Skip to content
JBRichardson.comIT Cloud Solutions

Backups that survive ransomware: the 3-2-1-1-0 rule

Security & Resilience 6 min readUpdated October 7, 2026

How to design backups an attacker cannot delete, and how to prove they work before you need them.

All guides

Modern ransomware goes after backups first. If the same account that runs your servers can also delete your backups, an intruder with that account can destroy both. Resilient backups assume the main environment will be compromised.

The 3-2-1-1-0 rule

  • 3 copies of your data: the live one and two backups.
  • 2 different kinds of storage, so one failure mode cannot take both.
  • 1 copy offsite, away from the building and the main cloud account.
  • 1 copy offline or immutable, which cannot be altered or deleted for a set period.
  • 0 errors: restores are tested and verified, not assumed.

Making a copy immutable

  • In AWS, use S3 Object Lock or an AWS Backup vault with Vault Lock, which prevents deletion until retention ends.
  • Store backups in a separate AWS account with its own credentials and MFA, so a compromised production account cannot reach them.
  • On-site, use a hardened repository with immutable retention for VMware backups, not a plain file share.
  • Protect backup software and its credentials like the keys to the business, because they are.

Decide what 'recovered' means

TermMeaningQuestion to answer
RPORecovery point objective: how much data you can loseIf we restore last night's copy, is that acceptable?
RTORecovery time objective: how long you can be downHow many hours before the business is hurt?

Test restores on a schedule

  1. Pick a critical system each quarter and restore it to an isolated environment.
  2. Time it and compare against your RTO.
  3. Check the data is usable by someone who knows the system.
  4. Fix what failed and record the result.