The 3-2-1 rule says keep three copies of your data, on two different types of storage, with one copy offsite. It is decades old, it predates ransomware, and it still holds. The modern extension, 3-2-1-1-0, adds one immutable or offline copy and zero verification errors, which is where most small businesses actually fall short.
The reason such an old rule survives is that it is not really about copies at all. Each number is defending against a different way of losing data, and the failures are independent, which is the whole trick. Three copies protects against a copy being corrupt or quietly incomplete. Two types of storage protects against a whole class of device failing the same way at the same time. One offsite protects against the fire, flood or theft that takes the building and everything in it. Stack them and no single event takes all three.
Work through it concretely for a small business. Copy one is the live data, on the server or in Microsoft 365. Copy two lives on different storage, a managed backup appliance, a cloud backup service, something that is not the same box running the workload, because a backup on the machine it protects is a copy of the risk. Copy three sits somewhere else entirely, and it is the one businesses skip, because it costs a little more and nothing bad has happened yet. Adelaide City General Practice is the shape of that gamble: their clinical systems ran on a single server where one motherboard failure meant at least a full business day without patient records, until the whole thing moved to AWS.
Then ransomware arrived and broke an assumption the rule had quietly relied on. The old model assumed your enemies were accidents: hardware dies, someone deletes the wrong folder, the office floods. Accidents do not go looking for your backups. Ransomware does, deliberately, because a business that can restore does not pay. Modern attacks hunt for backup servers, delete snapshots and encrypt network shares before triggering anything visible, and they do it using credentials they have already stolen.
That is what the extra one and the zero answer. The extra one is a copy that cannot be altered even by someone holding your administrator password: immutable cloud storage that refuses deletion for a set period, or a copy genuinely offline. The distinction that matters is not offsite but out of reach, because a backup server sitting in another office, joined to the same domain, is offsite and still reachable by an attacker who owns your network. And the zero is verification: backups checked, restores actually performed. A backup that has never been restored is a hope with a schedule, and the day you find out is the worst possible day to learn.
Two modern gaps trip up businesses that otherwise do this well. The first is Microsoft 365, where a great many owners assume Microsoft holds a backup on their behalf; Microsoft protects the platform, but your data is your responsibility, and the retention windows built into the service are designed for a deleted file last Tuesday, not for recovering from a compromise discovered months later. We back client tenants up daily with Veeam to a separate data centre with thirty days of history, precisely because the platform's own safety net is not one. The second gap is everything outside the file server: the accounting system, the job-management platform, the clinical software, each with its own arrangements that somebody should have checked and often nobody has.
The Essential Eight puts regular backups among its eight controls for exactly these reasons, and it is worth noting what the framework asks for, because it is stricter than most businesses expect. Not merely that backups run: that they are retained, that they are protected from the very network they are backing up, and that restoration is tested. Test-restored backups are also the item that turns a security claim into evidence, which is what insurers and tender panels are increasingly asking to see.
The honest caveat is that the rule is a floor, not a strategy. It tells you how many copies and where; it does not tell you how much data you can afford to lose or how long you can afford to be down, which are the questions that actually size a backup system, and which we cover separately. Start with the floor, though, because a business that genuinely meets 3-2-1-1-0 has removed most of the ways data disappears. If you want to know whether yours does, rather than assume, the Cyber Security Scorecard checks it free, or call 1800 456 567.
Find out whether yours actually is 3-2-1
Most businesses believe they meet the rule and fail on the third copy or the restore test. We check both against your real systems.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business