Contact
Backup & Recovery

The 3-2-1 Backup Rule Explained (and Why Ransomware Changed It)

The 3-2-1 backup rule explained - 3 copies, 2 media, 1 offsite - plus the 3-2-1-1-0 ransomware extension and a worked setup for a Singapore SME.

September 24, 2026 6 min read
Short answer: The 3-2-1 backup rule says: keep 3 copies of your data (the original plus two backups), on 2 different types of media, with 1 copy offsite. It works because no single failure – a dead drive, a fire, a stolen laptop – can take out every copy at once. Ransomware added a modern extension, 3-2-1-1-0: one of those copies should be offline or immutable (attackers now delete backups before encrypting), and zero errors when you verify restores. If your “backup” is OneDrive sync, you currently have one copy – read on.

Every backup vendor quotes the rule; almost nobody explains how to actually run it in a small Singapore office, or why ransomware quietly broke the original version. This guide does both – what the numbers mean, what counts as a real copy, and a worked example for a typical 20-person team.

The rule, unpacked: 3 copies, 2 media, 1 offsite

The rule was popularised by photographer Peter Krogh – people whose files are their livelihood tend to think clearly about losing them. Each number closes a specific failure mode:

  • 3 copies – your working data plus two backups. One backup is not enough, because backups fail too; the copy you discover is corrupt is always the one you needed.
  • 2 media types – for example, a NAS in the office and cloud storage. Two copies on the same device, or two drives of the same batch, share the same failure.
  • 1 offsite – a copy that survives whatever happens to your office: fire, flood, theft, or the power surge that takes out everything plugged in that day.

Ransomware backup: why the rule grew to 3-2-1-1-0

Modern ransomware crews do not just encrypt your files – they hunt down and delete or encrypt your backups first, because a business that can restore does not pay. That is why a ransomware backup strategy extends the rule with two more digits:

  • +1: one copy offline or immutable – either genuinely disconnected (rotated drives, tape) or cloud storage with immutability/object lock, where even an administrator account cannot delete or alter backups during the lock window. Security agencies like CISA explicitly recommend offline backups for exactly this reason.
  • +0: zero errors on verification – a backup is only real once a restore from it has succeeded. Scheduled test restores turn “we think we are covered” into “we checked”.

The practical implications: your backup console needs MFA and separate credentials (a stolen admin password should not reach the backups), and at least one copy must be beyond the reach of your own network.

What counts as a copy (and what doesn’t)

Looks like a backup Why it is not one
OneDrive / Google Drive sync Sync replicates changes – including deletion and encryption – to every “copy” within minutes
RAID on the server or NAS Protects against one dead disk; does nothing against deletion, ransomware, fire or theft
Microsoft 365 by itself Microsoft runs the service; protecting your data is your job under shared responsibility – retention windows are not versioned backup
An external drive left plugged in Ransomware encrypts every drive it can see; a connected disk is just another target
Snapshots on the same device Useful for quick rollback, but they die with the device that holds them

Backup best practices Singapore SMEs actually follow

Turning the rule into a routine is the part that fails in practice, so here is the shortlist of backup best practices Singapore teams can keep up without a full-time IT department:

  • Automate everything – human-triggered backups stop happening within a month. Agents and schedules, not calendar reminders.
  • Back up the SaaS too – Microsoft 365 mail, OneDrive and SharePoint need their own backup, typically S$3-S$8 per user per month.
  • Set retention deliberately – 30-90 days of versions operationally; longer only where regulation requires it.
  • Lock one copy – immutability on the cloud copy, or a genuinely offline rotation.
  • Test restores quarterly – restore a folder, a mailbox and (annually) a full server image. Singapore’s PDPC expects notifiable data breaches to be reported within 3 calendar days of assessment – a business that can restore fast is in a very different conversation than one that cannot.
  • Write down the restore order – which systems come back first, who runs it, where the credentials live (not only inside the systems being restored).

A worked example: 20-person Singapore office

Copy 1 is the live data: laptops syncing to Microsoft 365. Copy 2, first backup: a NAS in the office taking nightly versioned backups of endpoints and the file server – fast local restores for everyday “I deleted the folder” incidents. Copy 3, offsite: the NAS replicating nightly to Singapore-hosted cloud backup with immutability enabled, plus per-user Microsoft 365 backup. Two media (NAS + cloud), one offsite, one immutable, and restore tests on the calendar. Cost sits in the low hundreds per month – our cloud backup cost guide breaks down the per-TB and per-user numbers, and the NAS vs cloud comparison covers the hardware choice.

Rezolva angle: Rezolva designs and runs 3-2-1-1-0 backup for Singapore SMEs as part of managed cloud backup – NAS plus immutable cloud copy plus Microsoft 365 backup, with the quarterly restore tests actually done and documented. The rule is simple; the discipline is what you are outsourcing.

Frequently asked questions

What is the 3-2-1 rule when backing up data?

Keep three copies of your data – the working original plus two backups – on two different types of storage media, with at least one copy held offsite. The combination means no single event, from a failed drive to an office fire, can destroy every copy. It is the baseline standard for business data protection, extended in the ransomware era to 3-2-1-1-0.

Is the 3-2-1 backup rule outdated?

The core logic still holds; what changed is that ransomware now attacks backups deliberately. The modern extension, 3-2-1-1-0, adds one offline or immutable copy (so an attacker with admin access still cannot destroy it) and zero errors on restore verification. Treat 3-2-1 as the floor and the two extra digits as what makes it ransomware-proof.

Does OneDrive count as a backup?

No – OneDrive is sync, not backup. It replicates changes to all copies within minutes, which means deletions and ransomware encryption replicate too. Versioning and the recycle bin help with small accidents, but retention is limited and shared responsibility applies: protecting Microsoft 365 data is your job. A separate, versioned backup of M365 is the fix.

What is an immutable backup?

A backup that cannot be altered or deleted for a set period, even by administrator accounts – typically implemented with object lock on cloud storage or WORM (write once, read many) settings. Immutability is the practical answer to ransomware crews that compromise admin credentials and purge backups before encrypting: the locked copy survives regardless.

How often should backups be tested?

Restore a file or folder quarterly, a mailbox or SharePoint site quarterly, and a full server image at least annually. The test is the product: an unverified backup is a hope, and the 0 in 3-2-1-1-0 exists because corrupt backups are routinely discovered only on the day they are needed. Put the tests on the calendar and record the results.

Does the 3-2-1 rule protect against ransomware?

Only the extended version does reliably. Classic 3-2-1 copies that are all online and reachable can be encrypted or deleted by an attacker who gets admin access. Add one offline or immutable copy, separate MFA-protected credentials for the backup console, and verified restores – then ransomware becomes an outage you recover from, not a ransom negotiation.

About the author

Written by the Rezolva IT team – we run 3-2-1-1-0 backup (NAS + immutable cloud + Microsoft 365) for Singapore SMEs, including the quarterly restore drills. References: CISA guidance on offline backups and PDPC breach-notification timelines, as at August 2026.