04 66 72 51 22

The 3-2-1 backup rule: what it actually protects

Three copies of the data, on two different media, one of them off site. The 3-2-1 rule fits in a single sentence, which explains both its success in sales decks and how loosely it gets applied in the field.

Let us take each number for what it really protects.

3 copies: against data loss

The three copies count production plus two backups. The live file on your client's server is the first one.

The classic mistake is to count a replication as a copy. A RAID mirror, a folder sync or a real-time replica are not backups: they faithfully reproduce the deletion, the ransomware encryption and the application-level corruption. They protect against hardware failure, not against mistakes and not against malice.

What separates a backup from a copy is versioning: the ability to go back to an earlier state. Without it, you have redundancy, not backup.

2 different media: against systemic failure

Two media means two technologies, or two distinct failure domains. Two disks from the same batch, bought on the same day and worked the same way, often fail within weeks of each other.

In a modern architecture, the useful separation is less "disk versus tape" than "local infrastructure versus remote infrastructure": two environments that share no power supply, no network, no administrator and no hypervisor.

1 copy off site: against physical disaster

This is the part everyone understands, and the first one to slip when bandwidth is short.

The real criterion is not distance in kilometres but independence of risk. A copy in the office across the corridor shares the same building, the same electrical circuit and the same front door. A copy on a server that the same administrator account can wipe shares the same risk of compromise.

What the 3-2-1 rule does not say

This is where it hurts. An infrastructure perfectly compliant with 3-2-1 can still fail on the day of the incident, for four reasons the rule never addresses.

Retention depth. Three copies of data that has been corrupt for six weeks are three unusable copies. Ransomware that encrypts slowly, or silent application-level corruption, are sometimes detected long after the fact. The question to ask is not "how many copies?" but "how far back can I go?".

Immutability. If the account that writes the backups can also delete them, an attacker who obtains that account obtains both. Encryption at source with a key that never crosses the network, and a retention period the agent cannot purge at will, change the equation.

Restore time. An off-site copy on an 8 Mb/s link means several days of restoring for 2 TB. Technically compliant, operationally useless. That is why a local copy, in addition to the remote one, remains relevant: the local copy serves everyday restores, the remote one serves the disaster.

Verification. A backup that has never been restored is a hypothesis, not a guarantee.

A realistic implementation across a client estate

Across an estate of small and mid-sized businesses, here is an arrangement that respects the spirit of the rule without blowing the budget:

  1. Production on the client's workstations and servers.
  2. Local copy on a backup server at the client's site or at yours, for day-to-day restores — a file deleted by mistake comes back in minutes, not hours.
  3. Remote copy on a backup server you host yourself, or on a dedicated server, with long versioning.

Block-level delta and deduplication are what make this arrangement sustainable: only the changed blocks travel, and a file present on twenty workstations is stored once. That is what allows a comfortable retention depth without multiplying storage by the number of versions.

The question that really matters

Before counting your copies, ask your client a simple question: "how long can your business stop, and how much work can you afford to lose?"

Those two answers — the acceptable recovery time and the acceptable data loss — size everything else. The 3-2-1 rule is not a target: it is the floor from which you start designing.


Advising clients on their backup strategy? Ask for a BeBackup demo to see how block-level delta and deduplication make this arrangement economically viable.

Worth reading too

Contact the BeBackup team

Would you like to know more about our BeBackup backup solution?