← All transcripts

3‑2‑1 Backup Rule Explained: Protect Your Data from Disaster Transcript, AI Summary & Key Points

IBM Technology · Jun 21, 2026 · Education · 10:33 · EN

📄 Transcript

Searchable transcript of 3‑2‑1 Backup Rule Explained: Protect Your Data from Disaster — IBM Technology (10:33). Search for a phrase, then click its timestamp to jump straight to that moment in the video.

Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.

00:00 Three, two, one, liftoff, or disaster. If we're talking data backups, failing to follow the three, two one rule will probably result in the latter. So what is the three two one rule? It's a set of principles to protect you from data loss. Why should you care? Data is everywhere. You can always just make more, right? Well, data is the lifeblood of the modern enterprise.

00:25 It's your secret sauce, your customer records. Quite literally, it's both your future and your past. And if you lose it, then it's gonna feel like you're on that rocket that just crashed after takeoff. So let's take a look at the 3-2-1 rule to make sure this doesn't happen to you. And if stick around to the end, I'll throw in a few more numbers I think you're gonna wanna know.

00:46 Okay, let's look at what are the aspects of the 3 2 1 rule. First of all, there's a rule of three that makes up the three here. And it's basically that we need three copies. Of our data. Now, why is that? Well, we're going to have a primary copy of the data that we're working from and everyone should understand you need at least one backup because if you don't have that well then if the primary fails you've got nothing.

01:12 But bear in mind that if this thing goes down your one backup turns into no backups. So you're very exposed even still if you have only a single backup. A better idea, and this is what the rule of three is saying here, is that we have our primary copy of the data, we have a backup copy, and we have another backup copy. That way, now if we have two backups and one of them fails, then we still have a copy of our data.

01:43 So it's really simple. The rule of 3 here being have three copies of your data, even if at least one of those is what you're actually using in production. Now, the 2 portion of this. Says I need two different types of media. So I'm gonna store these backups on different types of storage devices. Now, why would I need that? Well, hardware sometimes fails.

02:07 So for instance, you might have stored this stuff on an SSD, solid state drive, and maybe that manufacturer had a bad batch of these and a whole bunch of them start failing. That's not hypothetical. That has actually happened. You're gonna wish that your backups were on something else as well. So maybe we're gonna put some of this on a spinning disk, on a hard disk drive.

02:30 And maybe I even have it NAS attached, network attached storage. So different technologies that are involved here so that if one fails, they don't all fail. And maybe even one other option would be to put one of these in the cloud. So I don't even know necessarily what technology is there. But I know it's not the very same drives that I have here. So three copies, two different types of media, and now we get down to the one.

02:57 At least one of these needs to be offsite. Now, why is that? Well, because we can have things like natural disasters. If I have a fire, flood, earthquake, something like that, then it doesn't matter how many of these I have. If they're all in one place, they all go up in smoke or they all get drowned. Or they all crush from the earthquake. So I need some, at least one of these to be offsite.

03:26 And that offsite, bear in mind, needs to have some geographical separation to it. So by this, I mean, I worked with a client one time where their main data center, their main offices were in New York City, and their offsite backup was just across the river in New Jersey. That's not geographical separation. If you have a hurricane, some massive winter storm that cuts the power to the whole area, well, then they're all going down.

03:53 So maybe you have one in New York and one in Arizona, for instance. So you want them really separated that way. There's three, two, one, three copies, two different types of media and at least one of them offsite. But I've got some more numbers for you. And now two more numbers, one and zero. What do those mean? Well, the one in this case means that I need at least one of these copies to be immutable or air gapped.

04:20 Now, what does that mean? An immutable backup is one where, think of it almost like a diode, where I can write one direction, the data flows in one direction but it doesn't go back the other way. So if I have a backup that is immutable, I can right out to it once but then I can read from it as many times as I want. I cannot overwrite that same. Now, I can still keep writing to the same storage, but it just keeps appending and adding more to it.

04:47 Now, what's the value of that? Well, if I have ransomware that has infected or encrypted my original copy, then it would be nice to know that I have a copy that it cannot also encrypt, because once it's been written, it can't be changed. So that's one example. A lot of organizations will say, yeah, but we do air gapped. Now, air gapping means just exactly that.

05:09 A lot of people that say they have air gap systems really don't an air gap means that it means there's air there's literally no connection between these two. So at some point there was a connection and then we separated them and at the point we separated then we took a snapshot. And this will forever now be locked in that time. In other words, the disadvantage to this is that it will not be current It will always be a snapshot and therefore will always be constantly falling further and further out of date.

05:43 The example with this is we can continue writing and not worry about it being overwritten, so it's still protected. But the big advantage here is I can keep writing out more copies. So it will be more up to date. But you need at least one of those to be immutable or error gapped so that it can't be changed after the fact. And the zero, ready for this?

06:05 We want none of these, no errors. Now, how does that happen? Well, I'll tell you for instance, I worked with a bank one time and they had done a good job of backing up all their data but what they didn't do was test those backups. And once they had a disaster, they went to go pull all the data from their backups, they had nothing. All of the data was useless.

06:30 So it's not enough to just do three, two, one, one. You also need to go back and periodically test those things, verify that recovery in fact, still works. Then if you have all of these things, you've got something that will really work. Oh, and there's another thing. Across all of this, what should we do? We should encrypt these backups. Because if we don't, someone may get a copy of one of these backups and then be able to read what might be our sensitive information.

06:59 So encrypt, and you'll notice one of the things that I'm verifying or maintaining, one of characteristics of this whole thing is I have no single points of failure. Because a single point of failure will come back to haunt you. So assuming we do all of this stuff, what are the benefits? What's the payoff for us? Well, it means we have among other things, protection against disasters, disaster recovery capabilities.

07:25 So as I mentioned, the fires, floods, and things like that. It's basically Murphy's law, which says anything that can go wrong will go wrong. And that's especially true when it comes to backups. Another thing we're trying to guard against are attacks. So where Murphy's Law is looking at accidental things that just happen in an imperfect world, attacks are intentional.

07:46 This is where someone's done ransomware or hacking into your systems and things like that. So if they've done that and I have sufficient backups, if someone does a ransomware attack and they say I've got your data and I'm not gonna give it to you until you pay me, if I say I got a copy of my data too, you can go pound salt, then we're covered. And then the other thing we can do is minimize downtime.

08:10 And every organization, whenever I ask them, how much downtime can you have? What kind of availability requirements do you have, guess what they all say? We need 24 by seven by 365. And I'm thinking in my head, you mean 365 and a quarter, right? You don't want leap day to be not working, right. So, but that's an laudable goal. But if you really thought about what that costs, in other words, if you never have a second of downtime, here's some numbers just for you to consider.

08:42 If you have 99% uptime, you know how much downtime that means in a year? It means three days. So 99% sounds pretty good until you started looking at that. Three days of downtime could be crippling for an organization. So we call those two nines of availability. What about if I have three nines of availability. What does this lead to? Well, this is gonna give us eight hours of downtime.

09:08 So basically a whole workday almost that's gonna be down even with three nines of availability. About four nines, of availability, surely this will make everybody happy. Well, four nimes will give you 52 minutes of downtime, it's almost an hour. And maybe that's good enough in a lot of cases, but in some it won't be. Let's say we go all the way on out here.

09:33 To five nines. Now what are we going to end up with? Five nines gives us around five minutes of downtime. So this is something maybe it would be tolerable. There are some cases where even that might not be acceptable. But the bottom line is every single one of these has a cost. And the further you move down, the more cost it is. And the more you want to have the downtime minimized.

10:01 The more you're gonna have to invest in backups. That's a huge part of all of this. So the bottom line is that you're going to have outages. The question is whether your environment will be resilient enough to weather the storm. Following the 3-2-1 backup rule is a great start and adding a few more digits to the plan will make it even better.

💡 Answer

Use three copies of data on two different media types, with at least one copy stored offsite; strengthen the plan with one immutable or air-gapped copy, zero recovery errors, encryption, and regular testing.

🧠 AI Summary

The 3-2-1 backup rule requires three copies of data, two different types of media, and at least one geographically separated offsite copy. A stronger plan adds one immutable or air-gapped copy and zero backup errors through periodic recovery testing. Backups should be encrypted and designed without single points of failure to withstand hardware failures, natural disasters, ransomware, and other attacks. Higher availability reduces downtime but requires greater investment.

🔑 Key Points

  • The 3-2-1 rule means three copies of data, two different types of media, and at least one geographically separated offsite copy.
  • Using two backups in addition to the primary copy ensures that one failed backup does not eliminate all backups.
  • Different storage technologies reduce the chance that a shared hardware failure will destroy every copy.
  • An immutable backup cannot be overwritten after being written, helping protect against ransomware encryption.
  • A true air gap requires no connection between systems after a snapshot is taken.
  • Backup recovery must be tested periodically because untested backups may fail when needed.
  • Backups should be encrypted to protect sensitive information if a copy is obtained by someone else.
  • Higher availability targets reduce permitted downtime but require greater investment in backups and resilience.

✅ Actionable items

  • Maintain three copies of data, including the primary production copy and two backups.
  • Store the copies on two different types of media, such as an SSD, hard disk drive, NAS, or cloud storage.
  • Place at least one backup in a geographically separate location rather than merely across a nearby river or within the same regional risk area.
  • Keep at least one copy immutable or air-gapped so it cannot be changed or encrypted after the relevant snapshot or write.
  • Periodically test backups and verify that recovery still works.
  • Encrypt backup copies to protect sensitive information.
  • Design the backup environment to avoid single points of failure.

🧭 Frameworks

3-2-1-1-0 backup rule04:36
  1. Keep three copies of data.
  2. Use two different types of media.
  3. Store at least one copy offsite with geographical separation.
  4. Keep at least one copy immutable or air-gapped.
  5. Maintain zero errors by periodically testing and verifying recovery.

🧰 Tools & AI usage

  • SSD — Storage media that can be used for backups.02:02
  • hard disk drive — Spinning-disk storage media that can be used as a different backup medium.02:25
  • network attached storage — A storage option for backup copies.02:30
  • cloud — A separate storage option for backup copies.02:40

📊 Numbers mentioned

Costs

  • Higher availability and lower downtime require greater investment in backups.
  • Every availability target has a cost.

Growth

  • 99% uptime allows three days of downtime per year.
  • Three nines of availability allows eight hours of downtime.
  • Four nines of availability allows 52 minutes of downtime.
  • Five nines of availability allows around five minutes of downtime.

⚖️ Advantages, risks & lessons

Advantages

  • Protection against fires, floods, earthquakes, and other natural disasters.
  • Protection against ransomware and hacking attacks.
  • Reduced downtime and improved disaster recovery capability.
  • No single point of failure when the backup environment is properly designed.

Risks

  • A single backup can fail and leave no usable backup.
  • A hardware defect can affect multiple copies stored on the same technology.
  • Backups stored in one location can be destroyed by the same disaster.
  • Ransomware can encrypt connected, mutable backups.
  • Air-gapped snapshots become increasingly out of date.
  • Untested backups may be unusable during recovery.
  • Unencrypted backups can expose sensitive information.

Lessons

  • A backup strategy must account for hardware failure, geographic disasters, intentional attacks, and recovery failure.
  • The number of copies alone is insufficient without media diversity, offsite separation, immutability, testing, and encryption.
  • Availability goals should be evaluated against their operational cost.

💬 Quotes

The bottom line is every single one of these has a cost.