieval Time | Use Case | Cost |
|---|---|---|---|
| Hot / Standard | Immediate | Recent backups, frequently accessed | $$$ |
| Cool / Infrequent Access | Minutes | Monthly backups, 30-90 day retention | $$ |
| Cold / Archive | Hours | Annual backups, compliance retention | $ |
| Deep Archive / Glacier | 12-48 hours | Legal hold, 7+ year retention | Cheapest |
An air-gapped backup is physically or logically disconnected from all networks, making it unreachable by ransomware, malware, or attackers who have compromised your network.
| Method | How It Works | Reconnection Risk |
|---|---|---|
| Tape media | Write to tape, eject, store in vault | Very low (manual process to reload) |
| Removable disk | Write to USB/eSATA drive, disconnect, store off-site | Low (must physically reconnect) |
| Rotating NAS | Two NAS devices alternate: one connected, one disconnected | Medium (connected NAS is at risk) |
| Method | How It Works | Reconnection Risk |
|---|---|---|
| Immutable cloud storage | Object lock prevents deletion/modification for a set period | Very low (even admins cannot delete) |
| SAN snapshot with restricted access | Snapshot on isolated storage; no network path from production | Low |
| Backup to isolated VLAN with one-way replication | Data flows in one direction; backup system has no production access | Medium |
Combine physical and logical air gaps:
- Daily backups to on-site NAS (fast recovery)
- Daily replication to cloud with immutable retention (logical air gap)
- Weekly tape or removable media stored off-site (physical air gap)
Immutable backups cannot be modified, encrypted, or deleted for a specified retention period -- even by administrators. This is the single most important defense against ransomware destroying your backups.
| Platform | Immutability Feature |
|---|---|
| AWS S3 | Object Lock (Governance or Compliance mode) |
| Azure Blob | Immutable Blob Storage (time-based or legal hold) |
| GCP Cloud Storage | Retention policies with Bucket Lock |
| Linux (local) | chattr +i (basic), or dedicated backup OS with immutable repository |
| Dedicated backup appliance | Vendor-specific immutable storage (hardware-enforced) |
| Mode | Can Admin Override? | Use Case |
|---|---|---|
| Governance | Yes, with special permissions | Testing; environments where flexibility is needed |
| Compliance | No, not even root/admin can delete | Regulatory requirements; ransomware protection where no exception is acceptable |
- Set immutability retention to match your RPO/RTO requirements (minimum 14 days recommended)
- Use compliance mode for your most critical backups
- Protect the credentials that manage immutability settings with extreme care (separate admin account, MFA, hardware key)
- Test restores from immutable storage regularly
A backup architecture specifically designed to survive a ransomware attack:
Production Environment
|
v
On-Site Backup (Disk/NAS)
- Encrypted at rest
- Separate credentials from production
- Immutable snapshots (14-day minimum)
|
v
Cloud Backup (Off-Site)
- Client-side encryption (key not stored in cloud)
- Object Lock / Immutable storage (30-day minimum)
- Separate cloud account from production
|
v
Air-Gapped Copy (Weekly)
- Tape or removable media stored off-site
- OR isolated NAS connected only during backup window
- Verified after each write
- Separate credentials: Backup systems must use different admin accounts than production (not domain admin)
- Separate networks: Backup infrastructure on an isolated VLAN
- Immutable storage: At least one copy must be immutable
- Offline copy: At least one copy must be physically disconnected
- Verified backups: Test restores weekly; automated integrity checks on every backup
- Encryption: All backups encrypted; encryption keys stored separately from backup data
| What | Type | Frequency | Destination | Retention |
|---|---|---|---|---|
| Full system | Full | Weekly (Sunday 1 AM) | Local NAS | 4 weeks |
| Daily changes | Incremental | Daily (1 AM) | Local NAS | 2 weeks |
| Database | Full + transaction log | Full: Daily / Logs: every 15 min | Local NAS | 2 weeks |
| Off-site copy | Replication | Daily (after backup completes) | Cloud (immutable) | 90 days |
| Air-gapped copy | Full | Monthly | Removable drive (off-site) | 12 months |
| What | Type | Frequency | Destination | Retention |
|---|---|---|---|---|
| Tier 1 systems | Full + Incremental | Full: Weekly / Incr: Daily | On-site backup appliance | 30 days |
| Tier 1 databases | CDP or 15-min logs | Continuous | On-site + cloud replica | 14 days online, 90 days archive |
| Tier 2-3 systems | Full + Incremental | Full: Weekly / Incr: Daily | On-site NAS | 30 days |
| All systems (off-site) | Replication | Daily | Cloud (immutable, 30 days) | 90 days hot, 1 year archive |
| Air-gapped copy | Full | Weekly | Tape or isolated NAS | 52 weeks |
| Annual archive | Full | Annually | Deep archive cloud + tape | 7 years |
| What | Type | Frequency | Destination | Retention |
|---|---|---|---|---|
| Tier 1 (mission critical) | CDP + hourly snapshots | Continuous | Active-active replication to DR site | 30 days online |
| Tier 2 | Full + Incremental | Full: Daily / Incr: Every 4 hours | On-site appliance + cloud | 90 days |
| Tier 3-4 | Full + Incremental | Full: Weekly / Incr: Daily | On-site NAS | 30 days |
| All tiers (off-site) | Replication | Per schedule above | Cloud (immutable, compliance mode) | Per regulation |
| Air-gapped | Full | Daily (Tier 1), Weekly (Tier 2-4) | Tape library + off-site vault | Per regulation |
| Compliance archive | Full | Monthly | Deep archive + tape vault | 7-10 years |
A backup you have never tested is a backup that might not work.
| Test Type | Frequency | What to Verify |
|---|---|---|
| Automated integrity check | Every backup | Checksum validation, no errors in log |
| Single file restore | Weekly | Can restore a specific file from backup |
| Application restore | Monthly | Restore a full application and verify it functions |
| Full system restore | Quarterly | Restore a complete server to bare metal or new VM |
| Full DR restore | Annually | Restore all Tier 1 systems; measure actual RTO and RPO |
- Backup job completed without errors
- Backup size is within expected range (not zero, not suspiciously small)
- Checksum/hash verification passed
- Restore test completed successfully
- Restored data is consistent and usable
- Restore time is within RTO target
- Data age is within RPO target
- Off-site copy is confirmed current
- Immutable storage lock is active and valid
- Air-gapped copy was completed on schedule
| Data Type | Minimum Retention | Regulatory Driver | Notes |
|---|---|---|---|
| Financial records | 7 years | SOX, IRS | May need longer for audit defense |
| Healthcare (PHI) | 6 years | HIPAA | From date last in effect |
| Employee records | 7 years post-termination | EEOC, state laws | Varies by state |
| CUI / defense contractor data | Per contract + 3 years | DFARS | Check specific contract terms |
| PCI cardholder data | 1 year | PCI DSS | Audit logs specifically |
| Email (business) | 3-7 years | Industry practice | Legal hold may extend indefinitely |
| General business data | 3 years minimum | Best practice | Longer if involved in litigation |
| Framework | Backup-Related Requirements |
|---|---|
| NIST 800-171 | 3.8.9 (media protection), 3.13.11 (CUI encryption) |
| CMMC Level 2 | RE.2.137 (regularly perform backups), RE.3.139 (tested restores) |
| HIPAA | 164.308(a)(7) -- Contingency plan including data backup |
| PCI DSS | 9.5 (media protection), 12.10.1 (incident response including restoration) |
| SOC 2 | CC6.1 (logical access to backup), A1.2 (recovery from disruptions) |
| ISO 27001 | A.12.3 (backup), A.17.1 (information security continuity) |
| GDPR | Article 32 (ability to restore data in a timely manner) |
- Inventory all data sources requiring backup
- Classify data by criticality (Tier 1-4)
- Define RTO and RPO for each tier
- Calculate total data volume and daily change rate
- Identify regulatory retention requirements
- Select backup solution (on-site appliance, software, cloud)
- Design backup schedule per tier
- Plan storage sizing (3x source data minimum)
- Select off-site target (cloud provider, tape vault, second site)
- Plan air-gap strategy
- Plan immutable storage configuration
- Design network (dedicated backup VLAN)
- Plan credential separation from production
- Deploy backup infrastructure
- Configure backup jobs per schedule
- Enable encryption (at rest and in transit)
- Configure immutable retention
- Set up monitoring and alerting (failed jobs, capacity)
- Configure off-site replication
- Set up air-gapped backup process
- Document all configurations
- Verify first full backup completes successfully
- Test single file restore
- Test full system restore
- Verify off-site copy is arriving
- Verify immutability is enforced (attempt to delete; confirm it fails)
- Verify air-gapped copy is disconnected
- Document actual RTO/RPO achieved
- Schedule recurring test calendar
Petronella Technology Group helps businesses build resilient IT infrastructure:
- Disaster Recovery Planning - Custom DR strategies
- Managed IT Services - 24/7 monitoring and backup management
- Cybersecurity Services - Comprehensive security posture
- Compliance Consulting - CMMC, HIPAA, SOC 2
Petronella Technology Group is headquartered in Raleigh, NC. Contact us or call (919) 348-4912.
Created and maintained by Petronella Technology Group - a cybersecurity and managed IT services firm based in Raleigh, NC. With 23+ years of experience and zero client breaches, we help businesses secure their infrastructure and achieve compliance.
- Website: petronellatech.com
- Phone: 919-348-4912
- Free Assessment: Book a consultation
MIT License - See LICENSE for details.