Insights  /  The 3-2-1 backup rule: still right, no longer enough

Insights

The 3-2-1 backup rule: still right, no longer enough

Insights By The Helios team  ·  11 August 2026  ·  4 min read

Ask anyone in IT how to do backups properly and you will hear the same answer: three copies of your data, on two different types of media, with one copy offsite. The 3-2-1 backup rule has been standard advice for two decades, and whether you run your own company's estate or look after backups for clients, you have probably repeated it yourself. It is still good advice. It has also quietly stopped being sufficient, and the gap between those two facts is where businesses get hurt.

What the 3-2-1 backup rule gets right

The rule endures because it encodes one genuinely important idea: no two copies of your data should be able to fail for the same reason. Disks die, so keep more than one copy. A whole class of media can fail or be corrupted together, so use two kinds. A building can flood, burn or be burgled, so keep a copy somewhere else.

Against the failures it was designed for, accidents, hardware faults and local disasters, 3-2-1 still works. It is short enough to remember, simple enough to audit, and it has saved an enormous amount of data. Nothing below argues you should abandon it. The problem is what it never claimed to cover, and what people assume it covers anyway.

Myth one: an offsite copy is a safe copy

The rule was written for a world where data loss was accidental. Ransomware is not an accident, it is an adversary, and modern operators go for the backups first: they delete shadow copies, sign in to the backup console with stolen admin credentials, and purge cloud repositories before they encrypt anything. If your offsite copy can be reached, changed or deleted using the same credentials that run the rest of your estate, it is not a separate copy in any meaningful sense. It shares a fate with the primary.

This is why the industry has drifted towards 3-2-1-1-0: the extra 1 is a copy that is immutable or genuinely offline, something a compromised administrator account cannot touch. You do not need the numerology, but you do need the property. At least one copy should survive an attacker who owns your credentials.

Sync is not backup. OneDrive, Dropbox and Google Drive replicate whatever happens to your files, including deletion and encryption, usually within minutes. A synced copy fails the 3-2-1 test in spirit even when it appears to pass it on paper, because it is designed to mirror damage faithfully.

Myth two: a completed job is a usable backup

3-2-1 counts copies. It says nothing about whether any of them can actually be restored, and that is the failure mode we see most often in real estates: the job that has been silently failing for six weeks, the chain that broke after a server was renamed, the backup that completes nightly but has the wrong folders in scope, the restore that technically works but takes four days when the business assumed four hours.

The 0 in 3-2-1-1-0 stands for zero errors after verification, and it is the least glamorous, most valuable part of the whole formula. Verification means restoring real data on a schedule and timing it, not reading a dashboard. We have written before about why a green tick is not a restore, and the short version holds: a backup you have never restored from is a hypothesis, not a control.

Myth three: following the rule means everything is covered

The rule protects the data inside your backup jobs. It is silent about the data that never made it into one. Three gaps come up constantly:

  • Microsoft 365 and other SaaS data. Microsoft keeps the service running; under the shared responsibility model, long-term recovery of your data is your job. Retention policies are not backup, and plenty of estates with immaculate server backups have nothing behind Exchange Online or SharePoint. Our Microsoft 365 security checklist pairs well with fixing this.
  • Laptops. Users keep real work on local disks whatever the policy says, and most endpoint fleets are backed by nothing but hope and OneDrive.
  • New systems. The server stood up in March that nobody added to a job. Scope rot is gradual and invisible.

The fix is to start from inventory, not from the backup tool: list every system and dataset the business would miss, then check each one against 3-2-1. Auditing only the things that are already in a job tells you nothing about the things that are not.

Where this fits with Helios

Helios watches Veeam and Acronis jobs across every site you look after and treats silence as a finding: failed jobs, stale jobs and jobs that have never run all surface in one view, next to the asset inventory, so a device with no backup at all is visible rather than simply absent. That is the unglamorous half of 3-2-1-1-0, the verification and the coverage, handled by the same agent that already tracks patching and protection state.

Hold your own house to your clients' standard

Helios is an AI-native platform for MSPs and in-house IT teams: monitoring, patching, security and service desk in one place, with a 14-day trial and no feature gating.

Start free

Read next

Insights MSP Tooling Costs as a Percentage of MRR: How to Model It Insights AI Guardrails for IT Automation: Approvals, Scopes and Audit Trails That Keep You Safe Insights MSP security checklist: harden your own house first