The 3-2-1 Backup Rule Is Outdated – Here’s What Comes Next

The 3-2-1 rule has long been hailed as the best approach to protecting your data, but the time has come for this to be updated.

Last updated on Aug 13, 2026
The 3-2-1 Backup Rule Is Outdated - Here's What Comes Next

With AI-powered ransomware now easier than ever to deploy, the risks that your organization faces are only increasing. We’re often encouraged to use backup as a solution to protect valuable data. And this is a great step. However, this will only ever be as effective as your backup strategy is. Simply put, there is no point following a plan perfectly, if that plan itself is flawed. 

In this article, we’ll dive into what the 3-2-1 backup policy is, the environment that it was developed within, and how technological advances have made it less effective today. 

What Is The 3-2-1 Rule?

The 3-2-1 rule is a quick and easy way to remember how you should be storing your backups. You should have three copies of your data, two different media types, with one version being stored offsite. This practice means that in the event of your data being inaccessible, you’ll have a backup to recover from. 

It’s worth noting that this model was developed during an era where one of the biggest risks to your data was hardware failure, fire, or theft. In other words, the risks were physical. Today, the risks are digital. Cyber-attacks pose risks that are completely different. Hardware is often offsite, with companies using cloud infrastructure.

Why The 3-2-1 Rule Is No Longer Enough

The best practices defined in the 3-2-1 rule are good enough to protect your data when things unexpectedly go wrong. They’re not, however, good enough to protect your data against threats that are proactively looking to harm your data.

Ransomware, for instance, will actively hunt and encrypt backups. It may also wait for an extended period, before activating. This means that if you attempt to restore the backup from offsite, the ransomware is already present or the backup is encrypted. 

The rule also has no way of addressing the growth of SaaS. Many workplaces are built around Microsoft 365 or Google Workspace. For the end user, it seems like data is stored securely within the cloud. However, these services operate a shared responsibility model, which means the onus remains on you to back up your data, while the provider is responsible for the infrastructure. 

The rule makes no mention of testing. It is not enough to have backup of your data; it needs to be tested to ensure that it works as expected. While the rule doesn’t explicitly rule out running tests, the omission is a significant one.

The acute increase in AI usage also generates new risks. Ransomware can iterate and evolve faster than before, giving it more opportunities to find its way around your defenses. 

The Replacement: 3-2-1-1-0 Backup

So now that we’ve comprehensively dismantled everything that’s good about the 3-2-1 rule, what is set up to take its place? 

I give you: 3-2-1-1-0. Admittedly, it is less catchy, but it is more effective. Let’s walk through what the extra 1-0 relate to so that we can better understand its role.

The 3-2-1 rule remains the standard, upon which the new sections are added on top of. These elements are added to defend against data corruption, deletion, or disaster. The original rules still apply and do the bulk of the work, but the additions might make the critical difference when a data loss event does occur. 

The extra 1 now covers one air gapped or immutable copy. It is essential that this is logically separate from the rest of your organization so that ransomware cannot reach it. This backup should be write-once storage, with time-locked retention. It is important that you check the details of your backups, ensuring that your provider hasn’t used “immutable” as a buzzword, without the technical capabilities to back it up. 

Finally, the 0 means zero errors. Your backup process should be monitored and tested to ensure that it is effective. An error-strewn backup, no matter how many of them there are, will not help your organization during times of need. 

What this means in practice

The good part about this extended advice is that it’s an evolution of the preexisting framework, rather than a complete rewriting of it. In practice, this means that you don’t have to take apart your entire strategy just to rebuild it. Instead, you need to assess how your current capabilities are implemented. Check whether your current vendors offer immutable storage, ensure that SaaS platforms are covered, inquire how testing is run.

The details of this stage will partly depend on the specifics of your current environment. It will differ depending on what tools you’re currently using, and the areas that you need coverage for. 

The Bottom Line

You need to ensure that your defensive strategy evolves just as quickly as attackers change their attack methods. This means you cannot rely on a strategy that kept you safe, even last year, to keep you safe today. This makes the challenge not just ensuring that your processes are implemented and optimized but ensuring that the processes themselves are as comprehensive as they need to be.

A great place to get started is to audit your Backup and Archiving solution, we’ve put together a shortlist of the best solutions that might suit your environment.

Backup And Recovery Resources

Further reading on backup and recovery from Expert Insights — buyers' guides, comparison articles, and platform-specific shortlists.

Written By Written By
Alex Zawalnyski
Alex Zawalnyski Journalist & Content Editor

Alex is an experienced journalist and content editor. He researches, writes, factchecks and edits articles relating to B2B cyber security and technology solutions, working alongside software experts.

Alex was awarded a First Class MA (Hons) in English and Scottish Literature by the University of Edinburgh.