Business backup: the 3-2-1-1-0 rule explained simply
Why a single copy of your data is not enough, what the 3-2-1-1-0 rule means and how to apply it to withstand hardware failures, human error and ransomware.

Almost every company does some form of backup. Many, however, find out it does not work at the very moment they need it: the external drive was connected to the server hit by ransomware, the cloud copy had not been updated for months, the restore had never been tested.
A backup is not worth the number of copies you make, but how easily and safely you can get back up and running. That is why it helps to follow a simple, memorable rule: 3-2-1-1-0.
The rule, digit by digit
- 3 copies of your data: the original plus at least two backup copies.
- 2 different media: for example local storage and a cloud service. If one type of media fails, the other is still available.
- 1 copy off site: a fire, a flood or a theft must not be able to destroy the original and the backups at the same time.
- 1 immutable or offline copy: a copy that, once written, cannot be changed or deleted for a set period, not even by an administrator. It is the decisive defense against ransomware, which today looks for and encrypts backups first.
- 0 restore errors: backups must be verified and restores tested regularly. A backup that has never been tested is just a hope.
What to protect
People often stop at the files on the server, but company data now lives in many places:
- servers and virtual machines, including configurations and operating systems;
- workstations and laptops, where documents never saved anywhere else are kept;
- databases and business applications;
- cloud services such as Microsoft 365: mail, OneDrive and SharePoint need their own backup, because the provider guarantees the availability of the service, not the long-term retention of your data;
- NAS devices and network drives.
Two numbers to decide before trouble strikes
- RPO (Recovery Point Objective): how much data can you afford to lose? If the answer is “one hour of work at most”, a nightly backup is not enough.
- RTO (Recovery Time Objective): how quickly do you need to be operational again? Restoring a file is one thing; bringing back an entire server within a few hours is another, and requires different tools.
Defining these two values for each system lets you choose backup frequency, technologies and costs without waste.
The most common mistakes
- Keeping backups on the same storage or network as the original data.
- Using the same administrator credentials for systems and backups.
- Not encrypting copies, especially off-site ones.
- Not checking backup reports: failed jobs go unnoticed for weeks.
- Never testing a full restore.
How 7dBackup does it
7dBackup applies the 3-2-1-1-0 rule without complications. Data is compressed and encrypted with AES-256 on the device itself, with customer-managed keys, and stored on immutable storage in certified European data centers, replicated across different sites. A single console protects Windows, macOS and Linux workstations, servers, VMware, Hyper-V and Proxmox environments, Microsoft 365, databases and NAS devices.
And so that recovery does not remain theoretical, our team helps you define RPO and RTO, set up retention policies and regularly test your return to operations.


