The 3-2-1 rule reigned for 20 years. But in 2026, faced with ransomware that encrypts even online backups, it's no longer enough. The new standard is called 3-2-1-1-0. Here's what each number means, and why your SMB must move to it.
3 — Three copies of the data
Your data lives in three places: production (workstation, server), a first local backup (NAS, array), and a second off-site backup (cloud, remote site). Three copies = three chances to survive.
2 — Two different media
Not three copies on the same type of storage. Disk + tape, or disk + cloud, or local disk + remote disk. Diversifying the medium protects against grouped hardware failures (corrupted firmware, batch defect).
1 — One off-site copy
At least one copy is not in the main building. Sovereign cloud (OVH, Outscale), remote site of another office, partner datacenter. Protects against fire, theft, flooding, major incident.
1 — One immutable copy
This is the new pillar against ransomware. One copy is stored in WORM (Write Once Read Many) mode — impossible to modify or delete for a defined period, even by a compromised administrator. Modern solutions (Veeam, Proxmox Backup Server, S3 Object Lock) support it natively.
0 — Zero errors after verification
A backup is only useful if it restores. Regular automatic integrity check + quarterly restore test in a sandbox environment. Many companies discover their backups are corrupted on the day of the incident. The test prevents that.
How much does it cost vs the loss?
For an SMB of 50 users, a full 3-2-1-1-0 strategy costs €200 to €500 ex. VAT per month depending on volume and RPO. The average cost of a non-recoverable ransomware incident is €250,000 (Hiscox 2024 study). The math is simple.

