Ransomware Backup Strategy: The 3-2-1-1-0 Rule That Actually Survives an Attack
A ransomware-resistant backup strategy means keeping multiple copies of your data where attackers can't reach or alter them — and proving you can restore them before you need to. The modern standard is the 3-2-1-1-0 rule: three copies of data, on two different media types, with one copy offsite, one copy offline or immutable, and zero errors on recovery verification. CISA's #StopRansomware guide names offline, tested backups as the single highest-leverage control you can deploy against ransomware, because it neutralizes the attacker's core leverage: the threat that your data is gone forever.
From 3-2-1 to 3-2-1-1-0: why the rule evolved
The original 3-2-1 rule predates ransomware. It was designed for hardware failure and site disasters:
- 3 copies of your data (one production, two backups)
- 2 different media types (e.g., disk and tape, or local SSD and cloud object storage)
- 1 copy offsite to survive a fire or flood at the primary site
Ransomware broke this model because attackers now actively hunt and encrypt backups. Many groups dwell in a network for days specifically to find and delete backup repositories before detonating. That's why two more digits were added:
- 1 copy immutable or offline — a copy that cannot be modified or deleted, even by an admin with stolen credentials
- 0 recovery errors — your restores are tested and verified, so "we have backups" doesn't become "the backups were corrupted"
The 3-2-1-1-0 version is now the best ransomware backup strategy baseline because the last two digits directly counter how ransomware operators behave.
The three types of backup and how they fit together
A working strategy combines three backup types to balance speed, cost, and recovery granularity:
- Full backup — a complete copy of all data. Slowest to create, fastest to restore from. Run this as your periodic baseline (e.g., weekly).
- Incremental backup — captures only data changed since the last backup of any type. Smallest and fastest to run, but restore requires replaying every increment in order, which is slower and riskier.
- Differential backup — captures everything changed since the last full backup. Larger than incrementals but needs only two restore points (the full plus the latest differential), making recovery simpler.
A common pattern: weekly full, daily differential, and frequent incrementals for critical databases. The key for ransomware is that at least one full backup lands in immutable storage on a schedule attackers can't tamper with.
Immutability is the control that stops the attack working
Immutable backups use write-once-read-many (WORM) storage or object-lock policies so data cannot be altered or deleted for a defined retention period — not by ransomware, not by a compromised admin account, not even by your own IT team. Implement it with:
- Object Lock in S3-compatible storage (AWS S3, Backblaze B2, Wasabi) in compliance mode
- Hardened Linux repositories or immutability flags in backup platforms like Veeam, Rubrik, or Cohesity
- True offline / air-gapped copies such as tape rotated out of the library, which is physically unreachable over the network
Pair immutability with ransomware recovery software that includes anomaly detection — flagging sudden spikes in changed or encrypted files — so you catch encryption in progress and know which recovery point predates the infection.
Map your backups to the ransomware attack lifecycle
Ransomware attacks unfold in roughly seven stages: initial access, establishing persistence, command-and-control, privilege escalation, internal reconnaissance, lateral movement and data exfiltration, and finally encryption/detonation. Your backup strategy should align to CISA's four #StopRansomware phases across that lifecycle:
- Prevent — isolate backup infrastructure with separate credentials and network segmentation so recon and lateral movement can't reach it.
- Detect — use backup anomaly detection to spot mass-encryption behavior early.
- Respond — identify the last clean recovery point before detonation using your verified backup history.
- Recover — restore from immutable copies, validated by your "0 errors" testing discipline.
The most common failure isn't missing backups — it's untested ones. Run a full restore drill at least quarterly, time it against your recovery time objective (RTO), and document gaps. A backup you've never restored is a hypothesis, not a strategy.
Not sure how your backup posture would hold up against a live attack? PlayCISO's free Ransomware Readiness Assessment walks you through immutability, restore testing, and recovery gaps in minutes — a fast way to pressure-test your 3-2
Ready to practise the decisions these articles describe?
Run a free War Room →