The 3-2-1 backup rule is a resilience guideline: keep at least three copies of important data, use two different storage types or failure domains, and place one copy off-site. Modern variants add an offline or immutable copy and verification. Counting copies is not enough if they share credentials, synchronise corruption or cannot be restored. The rule also does not define retention, recovery time, encryption, ownership or application consistency. A backup design should map data and dependencies, set RPO and RTO targets, isolate administration and monitor failed jobs. Regular restore exercises with acceptance criteria are essential because a successful backup status only confirms that a job completed. Results and exceptions should be recorded so protection gaps remain visible and actionable.
IT glossary
3-2-1 backup rule
Let's talk
Need help with this?
30 minutes with a senior consultant. No commitment, no sales pitch. An honest conversation about what you need and what we can do together.