Skip to content

About

Complete 3-2-1 backup strategy implementation guide. Covers on-site, off-site, cloud, air-gapped, and immutable backups with vendor-neutral examples for ransomware protection.

Topics

Resources

Stars

4 stars

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

3-2-1 Backup Strategy Guide

A complete implementation guide for the 3-2-1 backup rule and its modern extensions (3-2-1-1-0). This guide covers the fundamentals of backup strategy, on-site and off-site backup design, cloud backup, air-gapped backups, immutable storage, and ransomware protection -- all vendor-neutral with practical examples you can implement immediately.

Whether you are an IT administrator protecting a single server, an MSP managing dozens of client environments, or a compliance officer ensuring your backup program meets regulatory requirements, this guide provides a structured approach to building a resilient backup strategy.

Table of Contents


The 3-2-1 Rule Explained

The 3-2-1 backup rule is the foundational principle of data protection:

  • 3 copies of your data (1 primary + 2 backups)
  • 2 different storage media types (e.g., disk + tape, NAS + cloud)
  • 1 copy stored off-site (geographically separate from primary)

Why 3-2-1 Works

The probability of losing data decreases exponentially with each independent copy:

Scenario Single Copy 3-2-1
Single disk failure Data lost 2 copies remain
Site disaster (fire, flood) Data lost Off-site copy survives
Storage system corruption Data lost Different media type likely unaffected
Simultaneous failure of all 3 Extremely unlikely Probability decreases to near zero when copies are independent

Common Mistake: 3-2-1 Violations

What People Think Is 3-2-1 Why It Is Not
3 copies on the same NAS (RAID + snapshots) Same device = single point of failure
Primary + backup NAS + replica NAS (all on-site) No off-site copy
Primary + 2 cloud backups in the same region Same media type, same region risk
Primary + backup + sync to cloud folder Sync is not backup (deletions and ransomware sync too)

The Modern Extension: 3-2-1-1-0

The threat landscape has evolved, and so should your backup strategy. The 3-2-1-1-0 rule adds:

  • 3 copies of your data
  • 2 different media types
  • 1 off-site copy
  • 1 air-gapped or immutable copy (protection against ransomware)
  • 0 errors after backup verification (every backup is tested)

The additional "1" addresses the ransomware threat where attackers specifically target backup systems. An air-gapped or immutable copy cannot be reached or modified by ransomware that has compromised your network.

The "0" addresses the silent failure problem: backups that appear successful but contain corrupted or unrestorable data. Every backup should be verified.


Backup Types

Full Backup

Copies all selected data regardless of changes. This is the baseline.

Pros Cons
Fastest restore (single backup set) Longest backup window
Simplest recovery process Largest storage consumption
Self-contained Highest network bandwidth usage

Best for: Weekly baseline, monthly archive, critical systems where restore speed is paramount.

Incremental Backup

Copies only data that has changed since the last backup of any type (full or incremental).

Pros Cons
Fastest backup window Restore requires full + all incrementals in chain
Lowest storage usage Break in chain = data loss for that period
Lowest bandwidth usage Longer restore time

Best for: Daily backups between weekly fulls, environments with large data sets and limited backup windows.

Differential Backup

Copies all data that has changed since the last full backup.

Pros Cons
Restore requires only full + latest differential Grows larger each day since last full
Faster restore than incremental chains More storage than incremental
Simpler restore process Larger backup window than incremental

Best for: Environments that need a balance between backup speed and restore speed.

Snapshot

A point-in-time copy of a storage volume, usually at the block level.

Pros Cons
Near-instant creation Usually on same storage system (not a true backup alone)
Minimal performance impact Storage overhead increases over time
Granular recovery (individual files) Not a substitute for off-site backup

Best for: Quick recovery from accidental deletion, pre-change protection, complementing (not replacing) traditional backups.

Continuous Data Protection (CDP)

Captures every change to data in real time (or near real time).

Pros Cons
RPO of seconds to minutes Higher cost and complexity
Granular point-in-time recovery Significant storage and I/O overhead
Ideal for databases Requires specialized software

Best for: Tier 1 mission-critical systems where any data loss is unacceptable (financial databases, transaction systems).


On-Site Backup Design

On-site backups provide fast recovery for common failure scenarios (accidental deletion, disk failure, application errors).

Recommended Architecture

Production Storage
     |
     v
Local Backup Appliance or NAS
     |
     +-- Disk-based backup repository (primary local backup)
     +-- Snapshots (for rapid file-level recovery)
     +-- Replication to second on-site device (if budget allows)

Sizing Guidelines

Factor Guideline
Storage capacity 3x the source data size (to accommodate retention and growth)
Network bandwidth Dedicated backup VLAN; 1 Gbps minimum, 10 Gbps for large environments
Deduplication ratio Expect 5:1 to 20:1 depending on data type
RAID level RAID 6 or RAID 10 for backup targets

Security Controls

  • Backup repositories must be on a separate VLAN from production
  • Backup admin accounts must use unique credentials (not domain admin)
  • MFA on backup console access
  • Encrypt backups at rest (AES-256)
  • Restrict SMB/NFS access to backup servers only

Off-Site Backup Design

Off-site backups protect against site-level disasters (fire, flood, tornado, earthquake).

Options

Method RTO Cost Complexity Best For
Cloud backup 4-24+ hours $-$$$ Low-Medium Most organizations
Tape rotation to vault 24-72 hours $ Medium Large data, compliance (legal retention)
Replication to second site 1-4 hours $$$$ High Organizations with two data centers
Managed off-site backup (BaaS) 4-12 hours $$ Low Organizations without dedicated IT
Removable media rotation 24-48 hours $ Low Small environments

Distance Recommendations

  • Minimum: 50 miles from primary site (to survive regional events)
  • Recommended: Different geographic region (different weather patterns, utility grids, earthquake zones)
  • Maximum: Consider data sovereignty laws if crossing national borders

Cloud Backup

Key Considerations

Factor What to Evaluate
Encryption Encrypt before upload (client-side). Do not rely solely on cloud provider encryption.
Bandwidth Calculate initial seed upload time. A 10 TB seed over 100 Mbps takes approximately 9 days.
Egress costs Cloud providers charge for data download. Factor restore costs into your budget.
Storage tiers Use hot storage for recent backups, cold/archive for long-term (cheaper but slower retrieval).
Compliance Verify the cloud provider meets your regulatory requirements (FedRAMP, HIPAA BAA, SOC 2).
Restore speed Test restore speed. Large restores from cloud can take days without expedited delivery options.
Vendor lock-in Ensure you can export data in a standard format. Avoid proprietary backup formats without export tools.

Cloud Storage Tiers (Vendor-Neutral Concepts)

Tier Retrieval Time Use Case Cost
Hot / Standard Immediate Recent backups, frequently accessed $$$
Cool / Infrequent Access Minutes Monthly backups, 30-90 day retention $$
Cold / Archive Hours Annual backups, compliance retention $
Deep Archive / Glacier 12-48 hours Legal hold, 7+ year retention Cheapest

Air-Gapped Backups

An air-gapped backup is physically or logically disconnected from all networks, making it unreachable by ransomware, malware, or attackers who have compromised your network.

Physical Air Gap Methods

Method How It Works Reconnection Risk
Tape media Write to tape, eject, store in vault Very low (manual process to reload)
Removable disk Write to USB/eSATA drive, disconnect, store off-site Low (must physically reconnect)
Rotating NAS Two NAS devices alternate: one connected, one disconnected Medium (connected NAS is at risk)

Logical Air Gap Methods

Method How It Works Reconnection Risk
Immutable cloud storage Object lock prevents deletion/modification for a set period Very low (even admins cannot delete)
SAN snapshot with restricted access Snapshot on isolated storage; no network path from production Low
Backup to isolated VLAN with one-way replication Data flows in one direction; backup system has no production access Medium

Best Practice

Combine physical and logical air gaps:

  1. Daily backups to on-site NAS (fast recovery)
  2. Daily replication to cloud with immutable retention (logical air gap)
  3. Weekly tape or removable media stored off-site (physical air gap)

Immutable Backups

Immutable backups cannot be modified, encrypted, or deleted for a specified retention period -- even by administrators. This is the single most important defense against ransomware destroying your backups.

How Immutability Works

Platform Immutability Feature
AWS S3 Object Lock (Governance or Compliance mode)
Azure Blob Immutable Blob Storage (time-based or legal hold)
GCP Cloud Storage Retention policies with Bucket Lock
Linux (local) chattr +i (basic), or dedicated backup OS with immutable repository
Dedicated backup appliance Vendor-specific immutable storage (hardware-enforced)

Retention Lock Modes

Mode Can Admin Override? Use Case
Governance Yes, with special permissions Testing; environments where flexibility is needed
Compliance No, not even root/admin can delete Regulatory requirements; ransomware protection where no exception is acceptable

Implementation Tips

  • Set immutability retention to match your RPO/RTO requirements (minimum 14 days recommended)
  • Use compliance mode for your most critical backups
  • Protect the credentials that manage immutability settings with extreme care (separate admin account, MFA, hardware key)
  • Test restores from immutable storage regularly

Ransomware-Resilient Backup Architecture

A backup architecture specifically designed to survive a ransomware attack:

Production Environment
     |
     v
On-Site Backup (Disk/NAS)
  - Encrypted at rest
  - Separate credentials from production
  - Immutable snapshots (14-day minimum)
     |
     v
Cloud Backup (Off-Site)
  - Client-side encryption (key not stored in cloud)
  - Object Lock / Immutable storage (30-day minimum)
  - Separate cloud account from production
     |
     v
Air-Gapped Copy (Weekly)
  - Tape or removable media stored off-site
  - OR isolated NAS connected only during backup window
  - Verified after each write

Key Principles

  1. Separate credentials: Backup systems must use different admin accounts than production (not domain admin)
  2. Separate networks: Backup infrastructure on an isolated VLAN
  3. Immutable storage: At least one copy must be immutable
  4. Offline copy: At least one copy must be physically disconnected
  5. Verified backups: Test restores weekly; automated integrity checks on every backup
  6. Encryption: All backups encrypted; encryption keys stored separately from backup data

Backup Schedule Templates

Small Business (1-10 Servers)

What Type Frequency Destination Retention
Full system Full Weekly (Sunday 1 AM) Local NAS 4 weeks
Daily changes Incremental Daily (1 AM) Local NAS 2 weeks
Database Full + transaction log Full: Daily / Logs: every 15 min Local NAS 2 weeks
Off-site copy Replication Daily (after backup completes) Cloud (immutable) 90 days
Air-gapped copy Full Monthly Removable drive (off-site) 12 months

Medium Business (10-50 Servers)

What Type Frequency Destination Retention
Tier 1 systems Full + Incremental Full: Weekly / Incr: Daily On-site backup appliance 30 days
Tier 1 databases CDP or 15-min logs Continuous On-site + cloud replica 14 days online, 90 days archive
Tier 2-3 systems Full + Incremental Full: Weekly / Incr: Daily On-site NAS 30 days
All systems (off-site) Replication Daily Cloud (immutable, 30 days) 90 days hot, 1 year archive
Air-gapped copy Full Weekly Tape or isolated NAS 52 weeks
Annual archive Full Annually Deep archive cloud + tape 7 years

Enterprise / Compliance-Heavy

What Type Frequency Destination Retention
Tier 1 (mission critical) CDP + hourly snapshots Continuous Active-active replication to DR site 30 days online
Tier 2 Full + Incremental Full: Daily / Incr: Every 4 hours On-site appliance + cloud 90 days
Tier 3-4 Full + Incremental Full: Weekly / Incr: Daily On-site NAS 30 days
All tiers (off-site) Replication Per schedule above Cloud (immutable, compliance mode) Per regulation
Air-gapped Full Daily (Tier 1), Weekly (Tier 2-4) Tape library + off-site vault Per regulation
Compliance archive Full Monthly Deep archive + tape vault 7-10 years

Testing and Verification

A backup you have never tested is a backup that might not work.

Testing Schedule

Test Type Frequency What to Verify
Automated integrity check Every backup Checksum validation, no errors in log
Single file restore Weekly Can restore a specific file from backup
Application restore Monthly Restore a full application and verify it functions
Full system restore Quarterly Restore a complete server to bare metal or new VM
Full DR restore Annually Restore all Tier 1 systems; measure actual RTO and RPO

Verification Checklist

  • Backup job completed without errors
  • Backup size is within expected range (not zero, not suspiciously small)
  • Checksum/hash verification passed
  • Restore test completed successfully
  • Restored data is consistent and usable
  • Restore time is within RTO target
  • Data age is within RPO target
  • Off-site copy is confirmed current
  • Immutable storage lock is active and valid
  • Air-gapped copy was completed on schedule

Retention Policy Guide

Data Type Minimum Retention Regulatory Driver Notes
Financial records 7 years SOX, IRS May need longer for audit defense
Healthcare (PHI) 6 years HIPAA From date last in effect
Employee records 7 years post-termination EEOC, state laws Varies by state
CUI / defense contractor data Per contract + 3 years DFARS Check specific contract terms
PCI cardholder data 1 year PCI DSS Audit logs specifically
Email (business) 3-7 years Industry practice Legal hold may extend indefinitely
General business data 3 years minimum Best practice Longer if involved in litigation

Compliance Requirements

Framework Backup-Related Requirements
NIST 800-171 3.8.9 (media protection), 3.13.11 (CUI encryption)
CMMC Level 2 RE.2.137 (regularly perform backups), RE.3.139 (tested restores)
HIPAA 164.308(a)(7) -- Contingency plan including data backup
PCI DSS 9.5 (media protection), 12.10.1 (incident response including restoration)
SOC 2 CC6.1 (logical access to backup), A1.2 (recovery from disruptions)
ISO 27001 A.12.3 (backup), A.17.1 (information security continuity)
GDPR Article 32 (ability to restore data in a timely manner)

Implementation Checklist

Phase 1: Assessment

  • Inventory all data sources requiring backup
  • Classify data by criticality (Tier 1-4)
  • Define RTO and RPO for each tier
  • Calculate total data volume and daily change rate
  • Identify regulatory retention requirements

Phase 2: Design

  • Select backup solution (on-site appliance, software, cloud)
  • Design backup schedule per tier
  • Plan storage sizing (3x source data minimum)
  • Select off-site target (cloud provider, tape vault, second site)
  • Plan air-gap strategy
  • Plan immutable storage configuration
  • Design network (dedicated backup VLAN)
  • Plan credential separation from production

Phase 3: Implement

  • Deploy backup infrastructure
  • Configure backup jobs per schedule
  • Enable encryption (at rest and in transit)
  • Configure immutable retention
  • Set up monitoring and alerting (failed jobs, capacity)
  • Configure off-site replication
  • Set up air-gapped backup process
  • Document all configurations

Phase 4: Validate

  • Verify first full backup completes successfully
  • Test single file restore
  • Test full system restore
  • Verify off-site copy is arriving
  • Verify immutability is enforced (attempt to delete; confirm it fails)
  • Verify air-gapped copy is disconnected
  • Document actual RTO/RPO achieved
  • Schedule recurring test calendar

Professional Disaster Recovery Services

Petronella Technology Group helps businesses build resilient IT infrastructure:

Petronella Technology Group is headquartered in Raleigh, NC. Contact us or call (919) 348-4912.


About

Created and maintained by Petronella Technology Group - a cybersecurity and managed IT services firm based in Raleigh, NC. With 23+ years of experience and zero client breaches, we help businesses secure their infrastructure and achieve compliance.

License

MIT License - See LICENSE for details.

About

Complete 3-2-1 backup strategy implementation guide. Covers on-site, off-site, cloud, air-gapped, and immutable backups with vendor-neutral examples for ransomware protection.

Topics

Resources

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors