Definition

The 3-2-1-1 rule is a backup practice that structures data protection as follows:

  • 3 copies of the data, including production and two backups,
  • on 2 different storage media or technologies,
  • with 1 off-site copy, protected from a local incident such as fire, flooding or theft,
  • and 1 offline or tamper-protected copy that an attacker cannot reach.

Why the second "1" was added

The original 3-2-1 rule protects against hardware failure and site loss, but not against an attacker who can reach online backups. The final "1", an offline copy, corresponds to the offline backup recommended by ANSSI as a baseline defence against ransomware. It is the weakest link in many backup designs.

How Oxibox puts the final "1" into operation

Maintaining an offline copy manually with tape or unplugged disks is labour-intensive and slow to recover. Oxibox replaces that handling with a software air gap. Oxibox Backup Guardian keeps a copy on an append-only write path, with a retention floor that can only be extended. Compromised credentials cannot overwrite or delete it, yet it remains immediately recoverable. Appliance and Full Cloud deployments add a geo-redundant cloud copy for the off-site requirement.