Immutable Backups: Why 3-2-1 Is No Longer Enough

In 89% of ransomware cases, attackers targeted the backups. What 3-2-1-1-0 means, how immutability works – and what belongs in the emergency plan.

Your backup exists – but does it survive an attacker with domain admin rights? That is the question by which modern data protection is measured. Because ransomware groups have long since stopped merely encrypting production systems: they first seek out the backups, delete or encrypt them – and then negotiate with a company that no longer has a fallback option.

The figures on this are unambiguous. According to the Veeam Ransomware Trends Report 2025, in 89% of affected companies attackers deliberately targeted the backup repositories. At the same time, only 32% of respondents used immutable repositories. The gap between these two figures is the actual risk.

What happens when the backup falls

The same report paints a sober picture of recovery: 69% of the organizations surveyed were attacked in the past year. Of those affected, only 10% were able to recover more than 90% of their data – 57% recovered less than half.

The Sophos report “State of Ransomware 2025” adds the uncomfortable consequence: 49% of the companies whose data was encrypted paid the ransom, and recovery from backups was at its lowest level in six years. Those who pay rarely do so out of conviction – but because the backup was no longer there at the decisive moment or did not work.

From 3-2-1 to 3-2-1-1-0

The classic 3-2-1 rule – three copies, two media types, one copy off-site – stems from a time when the threat scenario was hardware failure or fire. Against an attacker standing in the network with stolen administrator rights, it helps only to a limited extent: he reaches all three copies if they are online and administrable with the same rights.

Veeam therefore formulates the extended rule 3-2-1-1-0:

  • 3 copies of the data,
  • on 2 different media,
  • 1 copy off-site,
  • 1 copy immutable or separated by an air gap,
  • 0 errors after automated recovery verification.

The last two digits make the difference. The additional “1” means: at least one copy can be neither deleted nor altered, even with full administrator rights. The “0” means: you do not rely on the backup working – you verify it automatically.

Immutability in practice: two proven approaches

For implementation with Veeam Backup & Replication, there are two established mechanisms:

Hardened Repository

A Linux server as a hardened repository, where Veeam stores backup files write-protected for a defined period via the immutability attribute of the file system – recommended on XFS, which additionally enables fast synthetic full backups. Even a compromised Veeam or domain admin account cannot delete the backups within the protection period. What matters is a clean hardening of the system itself: the repository must not be a member of the domain whose compromise it is meant to survive.

S3 Object Lock

Alternatively or additionally: object storage with S3 Object Lock, on-premises or in the cloud. Veeam then writes backups with a retention lock that even the storage provider’s admin cannot lift prematurely. A practical stumbling block: with most providers, Object Lock must be activated already when the bucket is created – AWS has only allowed retrofitting on existing buckets since the end of 2023.

Both approaches align with what the BSI recommends in its Ransomware measures catalog: keep at least one backup copy offline, regularly verify that an administrator account cannot reach this copy from the network, and actually practice restores.

The “0”: restore tests as routine, not as an event

A backup that has never been restored is a promise without proof. The zero in 3-2-1-1-0 requires automated recovery verification: backups are regularly started or mounted on a test basis and checked for consistency – not once a year manually, but as a fixed component of backup operations.

This is now also anchored in regulation. The NIS-2 directive expressly counts backup management, business continuity, and crisis management among the minimum measures in Art. 21(2)(c). For financial entities, DORA requires documented backup policies and periodic recovery tests in Art. 12 – expressly on systems that are separated from the production system. Anyone who sets up restore tests cleanly handles the technical and the compliance evidence in one step.

The compact emergency plan: who calls whom when the email is gone?

The best backup is of little use if, in an emergency, no one knows what to do. A ransomware incident typically also hits the communication channels: email, telephone system, and document store can fail at the same time. A usable emergency plan for the mid-market therefore need not be a hundred-page manual – but it must be available offline and at least answer:

  • Who decides? A crisis team with names and deputies, including the decision to shut down systems.
  • Who calls whom – and about what? A contact list on paper or on an independent device: management, IT, service providers, insurers, and reporting bodies where applicable.
  • What is restored first? A prioritized list of the business processes and the systems behind them.
  • Where are the credentials for the emergency? Separate from the compromisable directory service.

Anyone who wants to build this on a methodical foundation will find, with the BSI Standard 200-4, a framework for business continuity management that is expressly scalable to smaller organizations too; it replaces the older Standard 100-4 and is compatible with ISO 22301:2019, the certifiable BCMS standard. For most mid-market companies, the pragmatic order is: first the immutable copy and the practiced restore, then the structured BCM build-up on top of it.

How sector7 helps

We design and operate backup environments in lived Veeam practice – from the hardened repository, through object-lock storage targets, to automated recovery verification, monitored by our NOC around the clock. As an owner-led business with vendor-certified engineering practice (Juniper, Cisco, HPE, F5, Fortinet, Palo Alto Networks), we combine this with emergency planning and compliance consulting on ISO 27001, NIS-2, and DORA. Operation and support are available at predictable flat monthly rates.

Sources

Let's talk about your situation.