Backup & Continuity
The 3-2-1 backup rule explained (and why immutable backups matter now)
The 3-2-1 backup rule: three copies, two media, one off-site. What it means for a UK SME, how ransomware changed it, and why one copy must now be immutable.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
The 3-2-1 backup rule says keep at least three copies of your data, on two different types of storage, with one copy off-site. For an SME that is the live server, a local backup on a NAS and an encrypted cloud copy. Ransomware adds a fourth requirement: one copy must be immutable or offline so an attacker cannot delete it.
The 3-2-1 rule is the oldest piece of backup advice still in use, and it is still right. It is also no longer enough on its own. Ransomware operators now target backups deliberately, so a business can follow the rule to the letter and still lose everything. This article explains the rule, what it looks like for a UK SME in practice, and the fourth requirement, immutability, that turns it into a design that survives an attack.
The rule in one sentence
Keep at least three copies of your data, on two different types of storage, with one copy held off-site.
Each number answers a specific failure:
- Three copies because any single copy can fail, be corrupted or be overwritten. Two copies means one spare. Three means a spare even while one is being restored.
- Two media types because copies on the same technology tend to fail together. Two drives in the same NAS share its power supply, its firmware and its network. A NAS and cloud storage do not.
- One off-site because the building is a single point of failure. Fire, flood, theft and a contractor cutting through the power all take the on-site copies with them.
What it looks like for an SME
For a business of up to 250 people with a server or two and Microsoft 365, the pattern that meets the rule is:
| Copy | Where | Purpose |
|---|---|---|
| 1 | Live data on the server and in Microsoft 365 | Production |
| 2 | Local backup on a Synology NAS or backup appliance, several times a day | Fast restores of files and whole servers |
| 3 | Encrypted cloud backup, replicated from the NAS or taken directly, at least daily | Survives loss of the building |
| Plus | Independent backup of Microsoft 365 mailboxes, OneDrive, SharePoint and Teams | Covers data Microsoft does not back up for you |
This is the hybrid model, and it is what Dig IT runs for clients such as Mr Plant Hire, whose servers are backed up locally several times a day and to the cloud. The local copy means a failed server is restored in hours. The cloud copy means a fire at the depot would not cost the business its records. The trade-offs between local, cloud and hybrid are in on-site vs cloud vs hybrid backup.
What does not count
- Sync services. OneDrive, SharePoint, Dropbox and Google Drive mirror the original. Delete a file or encrypt it with ransomware and the change syncs everywhere in minutes. They are not backups.
- RAID. Redundant disks protect against a disk failing. They do nothing about deletion, corruption or encryption, which they replicate faithfully.
- Snapshots on the same system. Useful for quick rollbacks, but they live and die with the device.
- A second folder on the same server. One copy, twice.
- The backup that has never been restored. A copy nobody has tested is a hypothesis.
- Microsoft 365 retention. Recycle bins and retention policies help with recent mistakes but are not a backup with independent retention. See does Microsoft 365 include backup.
How ransomware changed the rule
A business can hold three copies on two media with one off-site and still be defenceless, because modern attacks are run by people, not just malware. An attacker who gains an administrator account spends days inside the network first. They find the backup console, delete or corrupt the backups, disable the cloud backup job, and only then encrypt the live systems. When the business goes to restore, there is nothing to restore from. That is the point at which the ransom gets paid.
The National Cyber Security Centre's guidance on offline backups in an online world sets out the response: at least one copy must be somewhere an attacker with your credentials cannot reach. The Cyber Security Breaches Survey 2025 found that around four in ten UK businesses identified an attack or breach in the previous year, so this is a mainstream risk rather than an edge case.
Immutable backups: the fourth digit
An immutable backup is a copy that cannot be modified or deleted until a set retention period expires, regardless of who asks. Even an administrator account, even the backup software itself, cannot remove it early. It is the modern equivalent of a tape in a safe, without the tape or the safe.
Where it comes from:
- Synology NAS: immutable snapshots that lock a point-in-time copy for a defined period, so a local backup cannot be wiped from the console.
- Cloud backup services: immutable or object-lock retention on business tiers, so the off-site copy survives a compromised account.
- Genuinely offline copies: a rotated drive kept off-site and disconnected. Effective, but it depends on someone doing the rotation.
The extended rule is often written 3-2-1-1-0: three copies, two media, one off-site, one immutable or offline, and zero errors, meaning backups are verified and test-restored. Both additions respond to how backups actually fail: the extra one to attackers, the zero to the silent job failure nobody noticed for months.
Backup credentials are the target
Immutability protects the copies. The other half is protecting the console. Backup systems should have their own administrator accounts, not the domain admin, with multi-factor authentication and no standing access from ordinary user PCs. If the backup software can be reached with the same credentials as the file server, the attacker who has one has both.
Retention: how far back you can go
The rule says nothing about how long copies are kept, and that matters as much as where. Ransomware can lie dormant for weeks. A deleted contract may not be missed for months. A common SME pattern is dailies for 30 days, weeklies for three months and monthlies for a year or more, with sector requirements sometimes extending it. Retention should match the recovery point objective agreed for each system and be a deliberate decision, not whatever the software defaulted to.
Testing: the zero
Every failure mode above is found by one habit: restoring. Restore a file monthly, a full server quarterly, and a Microsoft 365 mailbox on the same schedule. Time the server restore and compare it with the recovery time objective. Record the results. A managed backup service does this as routine and reports on it, which is why the businesses with the fewest backup surprises are usually those that stopped doing it themselves. The wider reasons plans fail are in why IT recovery plans fail.
A 3-2-1 checklist
- Three copies including the live data, or three backups plus live if you prefer the stricter reading.
- Two storage technologies with no shared failure mode.
- One copy off-site, encrypted.
- One copy immutable or offline, with retention longer than the time an attacker might wait.
- Backup console on separate credentials with multi-factor authentication.
- Microsoft 365 backed up independently.
- Retention set deliberately for each system.
- Restores tested on a schedule and recorded.
- Someone named who checks the jobs every day.
What to do next
If you cannot say which of your copies is immutable, or when a full restore was last timed, those are the two gaps to close first. Dig IT's backup and disaster recovery service implements local plus cloud backup with immutable copies and scheduled test restores for businesses across Hertfordshire, west Essex and London. Book an IT health check and we will measure your current setup against the rule.

