Back to Blog
Backup & Recovery 14 August 2025 · 7 min read

The 3-2-1 Backup Rule: Why It's Still the Gold Standard for Business Data Protection

The 3-2-1 backup rule has been a foundational principle of data protection for decades. Originally articulated by photographer Peter Krogh in the context of digital photography, it was adopted by the IT industry because it elegantly addresses the three most common causes of data loss: hardware failure, human error, and site-level disasters. In 2025, ransomware has made it more important than ever — and has exposed exactly why so many "backup strategies" that businesses think they have are actually dangerously insufficient.

The 3-2-1 Rule Explained

The logic is straightforward. If you only have the original and one backup on the same device or network, a single hardware failure can destroy both. If both copies are on the same site, a fire, flood, or physical theft wipes them simultaneously. The offsite copy survives site-level disasters. The multiple media types protect against media-specific failures.

Why OneDrive and Dropbox Are Not Backups

This is the most common misconception we encounter. "We use OneDrive, so we're backed up" is something we hear regularly — and it represents a serious misunderstanding of what cloud sync services do.

OneDrive, Dropbox, and SharePoint are synchronisation services. Their job is to keep files consistent across your devices. That means if a file is deleted — whether by accident, by ransomware, or by a departing employee — that deletion is synchronised across every device. The file is gone everywhere, simultaneously.

Microsoft 365's recycle bin and version history provide some protection for limited periods, but they are not a substitute for proper backup. Ransomware operators know this — their malware is specifically designed to encrypt or delete files in OneDrive-synced folders, triggering synchronisation of the encrypted versions across all devices.

How Ransomware Targets Backup Systems

Modern ransomware groups devote specific effort to identifying and destroying backup systems before deploying the encryption payload. Common tactics include:

A backup stored on a network share accessible with the same domain credentials as your regular systems is not a safe backup — it's just another target. The offsite, isolated copy is the one that actually saves you.

The Modern Standard: 3-2-1-1-0

In response to the ransomware threat, backup experts and vendors have extended the original rule. The 3-2-1-1-0 rule adds:

RTO and RPO: The Numbers That Actually Matter

Two metrics define the practical value of your backup strategy:

Most SMBs have never formally defined their RTO and RPO. Having this conversation with your IT provider is one of the most valuable things you can do — it shapes every decision about your backup architecture.

Key Takeaways

Category: Backup & Recovery Published: 14 August 2025 Read time: 7 minutes Author: Xen IT Team

Need help protecting your business?

Xen IT designs and manages backup solutions that meet the 3-2-1-1-0 standard, with regular restore testing included. Get a free assessment today.

Get a Free Assessment