
A server failure, an accidentally deleted folder, or a ransomware attack all raise the same question: is there a sound copy you can go back to? The 3-2-1 backup rule is a simple, measurable principle designed so that the answer is never left to chance. It calls for keeping three copies of your data, on two different types of media, with one of them in a different location.
This guide explains which risk each number in the rule protects against, the 3-2-1-1-0 extension that emerged with ransomware, and how to put the rule in place step by step on premises and in the cloud. The goal is to help IT teams compare their current backup setup against this framework and see exactly where the missing link is.
How many of your backups are truly independent?
Three copies kept in the same building and managed with the same account may be three copies on paper, yet they can all be lost in a single incident. The MAV Cloud team is ready to assess the independence of your current backup chain with you.
What is the 3-2-1 backup rule?
The 3-2-1 backup rule is a three-number checklist used in data protection planning. It is not tied to any single technology or product; it applies the same way to tape, disk, NAS, object storage, or a cloud service. That flexibility makes it a common language for both small offices and large data centers.
The rule’s three components are defined as follows:
- 3 copies: The original production data plus at least two independent backup copies.
- 2 different media: Copies kept on different types of storage, for example a local disk repository and object storage or tape.
- 1 different location: At least one copy in another building or data center.
The key concept here is independence. Backups kept in two separate folders on the same disk array may look like two copies by count, but the same failure will hit both. The rule is less about the number of copies and more about making sure they do not share a common point of failure.
Which risk does each number protect against?
You cannot properly evaluate a backup strategy without knowing which events it is meant to handle. Each component of the 3-2-1 approach targets a different loss scenario, and when one component is missing, that scenario is left exposed.
| Component | Risk it addresses | If it is missing |
|---|---|---|
| 3 copies | A single backup becoming corrupt, incomplete, or unreadable | If the only backup has a problem, there is no alternative to fall back on |
| 2 different media | Common failure of the same hardware type, firmware, or file system errors | The same fault can affect both copies at once |
| 1 different location | Fire, flooding, earthquake, theft, building-wide power problems | A regional event wipes out production and backups together |
As the table shows, the rule covers a wide range, from hardware failure to regional disaster. On its own, however, it was not designed for deliberate attacks such as ransomware; the rule has been extended over time to close that gap.
3-2-1-1-0 backup: the extended rule for the ransomware era
When the classic rule emerged, the biggest threats were hardware failure and natural disasters. Today, attackers deliberately hunt for backups and try to delete them. The U.S. Cybersecurity and Infrastructure Security Agency’s #StopRansomware Guide recommends keeping offline, encrypted backups of critical data and regularly testing their availability and integrity.
This need is met by adding two items to the 3-2-1 backup rule. The 3-2-1-1-0 backup model, also covered in Veeam’s explanation of the 3-2-1 rule, consists of five items:
- 3: At least three copies of the data.
- 2: At least two different storage media.
- 1: At least one copy in a different location.
- 1: At least one copy that is immutable or offline (air-gapped).
- 0: Zero errors in automated restore verification.
The fourth item requires a copy that cannot be deleted even if admin privileges are compromised; the fifth requires proof that the backup can actually be restored. In Veeam environments, this verification can be automated with isolated testing mechanisms such as SureBackup.
Common practice vs. the right approach: is the rule on paper or in practice?
At many organizations, the backup policy document says the rule is followed, but the reality on the ground is different. In common practice, the second copy sits on a NAS in the same server room, the offsite copy is an external drive an employee takes home, and no restore test has been run in years.
| Area | Common practice | The right approach |
|---|---|---|
| Second medium | Same disk type, same device family | A different storage type or different infrastructure |
| Different location | External drive carried by hand, irregularly | Automated, scheduled copying to another data center |
| Access | Same admin account as production | Separate credentials, multi-factor authentication |
| Immutability | None | At least one copy locked or offline |
| Verification | A “job succeeded” notification is considered enough | Periodic restore tests with records |
The gap usually stems not from missing technology but from undefined responsibility. A backup strategy becomes auditable only when the owner, schedule, and test calendar for each copy are written down.
Automating the offsite copy
MAV Cloud’s cloud backup service transfers Veeam-based copies on a schedule to a Türkiye-based Equinix data center. The second location and immutable copy design are planned together with you around your recovery targets.
Where does cloud backup fit in the 3-2-1 rule?
Cloud backup automates the offsite copy, the hardest part of the rule to put into practice. The local backup repository is used for fast restores, while the second copy is sent over the network to another data center. This removes error-prone manual steps such as carrying external drives.
In a typical architecture, the 3-2-1 backup rule is met like this:
- First copy: Live data on production servers.
- Second copy: An on-premises disk-based backup repository that enables short restore times.
- Third copy: A copy in the cloud, in a different data center, ideally locked as immutable.
The cloud copy can also satisfy the second-media requirement on its own, because it runs on different storage infrastructure and a different management layer. The point to watch is that access to the cloud account is separated from production credentials. Otherwise, a single compromised account can reach every copy.
SaaS data should not be left out of the picture either. When email, file sharing, and team messaging are held to the same rule, your backup strategy becomes complete.
Implementation steps: how to set up the rule from scratch
Putting the rule in place starts with inventory and targets, before any technical settings. The following steps show the typical setup order for a structure that complies with the 3-2-1 backup rule:
- Inventory: List servers, databases, file shares, and SaaS data, and determine how business-critical each one is.
- Recovery targets: Define acceptable data loss (RPO) and acceptable downtime (RTO) for each system.
- Retention policy: Put in writing how long daily, weekly, and monthly copies will be kept.
- Media and location: Choose the local repository and the offsite target, and confirm that the two do not share a common point of failure.
- Identity separation: Separate access to the backup infrastructure from the production domain and require multi-factor authentication.
- Immutability layer: Configure at least one copy as locked or offline.
- Testing and monitoring: Put restore tests on a schedule and regularly monitor failed jobs and capacity.
RPO and RTO values directly determine how often each system is backed up and which copy lives in which location. A critical database may need hourly copies, while daily copies may be enough for an archive-type file server.
Common mistakes and the right way
Because the 3-2-1 backup rule is a simple principle, people tend to assume it is being followed, yet small gaps weaken the whole structure. The most common mistakes seen in the field, and the right way to handle them, are:
- Treating replication as backup: Synchronous replication copies deleted or encrypted files to the other side as well. The right way is to keep independent restore points that let you go back to earlier versions.
- Mistaking a sync folder for a backup: Cloud file sync services also sync deletions; they are access tools, not backups.
- Managing all copies with one account: A single compromised account affects the entire chain. Copies should be protected with different credentials.
- Not testing: A “job succeeded” notification is not proof that data can be restored. Run periodic restore tests and record the results.
- Not monitoring capacity: A full repository can cause jobs to fail silently.
What these mistakes have in common is treating the rule as a one-time setup. A backup chain is a living structure that must be updated as systems change. The broader picture is covered in our article on backup strategies.
Data location in Türkiye and the KVKK dimension
When choosing a location for the offsite copy, what matters is not only geographic distance but also the country where the data is stored. Backups contain all the personal data in your production data, and KVKK (Türkiye’s Personal Data Protection Law, Law No. 6698) expects data controllers to take appropriate technical and administrative measures.
For an office in Istanbul, placing the second location in Türkiye but in a different data center provides both regional risk separation and simpler cross-border transfer assessments. Given the earthquake risk, it is also important that production and backup copies are not in the same building or on the same infrastructure. This information is general in nature and does not constitute legal advice.
A 3-2-1 setup with MAV Cloud: infrastructure, standards, and SLA target
MAV Cloud delivers backup and disaster recovery services from a Türkiye-based Equinix data center, on VMware infrastructure with Veeam-based backup. Within the 3-2-1 backup rule, the service usually takes on the role of the offsite and immutable copy.
- Standards: ISO/IEC 27001, ISO/IEC 27701, ISO 22301, ISO 9001, and ISO/IEC 20000 certifications.
- SLA target: A 99.9% monthly availability target for the backup service.
- First-response targets: 15 minutes for critical requests, 1 hour for high priority, and 4 hours for medium priority.
- Support: 24/7 expert support and 24/7 system monitoring.
Cloud backup for the offsite copy and immutable backup for the undeletable copy can be designed together.
Frequently asked questions
What is the 3-2-1 backup rule?
It is the principle of keeping at least three copies of your data, on at least two different storage media, with at least one copy stored in a different location. The goal is to prevent a single failure or incident from destroying all copies at once.
What is the difference between 3-2-1-1-0 backup and the classic rule?
The extended model adds two items to the classic rule: keeping at least one copy immutable or offline, and zero errors in restore verification. These additions provide protection against deliberate attacks such as ransomware.
Does production data count as one of the three copies?
Yes. One of the three copies is the live production data, and the other two are backups independent of it. In practice, this means you need at least two separate backups.
Does cloud backup alone satisfy the 3-2-1 rule?
Not on its own. A cloud copy can meet the different-location and different-media requirements, but it should be used together with a local copy for fast restores, bringing the total to three copies.
Can replication replace backup?
No. Replication is used to shorten downtime, but deleted or encrypted data is copied to the other side as well. You need independent restore points to go back to earlier versions.
How far away should the offsite copy be?
There is no single distance value. The copy should be kept in a data center that does not share the same regional risks as the production environment, meaning not the same building, not the same power infrastructure and, where possible, not the same disaster risk.
How often should restore tests be run?
Frequency depends on how critical the system is and how quickly it changes. A common approach is regular, automated verification for critical systems and periodic sampling for others; recording the results also matters for audits.
Should Microsoft 365 data be included in the rule?
Email and files on SaaS platforms can also be lost through accidental deletion, compromised accounts, or ransomware. Keeping an independent backup of this data should be considered to make your backup strategy complete.
Measure your current backup chain against the rule
A free assessment can reveal which copy is missing, which copies share the same risk, and whether your restore times meet your targets.
For organizations new to the topic, the first step is to list the number, media, and location of your current copies in a single table. IT teams undecided between on-premises and cloud can make the call by creating an offsite copy for one of their most critical systems and measuring the restore time. Businesses ready to build the structure can finalize their retention policy and setup plan based on the 3-2-1 backup rule together with the MAV Cloud team.

