Last updated: April 29, 2026
Backups are the last line. They are also the prime target — modern ransomware encrypts backups before triggering payload. DR design must assume backups are attacker-accessible.
RTO and RPO defined
- RTO (Recovery Time Objective) — how long you can be down
- RPO (Recovery Point Objective) — how much data you can lose
Per-system RTO/RPO. Critical: minutes / no data loss. Tier-3: days / 24h data loss.
The 3-2-1-1-0 rule
- 3 copies of data
- 2 different media types
- 1 offsite
- 1 immutable / offline (the new addition)
- 0 errors after recovery testing
Immutable backups
- S3 Object Lock (compliance mode) — even root can’t delete
- Azure Blob immutable storage
- On-prem: tape, write-once-read-many appliances
Testing — the part that fails
Most organisations have backups. Few have tested recovery. Quarterly tabletop minimum: simulate a ransomware encryption event; restore from backups; measure actual RTO.
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.