🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

Ransomware Backup Strategy: The 3-2-1-1-0 Rule That Actually Survives an Attack

October 4, 2026 · PlayCISO

A ransomware-resistant backup strategy means keeping multiple copies of your data where attackers can't reach or alter them — and proving you can restore them before you need to. The modern standard is the 3-2-1-1-0 rule: three copies of data, on two different media types, with one copy offsite, one copy offline or immutable, and zero errors on recovery verification. CISA's #StopRansomware guide names offline, tested backups as the single highest-leverage control you can deploy against ransomware, because it neutralizes the attacker's core leverage: the threat that your data is gone forever.

From 3-2-1 to 3-2-1-1-0: why the rule evolved

The original 3-2-1 rule predates ransomware. It was designed for hardware failure and site disasters:

  • 3 copies of your data (one production, two backups)
  • 2 different media types (e.g., disk and tape, or local SSD and cloud object storage)
  • 1 copy offsite to survive a fire or flood at the primary site

Ransomware broke this model because attackers now actively hunt and encrypt backups. Many groups dwell in a network for days specifically to find and delete backup repositories before detonating. That's why two more digits were added:

  • 1 copy immutable or offline — a copy that cannot be modified or deleted, even by an admin with stolen credentials
  • 0 recovery errors — your restores are tested and verified, so "we have backups" doesn't become "the backups were corrupted"

The 3-2-1-1-0 version is now the best ransomware backup strategy baseline because the last two digits directly counter how ransomware operators behave.

The three types of backup and how they fit together

A working strategy combines three backup types to balance speed, cost, and recovery granularity:

  • Full backup — a complete copy of all data. Slowest to create, fastest to restore from. Run this as your periodic baseline (e.g., weekly).
  • Incremental backup — captures only data changed since the last backup of any type. Smallest and fastest to run, but restore requires replaying every increment in order, which is slower and riskier.
  • Differential backup — captures everything changed since the last full backup. Larger than incrementals but needs only two restore points (the full plus the latest differential), making recovery simpler.

A common pattern: weekly full, daily differential, and frequent incrementals for critical databases. The key for ransomware is that at least one full backup lands in immutable storage on a schedule attackers can't tamper with.

Immutability is the control that stops the attack working

Immutable backups use write-once-read-many (WORM) storage or object-lock policies so data cannot be altered or deleted for a defined retention period — not by ransomware, not by a compromised admin account, not even by your own IT team. Implement it with:

  • Object Lock in S3-compatible storage (AWS S3, Backblaze B2, Wasabi) in compliance mode
  • Hardened Linux repositories or immutability flags in backup platforms like Veeam, Rubrik, or Cohesity
  • True offline / air-gapped copies such as tape rotated out of the library, which is physically unreachable over the network

Pair immutability with ransomware recovery software that includes anomaly detection — flagging sudden spikes in changed or encrypted files — so you catch encryption in progress and know which recovery point predates the infection.

Map your backups to the ransomware attack lifecycle

Ransomware attacks unfold in roughly seven stages: initial access, establishing persistence, command-and-control, privilege escalation, internal reconnaissance, lateral movement and data exfiltration, and finally encryption/detonation. Your backup strategy should align to CISA's four #StopRansomware phases across that lifecycle:

  • Prevent — isolate backup infrastructure with separate credentials and network segmentation so recon and lateral movement can't reach it.
  • Detect — use backup anomaly detection to spot mass-encryption behavior early.
  • Respond — identify the last clean recovery point before detonation using your verified backup history.
  • Recover — restore from immutable copies, validated by your "0 errors" testing discipline.

The most common failure isn't missing backups — it's untested ones. Run a full restore drill at least quarterly, time it against your recovery time objective (RTO), and document gaps. A backup you've never restored is a hypothesis, not a strategy.

Not sure how your backup posture would hold up against a live attack? PlayCISO's free Ransomware Readiness Assessment walks you through immutability, restore testing, and recovery gaps in minutes — a fast way to pressure-test your 3-2

Ready to practise the decisions these articles describe?

Run a free War Room →