Skip to main content
Dig IT Solutions logo

Backup & Continuity

The 3-2-1 backup rule explained (and why immutable backups matter now)

The 3-2-1 backup rule: three copies, two media, one off-site. What it means for a UK SME, how ransomware changed it, and why one copy must now be immutable.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

The 3-2-1 backup rule says keep at least three copies of your data, on two different types of storage, with one copy off-site. For an SME that is the live server, a local backup on a NAS and an encrypted cloud copy. Ransomware adds a fourth requirement: one copy must be immutable or offline so an attacker cannot delete it.

The 3-2-1 rule is the oldest piece of backup advice still in use, and it is still right. It is also no longer enough on its own. Ransomware operators now target backups deliberately, so a business can follow the rule to the letter and still lose everything. This article explains the rule, what it looks like for a UK SME in practice, and the fourth requirement, immutability, that turns it into a design that survives an attack.

The rule in one sentence

Keep at least three copies of your data, on two different types of storage, with one copy held off-site.

Each number answers a specific failure:

  • Three copies because any single copy can fail, be corrupted or be overwritten. Two copies means one spare. Three means a spare even while one is being restored.
  • Two media types because copies on the same technology tend to fail together. Two drives in the same NAS share its power supply, its firmware and its network. A NAS and cloud storage do not.
  • One off-site because the building is a single point of failure. Fire, flood, theft and a contractor cutting through the power all take the on-site copies with them.

What it looks like for an SME

For a business of up to 250 people with a server or two and Microsoft 365, the pattern that meets the rule is:

CopyWherePurpose
1Live data on the server and in Microsoft 365Production
2Local backup on a Synology NAS or backup appliance, several times a dayFast restores of files and whole servers
3Encrypted cloud backup, replicated from the NAS or taken directly, at least dailySurvives loss of the building
PlusIndependent backup of Microsoft 365 mailboxes, OneDrive, SharePoint and TeamsCovers data Microsoft does not back up for you

This is the hybrid model, and it is what Dig IT runs for clients such as Mr Plant Hire, whose servers are backed up locally several times a day and to the cloud. The local copy means a failed server is restored in hours. The cloud copy means a fire at the depot would not cost the business its records. The trade-offs between local, cloud and hybrid are in on-site vs cloud vs hybrid backup.

What does not count

  • Sync services. OneDrive, SharePoint, Dropbox and Google Drive mirror the original. Delete a file or encrypt it with ransomware and the change syncs everywhere in minutes. They are not backups.
  • RAID. Redundant disks protect against a disk failing. They do nothing about deletion, corruption or encryption, which they replicate faithfully.
  • Snapshots on the same system. Useful for quick rollbacks, but they live and die with the device.
  • A second folder on the same server. One copy, twice.
  • The backup that has never been restored. A copy nobody has tested is a hypothesis.
  • Microsoft 365 retention. Recycle bins and retention policies help with recent mistakes but are not a backup with independent retention. See does Microsoft 365 include backup.

How ransomware changed the rule

A business can hold three copies on two media with one off-site and still be defenceless, because modern attacks are run by people, not just malware. An attacker who gains an administrator account spends days inside the network first. They find the backup console, delete or corrupt the backups, disable the cloud backup job, and only then encrypt the live systems. When the business goes to restore, there is nothing to restore from. That is the point at which the ransom gets paid.

The National Cyber Security Centre's guidance on offline backups in an online world sets out the response: at least one copy must be somewhere an attacker with your credentials cannot reach. The Cyber Security Breaches Survey 2025 found that around four in ten UK businesses identified an attack or breach in the previous year, so this is a mainstream risk rather than an edge case.

Immutable backups: the fourth digit

An immutable backup is a copy that cannot be modified or deleted until a set retention period expires, regardless of who asks. Even an administrator account, even the backup software itself, cannot remove it early. It is the modern equivalent of a tape in a safe, without the tape or the safe.

Where it comes from:

  • Synology NAS: immutable snapshots that lock a point-in-time copy for a defined period, so a local backup cannot be wiped from the console.
  • Cloud backup services: immutable or object-lock retention on business tiers, so the off-site copy survives a compromised account.
  • Genuinely offline copies: a rotated drive kept off-site and disconnected. Effective, but it depends on someone doing the rotation.

The extended rule is often written 3-2-1-1-0: three copies, two media, one off-site, one immutable or offline, and zero errors, meaning backups are verified and test-restored. Both additions respond to how backups actually fail: the extra one to attackers, the zero to the silent job failure nobody noticed for months.

Backup credentials are the target

Immutability protects the copies. The other half is protecting the console. Backup systems should have their own administrator accounts, not the domain admin, with multi-factor authentication and no standing access from ordinary user PCs. If the backup software can be reached with the same credentials as the file server, the attacker who has one has both.

Retention: how far back you can go

The rule says nothing about how long copies are kept, and that matters as much as where. Ransomware can lie dormant for weeks. A deleted contract may not be missed for months. A common SME pattern is dailies for 30 days, weeklies for three months and monthlies for a year or more, with sector requirements sometimes extending it. Retention should match the recovery point objective agreed for each system and be a deliberate decision, not whatever the software defaulted to.

Testing: the zero

Every failure mode above is found by one habit: restoring. Restore a file monthly, a full server quarterly, and a Microsoft 365 mailbox on the same schedule. Time the server restore and compare it with the recovery time objective. Record the results. A managed backup service does this as routine and reports on it, which is why the businesses with the fewest backup surprises are usually those that stopped doing it themselves. The wider reasons plans fail are in why IT recovery plans fail.

A 3-2-1 checklist

  • Three copies including the live data, or three backups plus live if you prefer the stricter reading.
  • Two storage technologies with no shared failure mode.
  • One copy off-site, encrypted.
  • One copy immutable or offline, with retention longer than the time an attacker might wait.
  • Backup console on separate credentials with multi-factor authentication.
  • Microsoft 365 backed up independently.
  • Retention set deliberately for each system.
  • Restores tested on a schedule and recorded.
  • Someone named who checks the jobs every day.

What to do next

If you cannot say which of your copies is immutable, or when a full restore was last timed, those are the two gaps to close first. Dig IT's backup and disaster recovery service implements local plus cloud backup with immutable copies and scheduled test restores for businesses across Hertfordshire, west Essex and London. Book an IT health check and we will measure your current setup against the rule.

Frequently asked questions

Does the live copy count as one of the three?
In the original formulation, yes: the production data plus two backups makes three. Many practitioners now treat it as three backup copies in addition to the live data, which is safer. Either way the point is that one backup is not enough, because a single backup can fail, be corrupted or be encrypted along with the system it protects.
What counts as two different types of media?
Two storage technologies that do not share a failure mode: a NAS on the local network and cloud object storage, or a backup appliance and a rotated external drive kept off-site. Two folders on the same server, or two drives in the same NAS, do not count. The aim is that a single fault, a single attacker or a single mistake cannot reach both.
Is OneDrive or SharePoint my off-site copy?
No. Sync services replicate whatever happens to the original, including deletion and ransomware encryption, to every connected device and to the cloud within minutes. They are collaboration tools, not backups. Microsoft 365 data needs its own independent backup with its own retention, and that backup can be one of your three copies, but the live tenant cannot.
What does immutable mean in a backup context?
An immutable backup is a copy that cannot be altered or deleted for a defined retention period, even by an administrator account. Attackers who reach the backup console can delete ordinary backups before encrypting live data. Immutability, available on modern NAS devices such as Synology and on business cloud backup services, removes that option and is now the control that decides whether a ransomware attack is recoverable.
How is 3-2-1-1-0 different?
It extends the rule with two more digits: one copy that is immutable or offline, and zero errors, meaning every backup is verified and test-restored so you know it works. The extra one addresses ransomware. The zero addresses the more common failure, which is a backup that ran with errors for months and was discovered to be useless during a restore.
How long should backups be kept?
Long enough to recover from problems discovered late. Ransomware can sit in a network for weeks before triggering, and a deleted file may not be missed for months. A common SME pattern is daily backups kept for 30 days, weekly for three months and monthly for a year or more, with legal or regulatory requirements sometimes extending it. Retention should be a deliberate decision, not a default.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us