# Backups that survive ransomware: the 3-2-1-1-0 rule

*Security & Resilience · 6 min read · Updated 2026-10-07 · https://www.jbrichardson.com/resources/ransomware-resilient-backups*

**Short answer:** Follow 3-2-1-1-0: three copies, two media types, one offsite, one offline or immutable, and zero errors after tested restores. Keep backups in a separate account with its own credentials and MFA, use immutable storage such as S3 Object Lock, and rehearse restores each quarter against your recovery time objective.

Modern ransomware goes after backups first. If the same account that runs your servers can also delete your backups, an intruder with that account can destroy both. Resilient backups assume the main environment will be compromised.

## The 3-2-1-1-0 rule

- 3 copies of your data: the live one and two backups.
- 2 different kinds of storage, so one failure mode cannot take both.
- 1 copy offsite, away from the building and the main cloud account.
- 1 copy offline or immutable, which cannot be altered or deleted for a set period.
- 0 errors: restores are tested and verified, not assumed.

## Making a copy immutable

- In AWS, use S3 Object Lock or an AWS Backup vault with Vault Lock, which prevents deletion until retention ends.
- Store backups in a separate AWS account with its own credentials and MFA, so a compromised production account cannot reach them.
- On-site, use a hardened repository with immutable retention for VMware backups, not a plain file share.
- Protect backup software and its credentials like the keys to the business, because they are.

## Decide what 'recovered' means

| Term | Meaning | Question to answer |
| --- | --- | --- |
| RPO | Recovery point objective: how much data you can lose | If we restore last night's copy, is that acceptable? |
| RTO | Recovery time objective: how long you can be down | How many hours before the business is hurt? |

## Test restores on a schedule

1. Pick a critical system each quarter and restore it to an isolated environment.
2. Time it and compare against your RTO.
3. Check the data is usable by someone who knows the system.
4. Fix what failed and record the result.

> **An untested backup is a hope** The most common backup failure is not missing software. It is a restore nobody has ever tried.

---
Published by JBRichardson LLC, 1603 North Olden Ave, Ewing, NJ 08638. Phone (609)-564-3016. https://www.jbrichardson.com/contact
