Skip to main content

The 3-2-1-2-0 Rule

  • August 3, 2026
  • 5 comments
  • 43 views

Nico Losschaert
Forum|alt.badge.img+13

Why True Cyber Resilience Requires More Than One Immutable Repository

 

 

"You wouldn't protect your house with just one lock. So why protect your last line of defense with just one immutable technology?"

For years, the 3-2-1-1-0 rule has been the benchmark for designing resilient backup environments. It has helped thousands of organizations improve their backup strategy and defend themselves against ransomware.

But cyber threats continue to evolve.

Attackers are no longer just encrypting production workloads—they are actively targeting backup infrastructures because they know that if they can destroy your backups, they control your recovery.

That made me think...

Is one immutable repository really enough?

Or should we apply the same security principles that we use everywhere else?

 

Protecting Your Home

Imagine you're leaving your house for a two-week vacation.

Before you leave, what do you do?

Certainly not just this:

✔ Close the front door.

Instead, you probably do something like this:

  • 🔐 Lock the door

  • 🔒 Use security locks

  • 🚪 Close every window

  • 🚨 Activate the alarm system

  • 📷 Enable security cameras

  • 💡 Turn on automatic lighting

  • 👥 Ask the neighbours to keep an eye on your house

Why?

Because security is built in layers.

No single measure guarantees protection.

Every additional layer increases the attacker's effort.

Every additional layer decreases the chance of success.

 

Now Replace "House" With "Backup Infrastructure"

The same philosophy applies to backup.

Many organizations invest heavily in:

  • Firewalls

  • MFA

  • EDR/XDR

  • Network segmentation

  • Zero Trust

  • Identity protection

Yet when it comes to the last line of defense, they often rely on one immutable repository.

That isn't necessarily wrong.

But it raises an important question.

Why would we rely on a single security technology to protect the most valuable copies of our data?

 

The Industry Standard: 3-2-1-1-0

Let's briefly revisit the well-known rule.

Number

Meaning

3

Keep at least three copies of your data

2

Store them on two different media or technologies

1

Keep one copy offsite

1

Ensure one copy is immutable or offline

0

Verify zero backup errors through testing

It remains one of the best backup strategies ever created.

And I still fully support it.

But I believe we can strengthen it even further.

 

Introducing My 3-2-1-2-0 Rule

The additional 2 is simple.

Use two different immutable technologies.

Not because one isn't secure.

But because technology diversity increases cyber resilience.

Different technologies.

Different architectures.

Different attack surfaces.

Different ways of protecting your data.

Exactly like using both an alarm system and security cameras to protect your house.

 

Repository #1 – Veeam Hardened Repository

Veeam Installer Appliance (VIA) running a hardened Linux repository offers:

  • Linux hardening

  • XFS immutability

  • Minimal attack surface

  • Tight Veeam integration

  • Excellent ransomware protection

It has become one of the most trusted repository designs in the Veeam ecosystem.

 

Repository #2 – Object First OOTBI

Now add an Object First Ootbi appliance.

Purpose-built exclusively for Veeam.

Designed from day one around immutable object storage.

Its strengths include:

  • Out-of-the-Box Immutability

  • Purpose-built architecture

  • Simple deployment

  • Minimal administration

  • Strong ransomware resilience

It doesn't replace the hardened repository.

It complements it.

 

Why Technology Diversity Matters

Imagine a burglar.

He manages to bypass your security lock.

Your alarm immediately triggers.

Security cameras record everything.

Motion sensors activate.

Neighbours are alerted.

Each layer is independent.

Each layer increases resilience.

The same principle applies to backup repositories.

If one immutable technology experiences an operational issue, misconfiguration, or unforeseen vulnerability, the second repository remains fundamentally different.

That's the power of diversity.

 

Cyber Resilience Is About Reducing Common Risk

One immutable repository is excellent.

Two immutable repositories based on different technologies are even stronger.

You're not simply creating another copy.

You're reducing shared risk.

You're avoiding putting all your eggs in one security basket.

And that is exactly what resilience is about.

 

From Backup to Recovery Confidence

At the end of the day, backup is not the goal.

Recovery is.

Your organization doesn't care whether the backup job completed successfully.

It cares whether critical business systems can be restored after a cyberattack.

That's why I believe the conversation should evolve from:

"Do we have immutable backups?"

to

"How resilient is our immutable backup strategy?"

 

Final Thoughts

The 3-2-1-1-0 rule remains the foundation of modern data protection.

I don't want to replace it.

I want to build upon it.

That's why I advocate what I call the 3-2-1-2-0 rule:

  • ✔ 3 copies of your data

  • ✔ 2 different storage technologies

  • ✔ 1 copy offsite

  • ✔ 2 independent immutable technologies

  • ✔ 0 backup verification errors

Because cyber resilience isn't about trusting a single lock.

It's about building multiple independent layers that work together to protect what matters most.

 

What Do You Think?

Would you trust your home to a single lock?

Then why trust your backups to a single immutable technology?

I'd love to hear your thoughts.

How are you increasing the resilience of your backup repositories? Are you relying on one immutable technology, or have you already embraced diversity in your cyber resilience strategy?

5 comments

Chris.Childerhose
Forum|alt.badge.img+22

Great write-up Nico.  We have multiple copies of backups across our datacenters sending them to each other with immutable object storage.


coolsport00
Forum|alt.badge.img+23
  • Veeam Legend
  • August 3, 2026

Nice post Nico! I have “data everywhere” in my environment...and yes, it of course is immutable too. But, even more importantly...as you mention above, is having the ability to recover it! Hopefully I’m covered in the event of some mishap 🙏🏻

Thank you for sharing!


wolff.mateus
Forum|alt.badge.img+12
  • Veeam Vanguard
  • August 4, 2026

I remember that some years ago, when v11 was release and bring to us the imuttability on local repositories. That fetature becomes the golden ticket. It was a big differencial to have a Linux immutable repository. Nowadays only one level of imutability is not enough. Great post ​@Nico Losschaert!


  • New Here
  • August 4, 2026

Hi Nico , it sounds great to me having 2 immutable copies like at home having I photo and it copie in an safe protected for fires. 
But who can afford this at home or in enterprises in term of budget , competencies , and procedures etc.

at home you have different keys for the same gate , , different protection at the perimeter and inside you have different copies of your data if you are well prepared for the risks , but who have different copies of your all your data ? (Non digital included) . I recon a few less Than 5% . 
in enterprise it can be more probably 20% who are keen to invest more on data protection from the backup that in cyber security. 
In my point of view I would more advise my customers to invest on 2 different repositories from different technologies and both with the ability to manage Immutability when the can afford it , and if they cannot I would suggest them to improve the controls of there backups and restore . this is the 80% of the small companies. 
what do you think , does it make sense ? 
PS: now with your post I begin to understand why Veeam acquired Object First. 

 


Nico Losschaert
Forum|alt.badge.img+13

Hi Nico , it sounds great to me having 2 immutable copies like at home having I photo and it copie in an safe protected for fires. 
But who can afford this at home or in enterprises in term of budget , competencies , and procedures etc.

at home you have different keys for the same gate , , different protection at the perimeter and inside you have different copies of your data if you are well prepared for the risks , but who have different copies of your all your data ? (Non digital included) . I recon a few less Than 5% . 
in enterprise it can be more probably 20% who are keen to invest more on data protection from the backup that in cyber security. 
In my point of view I would more advise my customers to invest on 2 different repositories from different technologies and both with the ability to manage Immutability when the can afford it , and if they cannot I would suggest them to improve the controls of there backups and restore . this is the 80% of the small companies. 
what do you think , does it make sense ? 
PS: now with your post I begin to understand why Veeam acquired Object First. 

 

Hi ​@sebsim , I fully understand your remark. I agree, every layer costs extra money, unfortunately. But as you know, data has grown enormously during the years and has become so important for a company, that they are facing a very big problem when they are missing that data. Unfortunately, often it means becoming bankrupt without it. Therefore as a company owner you have to ask yourselves, how important is that data for the company and how many risk will we take of loosing it? As a consultant I have to give correct advice. As mentioned, the 3-2-1-1-0 is the base, the minimum every company should have. If you want to bring your company a level higher and being more secure to have your data when some bad things happen, implement the 3-2-1-2-0 rule. It’s a bit like implementing a Disaster Recovery solution and having DR plans or having the idea that this is not necessary.