Cybersecurity

The 3-2-1-1 Backup Rule: What Separates Those Who Survive a Ransomware Attack

The 3-2-1-1 rule explained step by step to protect your business from ransomware: 3 copies, 2 media types, 1 offsite. The IMACS SERVICES guide.

By Équipe IMACS SERVICES · Ingénieurs IT & cybersécurité 5 min read
Illustration: backup, cloud copy and isolated copy

A successful ransomware attack can paralyse an SME for several days to several weeks — the European cybersecurity agency ENISA ranks ransomware as one of the major threats facing European organisations1. The determining factor is not prevention — which can be circumvented — but the quality of the backup and restoration procedure. The 3-2-1-1 rule, recommended by the US CISA and by ANSSI in its anti-ransomware guides2, remains the best compass available today.

The 3-2-1-1 Rule, Clearly Explained

  • 3 copies of your data (the original + 2 backups)
  • on 2 different media types (disk + tape, or disk + cloud)
  • with 1 offsite copy (geographically remote)

This rule, formulated by photographer Peter Krogh twenty years ago, remains relevant: it protects against three distinct families of risk — hardware failure, local disaster, and targeted attack.

Why It Is No Longer Sufficient on Its Own

Modern ransomware has evolved. It no longer simply encrypts production data: it actively hunts for backups before triggering encryption. The attacker typically gains access several weeks before the attack, using that time to:

  • Map your infrastructure
  • Identify your administrator accounts
  • Locate and delete your backups
  • Exfiltrate sensitive data (double extortion)

This is why the 3-2-1-1 rule has evolved into 3-2-1-1-0:

  • 1 additional immutable copy (impossible to modify or delete)
  • 0 errors during restoration tests (systematic verification)

Immutability in Practice

An immutable backup is a copy that cannot be overwritten, encrypted, or deleted for a defined period — even by an administrator with the appropriate rights.

Three approaches predominate:

1. Object Storage with Locking (S3 Object Lock, Azure Blob Immutable, and equivalents)

The current standard. The copy is locked for N days (typically 30 to 90), even against a compromised root account.

2. Magnetic Tape (LTO)

A long-standing method, still effective: a tape removed from the robot and stored offsite is physically unreachable by the attacker.

3. Hardened Backup Appliance

A hardware safe with a locked OS, without SSH access or administration API from the production network.

Restoration Tests: Non-Negotiable

An untested backup is an imaginary backup. We have supported businesses that believed they had been backing up for years — only to discover, on the day it mattered, that their backup was corrupted, incomplete, or entirely empty.

The ideal test is quarterly and covers:

  • A complete folder restored to an isolated environment
  • A complete database brought back up
  • A full server restored (at least once a year)

The measured restoration time becomes your actual RTO (Recovery Time Objective). It is this figure, not the one promised by your service provider, that counts.

RTO and RPO: The Two Key Indicators

Every backup plan must set two explicit objectives:

  • RTO (Recovery Time Objective): how much downtime is acceptable before systems are back up?
  • RPO (Recovery Point Objective): how much data loss is acceptable?

For a law firm, a typical RPO is 1 hour (backups every hour). For an industrial SME, 4 hours is often acceptable. These values drive the entire upstream architecture.

The Cost of a Serious Backup Strategy — Indicative Figures

For an SME with 20 to 50 workstations, a file server, and a business application, here are the indicative figures we observe in managed services (to be adjusted according to data volumes, target RTO/RPO, and retention period):

  • Local backup + immutable cloud backup: typically £170–£340/month ex. VAT
  • Quarterly restoration tests: included in the Pro managed services package
  • Annual consistency audit: 1 to 2 engineer days

This should be weighed against the cost of prolonged business interruption following a ransomware attack — lost revenue, unproductive salaries, crisis communications, CNIL notification — which can rapidly amount to tens of thousands of pounds for an SME, not counting reputational damage. The exact cost depends on daily turnover and the duration of the outage; a personalised quotation remains the only way to obtain a reliable estimate for your specific situation.

What We Deploy for Our Clients

  • Local backup on a dedicated appliance (short RTO)
  • Immutable cloud backup with a sovereign hosting provider (controlled RPO)
  • Weekly rotation of an offline copy for critical organisations
  • Quarterly restoration tests, fully documented
  • Monthly reporting on backup consistency

All included within the managed services package, with no hidden costs.

Going Further

Our Cybersecurity offering covers the full spectrum: audit, EDR, MFA, immutable backups, and BCP/DRP.

Request your free preliminary assessment to evaluate your backup strategy in 15 questions.

Sources

Transparency note: we have removed all statistics that cannot be publicly verified (for example, the myth that "60% of SMEs close within six months of a ransomware attack", whose original source is untraceable and whose methodology is contested). If any claim strikes you as doubtful, write to us — we will correct or remove it.

Footnotes

  1. ENISA, Threat Landscape (annual report). Ransomware regularly features among the major threats identified. See enisa.europa.eu. ↩

  2. ANSSI, Guide pour anticiper et gérer une attaque par rançongiciel (cert.ssi.gouv.fr); CISA, Ransomware Guide (cisa.gov). Both explicitly recommend the 3-2-1-1 rule (and its evolution to 3-2-1-1-0), as well as the implementation of immutable copies and regular restoration tests. ↩

Keywords

  • Backup
  • Ransomware
  • PRA
  • Immutability

Does this article resonate with your situation?

Our free 15-question pre-assessment gives you a personalised report within 24 hours. No commitment.

Related articles

Read next.

3-2-1-1 Backup: Surviving a Ransomware Attack