{"id":16281,"date":"2026-06-05T13:48:01","date_gmt":"2026-06-05T13:48:01","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=16281"},"modified":"2026-07-09T16:27:26","modified_gmt":"2026-07-09T16:27:26","slug":"3-2-1-1-0-restore-test","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/06\/05\/3-2-1-1-0-restore-test\/","title":{"rendered":"Backup against ransomware: 3-2-1-1-0 instead of 3-2-1"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">8 min. read<\/p>\n<p><strong>Most backup concepts are built for disk failure, not an active attacker. Modern ransomware targets the backup first &#8211; deleting or encrypting it to strip the victim of their strongest leverage against extortion. A backup that holds up under real pressure doesn&#8217;t just follow the old three-copy rule; it follows a harder version. What matters is a passed restore test, not the documentation in the concept paper.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Ransomware targets the backup.<\/strong> According to Sophos, attackers attempt to compromise backups in 94 percent of cases. Organizations that only protect against hardware failure are planning around the wrong threat model.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">3-2-1-1-0 closes the gap the old rule leaves open.<\/strong> An immutable copy and an offline copy put the backup out of an attacker&#8217;s reach. The zero stands for zero errors in the recovery test.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Without a restore test, there is no proof.<\/strong> A backup that has never been restored is not a reliable recovery path. Only regular restore tests reveal whether data, permissions, and dependencies actually work when it counts.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/29\/the-edge-device-as-a-ransomware-gateway-why-mfa-at-the-vpn-is-not-enough\/\" style=\"color:#333;text-decoration:underline;\">The Edge Device as a Ransomware Entry Point<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/29\/nis2-vollstreckung-2026-bsi-audit-persoenliche-haftung\/\" style=\"color:#333;text-decoration:underline;\">NIS2 Is Now Being Enforced<\/a><\/p>\n<p><strong>What is the 3-2-1-1-0 rule?<\/strong> This extended backup strategy follows a fixed pattern. Three copies of the data are stored on two different media types, one of them at a separate location. On top of that comes an immutable or offline copy, and the requirement that recovery must be tested with zero errors. It hardens the classic 3-2-1 rule specifically against ransomware.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why ransomware goes after backups first<\/h2>\n<p>A well-planned ransomware attack doesn&#8217;t encrypt immediately. It moves through the network first, locates backup systems, and disables them before touching production data. The logic is straightforward: a victim with an intact backup can restore. Without a reliable copy, the options narrow to payment, full rebuild, or data loss. The backup itself becomes the primary target.<\/p>\n<p>Incident data consistently reflects the same pattern. In the vast majority of cases, attackers actively attempt to compromise backups &#8211; and in more than half of those cases, they succeed. When the backup fails, recovery costs climb sharply because the fast path back no longer exists.<\/p>\n<div style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\" class=\"evm-stat-highlight\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">94 Percent<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">of organizations hit by ransomware report that attackers deliberately attempted to compromise their backups.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: Sophos, State of Ransomware<\/div>\n<\/div>\n<p>That changes the requirement entirely. Having a backup is not enough. It must survive an attacker who is actively hunting for it. A backup system reachable with the same credentials as the rest of the network remains part of the compromisable infrastructure.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What 3-2-1-1-0 demands beyond the original rule<\/h2>\n<p>The classic 3-2-1 rule dates from an era when data loss was primarily a technical event: a failed drive, a fire, an accidental deletion. Against those scenarios it still holds up. Against an attacker who is actively working through your infrastructure, it has a gap. The two additional digits close exactly that.<\/p>\n<div style=\"overflow-x:auto;-webkit-overflow-scrolling:touch;margin:16px 0 32px 0;\" data-element=\"comparison_table\">\n<table style=\"width:100%;min-width:560px;border-collapse:collapse;font-size:0.95em;\">\n<thead>\n<tr style=\"background:#003340;color:#fff;\">\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #003340;color:#fff;\">Digit<\/th>\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #003340;color:#fff;\">Meaning<\/th>\n<th style=\"padding:12px 16px;text-align:left;border:1px solid #003340;color:#fff;\">Protects against<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>3 copies<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">Original plus two backups<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#69d8ed;font-weight:600;\">isolated data loss<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>2 media<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">two different storage types<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#69d8ed;font-weight:600;\">media failure<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>1 offsite<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">one copy at a separate location<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#69d8ed;font-weight:600;\">site-level damage<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>1 immutable or offline<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">a copy that cannot be deleted or is fully disconnected<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#69d8ed;font-weight:600;\">ransomware access<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\"><strong>0 errors<\/strong><\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;\">verified restore<\/td>\n<td style=\"padding:12px 16px;border:1px solid #ddd;color:#69d8ed;font-weight:600;\">silent failure when it counts<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>The first three digits remain the familiar rule. The fourth digit and the zero harden it against ransomware. At least one backup sits beyond the attacker&#8217;s reach. Recovery is tested, not merely documented.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What immutability and air-gapping deliver when it matters<\/h2>\n<p>Behind the fourth digit lie two concepts that are often used interchangeably but do not mean the same thing. Immutability means the backup cannot be modified or deleted for a defined retention period &#8211; not even by an administrator with stolen credentials. Technically, this relies on mechanisms such as Object Lock or write-once storage that accepts data exactly once.<\/p>\n<p>An air gap means separation. The copy sits logically or physically outside every network an attacker can reach. Only when both properties are combined do you get a backup that reliably survives a determined attack. An immutable copy on a reachable system can be circumvented if the attacker is able to manipulate the retention rules. A disconnected copy without write protection can be overwritten the next time it is connected. The combination is where a backup becomes truly secure.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The Test Nobody Runs<\/h2>\n<p>The zero in the rule is the most uncomfortable position, because it demands work. Writing a backup is routine; restoring one is not. That is precisely why the restore test remains theoretical in many organizations &#8211; until an incident forces the issue. Then it turns out the backup was incomplete, a key is missing, recovery takes days instead of hours. These surprises belong in the test, not in the incident.<\/p>\n<div style=\"display:grid;grid-template-columns:repeat(auto-fit,minmax(280px,1fr));gap:16px;margin:28px 0;\" class=\"evm-pros-cons\">\n<div style=\"background:#fdf3f3;padding:24px 28px;border-radius:8px;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#c0392b;\">What fails<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Backups accessible with the same admin credentials as the production network<\/li>\n<li style=\"margin-bottom:6px;\">Immutability assumed but never verified against tampering<\/li>\n<li style=\"margin-bottom:6px;\">Restore practiced only on paper, never under real conditions<\/li>\n<li>Recovery time unknown until an incident measures it<\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#f1f7f0;padding:24px 28px;border-radius:8px;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#2d7a3e;\">What holds<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">One immutable and one separate copy stored outside the domain<\/li>\n<li style=\"margin-bottom:6px;\">Dedicated credentials for the backup system, isolated from day-to-day operations<\/li>\n<li style=\"margin-bottom:6px;\">Regular restore tests with measured recovery times<\/li>\n<li>An isolated recovery environment ready for the real emergency<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>The difference between the two columns requires no additional license. It requires discipline. A backup is not a purchase you check off a list &#8211; it is a process that must be proven. Anyone who takes the fourth position seriously and tests the zero regularly will have, when it matters, the one lever that renders an attack useless.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>What exactly does the extended backup rule mean?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Three copies of the data on two different media, one of them at a separate location. Add to that an immutable or offline copy, and the requirement that recovery has been tested with zero errors. The last two elements specifically harden the classic 3-2-1 rule against ransomware that targets backups directly.<\/p>\n<\/details>\n<details>\n<summary><strong>Why is the old 3-2-1 rule no longer enough?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">It protects against technical data loss such as hardware failure, fire, or accidental deletion &#8211; but not against an attacker actively probing your infrastructure. If all copies are online and reachable with the same credentials, ransomware can encrypt them too. Only an immutable or air-gapped copy closes that gap.<\/p>\n<\/details>\n<details>\n<summary><strong>What is the difference between immutability and an air gap?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Immutability means a backup cannot be modified or deleted for a defined period &#8211; even with admin rights. An air gap means physical or logical separation from any reachable network. Only when both properties are combined do you get a copy that reliably survives a serious attack. Either alone can be circumvented.<\/p>\n<\/details>\n<details>\n<summary><strong>How often should you run a restore test?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Regularly &#8211; and for truly critical systems, at least quarterly. What matters is not just testing whether individual files can be read back, but verifying the complete restoration of a system including the measured time it takes. Only then does &#8220;the backup works&#8221; stop being an assumption and become a concrete, defensible number.<\/p>\n<\/details>\n<details>\n<summary><strong>What is an isolated recovery environment?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">A segregated area where systems can be restored from backup and verified without touching a production network that may still be compromised. This ensures the recovery is clean and does not reintroduce the same malicious code that triggered the incident in the first place.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/26\/cyber-liability-in-administration-three-levels-no-plan\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/cyber-haftung-foederalismus-illustration-250x140.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Cyber Liability in Administration: Three Levels, No Plan<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/30\/linux-kernel-luecken-bsi-update-dirty-frag-root-eskalation\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/linux-kernel-luecken-bsi-update-dirty-frag-root-eskalation-2026-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Linux Kernel Vulnerabilities: BSI Warns of Root Escalation<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/01\/14-malicious-npm-packages-in-four-hours-why-static-third-party-checks-are-no\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/14-boesartige-npm-pakete-in-vier-stunden-warum-statische-third-party-pruefung-nicht-mehr-reicht-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">14 Malicious npm Packages in Four Hours: Why Static Third-Party Checks Are No Longer Enough<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/19\/platform-engineering-critical-infrastructure\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-platform-engineering-geschaeftskritische-78956570.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Platform Engineering is no longer just a DevEx project<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/ciso-compliance-under-nis2\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-ciso-compliance-under-nis2-67286561-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Managed Security Services: CISO Does Not Bear Sole Liability<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/stanford-ai-index-2026-inaccuracy-cybersecurity-mittelstand\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-stanford-ai-index-2026-inaccuracy-cybers-67641028-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Stanford AI Index 2026: Inaccuracy overtakes cybersecurity as top risk \u2013 what SMEs must measure<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"Ransomware targets backups. Why the old 3-2-1-1-0 rule is being replaced, what immutability and air-gap mean, and why the restore test is decisive.","protected":false},"author":10,"featured_media":16348,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Ransomware backup","_yoast_wpseo_title":"Backup against ransomware: 3-2-1-1-0 instead of 3-2-1","_yoast_wpseo_metadesc":"Protect your data: Learn why 3-2-1-1-0 beats old backup rules, what Immutability & Air-Gap mean, and why only restore tests count.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255],"tags":[233],"class_list":["post-16281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en","tag-ransomware"],"evm_reading_time_minutes":8,"wpml_language":"en","wpml_translation_of":16149,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/16281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=16281"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/16281\/revisions"}],"predecessor-version":[{"id":21178,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/16281\/revisions\/21178"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/16348"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=16281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=16281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=16281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}