Cybersecurity

The 3-2-1-1 Backup Rule: What Separates Those Who Survive a Ransomware Attack

The 3-2-1-1 rule explained step by step to protect your business from ransomware: 3 copies, 2 media types, 1 offsite. The IMACS SERVICES guide.

By Équipe IMACS SERVICES · Ingénieurs IT & cybersécurité 5 min read

A successful ransomware attack can paralyse an SME for several days to several weeks — the European cybersecurity agency ENISA ranks ransomware as one of the major threats facing European organisations1. The determining factor is not prevention — which can be circumvented — but the quality of the backup and restoration procedure. The 3-2-1-1 rule, recommended by the US CISA and by ANSSI in its anti-ransomware guides2, remains the best compass available today.

The 3-2-1-1 Rule, Clearly Explained

  • 3 copies of your data (the original + 2 backups)
  • on 2 different media types (disk + tape, or disk + cloud)
  • with 1 offsite copy (geographically remote)

This rule, formulated by photographer Peter Krogh twenty years ago, remains relevant: it protects against three distinct families of risk — hardware failure, local disaster, and targeted attack.

Why It Is No Longer Sufficient on Its Own

Modern ransomware has evolved. It no longer simply encrypts production data: it actively hunts for backups before triggering encryption. The attacker typically gains access several weeks before the attack, using that time to:

  • Map your infrastructure
  • Identify your administrator accounts
  • Locate and delete your backups
  • Exfiltrate sensitive data (double extortion)

This is why the 3-2-1-1 rule has evolved into 3-2-1-1-0:

  • 1 additional immutable copy (impossible to modify or delete)
  • 0 errors during restoration tests (systematic verification)

Immutability in Practice

An immutable backup is a copy that cannot be overwritten, encrypted, or deleted for a defined period — even by an administrator with the appropriate rights.

Three approaches predominate:

1. Object Storage with Locking (S3 Object Lock, Azure Blob Immutable, and equivalents)

The current standard. The copy is locked for N days (typically 30 to 90), even against a compromised root account.

2. Magnetic Tape (LTO)

A long-standing method, still effective: a tape removed from the robot and stored offsite is physically unreachable by the attacker.

3. Hardened Backup Appliance

A hardware safe with a locked OS, without SSH access or administration API from the production network.

Restoration Tests: Non-Negotiable

An untested backup is an imaginary backup. We have supported businesses that believed they had been backing up for years — only to discover, on the day it mattered, that their backup was corrupted, incomplete, or entirely empty.

The ideal test is quarterly and covers:

  • A complete folder restored to an isolated environment
  • A complete database brought back up
  • A full server restored (at least once a year)

The measured restoration time becomes your actual RTO (Recovery Time Objective). It is this figure, not the one promised by your service provider, that counts.

RTO and RPO: The Two Key Indicators

Every backup plan must set two explicit objectives:

  • RTO (Recovery Time Objective): how much downtime is acceptable before systems are back up?
  • RPO (Recovery Point Objective): how much data loss is acceptable?

For a law firm, a typical RPO is 1 hour (backups every hour). For an industrial SME, 4 hours is often acceptable. These values drive the entire upstream architecture.

The Cost of a Serious Backup Strategy — Indicative Figures

For an SME with 20 to 50 workstations, a file server, and a business application, here are the indicative figures we observe in managed services (to be adjusted according to data volumes, target RTO/RPO, and retention period):

  • Local backup + immutable cloud backup: typically £170–£340/month ex. VAT
  • Quarterly restoration tests: included in the Pro managed services package
  • Annual consistency audit: 1 to 2 engineer days

This should be weighed against the cost of prolonged business interruption following a ransomware attack — lost revenue, unproductive salaries, crisis communications, CNIL notification — which can rapidly amount to tens of thousands of pounds for an SME, not counting reputational damage. The exact cost depends on daily turnover and the duration of the outage; a personalised quotation remains the only way to obtain a reliable estimate for your specific situation.

What We Deploy for Our Clients

  • Local backup on a dedicated appliance (short RTO)
  • Immutable cloud backup with a sovereign hosting provider (controlled RPO)
  • Weekly rotation of an offline copy for critical organisations
  • Quarterly restoration tests, fully documented
  • Monthly reporting on backup consistency

All included within the managed services package, with no hidden costs.

Going Further

Our Cybersecurity offering covers the full spectrum: audit, EDR, MFA, immutable backups, and BCP/DRP.

Request your free preliminary assessment to evaluate your backup strategy in 15 questions.

Sources

Transparency note: we have removed all statistics that cannot be publicly verified (for example, the myth that "60% of SMEs close within six months of a ransomware attack", whose original source is untraceable and whose methodology is contested). If any claim strikes you as doubtful, write to us — we will correct or remove it.

Footnotes

  1. ENISA, Threat Landscape (annual report). Ransomware regularly features among the major threats identified. See enisa.europa.eu.

  2. ANSSI, Guide pour anticiper et gérer une attaque par rançongiciel (cert.ssi.gouv.fr); CISA, Ransomware Guide (cisa.gov). Both explicitly recommend the 3-2-1-1 rule (and its evolution to 3-2-1-1-0), as well as the implementation of immutable copies and regular restoration tests.

Keywords

  • Sauvegarde
  • Ransomware
  • PRA
  • Immuabilité

Does this article resonate with your situation?

Our free 15-question pre-assessment gives you a personalised report within 24 hours. No commitment.

Related articles

Read next.