Module 4 · Backup Strategy — 3-2-1-1-0 and Ransomware-Resilient Architecture

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 14, 2026
4 min read
Read as
100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. Backup strategy is the foundation of recovery — but most Indian enterprises run backup architectures that are vulnerable to the very threats that necessitate recovery. Ransomware actors specifically target backups. This module covers the 3-2-1 rule, immutable storage, air-gapped backups, and the modern ransomware-resilient backup architecture.

Why this module exists. A backup that fails to restore is worse than no backup — it costs effort to maintain and provides false assurance. This module covers what to back up, how to store it so attackers cannot destroy it, and how to verify it works.

The 3-2-1 rule — the baseline

The classic backup recipe: 3 copies of data, on 2 different media types, with 1 copy off-site. The interpretation in modern cloud-native environments:

  • Primary (production data) + 2 backups.
  • Two different storage technologies (e.g., disk + object storage; or cloud + on-prem).
  • One copy geographically separated from the others — different region, different cloud, different building.
Worried about your exposure?

Get a free attack-surface review

We check what an attacker would see about your business — leaked credentials, exposed services, dark-web mentions. 30 minutes, no obligation.

Book exposure review Replies in 4 working hrs · India-only · Senior consultants