What does it mean to apply the 3-2-1 backup rule?
It means keeping multiple copies of data, using more than one storage type or location, and keeping at least one copy outside the primary environment. For ransomware, that copy must be isolated, immutable, or use separate credentials.
Risks to review
- Count sync as a separate copy when replicating deletions or encryption.
- Save all copies on the same server, account or location.
- Allow administrators of the main environment to also delete all copies.
- Buy storage without defining retention, encryption and restore.
Safe recommendations
- Classify data and services according to impact and frequency of change.
- Maintain fast local copies and another external or cloud copy depending on the risk.
- Separate credentials and protect a copy from modification or deletion.
- Encrypt data in transit and at rest and control who can recover.
- Monitor task failures, capacity, and duration.
- Test representative restorations and document times and results.
When to seek specialized help
- Copies use the same domain, administrator or storage environment as production.
- It is unclear whether cloud services, email and SaaS applications are included.
- No representative sample has been restored or recovery time has never been measured.
Reference sources
These public sources provide general good-practice guidance. They do not replace an assessment of your environment.

