What is the 3-2-1 Backup Rule
The 3-2-1 backup rule is a widely recognized industry standard for protecting data against any kind of failure, human error, or unexpected event (fire, theft, ransomware, hardware failure, etc.).
The name comes from three numbers:
- 3 total copies of the data (the original + 2 backup copies)
- 2 different storage media (for example, local disk and NAS, or disk and tape)
- 1 copy kept offsite, away from the main location
Why it matters
Having just one backup copy, even if it exists, doesn't protect against every possible scenario. For example:
- If the backup lives on the same storage or in the same rack as the original system, a hardware failure or fire can destroy both at once.
- If all copies are in the same building, an event like flooding, fire, or theft can wipe them out together.
- If ransomware encrypts a network-attached backup too, the only copy that's truly safe is the one that's isolated (offline or offsite).
The 3-2-1 rule drastically reduces the risk of total data loss, because no single point of failure can destroy all copies at the same time.
How it works in practice
| Element | Example |
| Original copy | Production data on the Syneto system |
| 2nd copy (same site) | Backup on different storage on-site, e.g. a secondary storage system or a NAS |
| 3rd copy (offsite) | Backup replicated to a remote site, to the cloud, or on removable media kept elsewhere |
A backup is considered "verified" when it is:
- Complete: it covers all relevant systems and data, not just part of them.
- Intact: it has been tested with an actual restore, not just created.
- Up to date: it reflects the recent state of the data, not an outdated version.
Why this is Required before an RMA intervention
During a hardware replacement (RMA), there is always a residual risk, however small, of data loss related to the operation itself. That's why, before proceeding with a component replacement, confirmation is required that the customer has a complete, intact, and up-to-date 3-2-1 backup of the systems involved. This isn't a bureaucratic hurdle — it's a safeguard for the customer's own data. If something unexpected happens during the intervention, a verified backup ensures no data is permanently lost.
IMPORTANT
If a backup isn't in place or can't be verified, the intervention cannot proceed until this condition is met.
FAQ
My Syneto storage already has a built-in backup, isn't that enough? No. If the backup lives on the same system or the same site as the original data, it doesn't satisfy the 3-2-1 rule — it's missing media diversification and/or an offsite copy.
What happens if I don't have a backup ready? The RMA intervention is paused until an adequate backup of the affected systems is put in place and verified.
How do I verify my backup is "intact"? By performing a test restore (even a partial one) to confirm the data is actually recoverable — not just that the backup process completed without errors.