We're hearing about 3-2-1-1-0 lately, what's the difference vs 3-2-1?
3-2-1-1-0 is the modern extension: 3 copies, 2 media, 1 offsite, 1 immutable or air-gapped, 0 errors in restore tests. The extra 1 covers ransomware, the 0 covers the 'we had backup but it didn't work' scenario.
Try this first
- 1The extra 1 (immutable or air-gapped) is the key addition. In practice: S3 Object Lock on an offsite cloud tier, a Veeam hardened repo, or physically disconnected tape/USB off the network.
- 2The 0 (zero errors on verification) means every backup job needs to be verified, not just 'completed'. Veeam SureBackup, NAKIVO Recovery Verification or a homegrown restore-test script give that.
- 3Audit your current setup against each digit: do you really have 3 copies including production, or 2 (prod + 1 backup)? Truly on 2 media types, or all on disk? Is offsite really offsite or just a 2nd NAS in the same fire compartment?
- 4Pick a mechanism for the extra 1 that's physically or logically disconnected from production. If ransomware reaches your NAS via AD, the immutable layer must be independent of that.
- 5Schedule quarterly restore tests that hit every layer: 1 file from local, 1 system from offsite, 1 set from immutable. Log which failed and why.
- 6Document for management: which threats 3-2-1-1-0 covers (ransomware, fire, ex-employee, user error) and which it doesn't (massive provider-wide outage).
When to bring us in
A cyber-insurance policy or compliance audit can set specific requirements on immutability duration, air-gap frequency or test cadence. Read the policy and align, otherwise coverage is up for debate.
See also
- We have backups but we do not know if they workA backup that cannot be restored is not a backup. Testing matters as much as taking the backup.
- Suspected ransomware: what to do RIGHT NOWThe first 30 minutes are critical. One wrong move spreads the damage. Read before acting.
- Someone accidentally deleted an important folderUsually fine to recover. The trick: do not save anything new on that drive until you know how.
None of the above fits?
Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.
Or skip the DIY entirely
Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.