Building a Backup and Disaster Recovery Strategy That Actually Works
Backups that nobody has restored are not backups. Here is the operational playbook for a 3-2-1-1-0 strategy that survives ransomware, hardware loss, and human error.

The 3-2-1-1-0 rule
The classic 3-2-1 backup rule — three copies, two media types, one off-site — has evolved. The modern rule is 3-2-1-1-0: three copies, two media, one off-site, one immutable, zero unverified restores.
The two additions matter. Immutability defeats ransomware that targets backup repositories. Verified restores defeat the most common operational failure: backups that have been running successfully for years and are unreadable when needed.
RPO and RTO drive the design
Recovery Point Objective is how much data you can afford to lose. Recovery Time Objective is how long you can afford to be down. Both are business decisions, not technical ones. Drive them out of the business before you choose tools.
A 24-hour RPO and 4-hour RTO is achievable with nightly snapshots and a documented restore runbook. A 1-minute RPO and 5-minute RTO requires synchronous replication and active-active infrastructure — an order of magnitude more expensive.
Immutable backup tier
At least one copy of your backup must be immutable for its retention period. S3 Object Lock in compliance mode, immutable Veeam repositories, write-once optical media, or a properly air-gapped tape vault all qualify.
Immutability defeats the ransomware attack pattern where attackers spend weeks inside your network deleting backup history before triggering encryption. Without an immutable tier, the attacker controls your recovery path.
Application-consistent versus crash-consistent
A crash-consistent backup is what you get when you snapshot a running system without coordinating with the application. An application-consistent backup is what you get when you flush database buffers, quiesce writes, and then snapshot.
For databases, application-consistent backups via the database's native tooling (pg_basebackup, mysqldump, native SQL Server backup) are non-negotiable. Crash-consistent snapshots may restore to a state the database cannot recover from.
Test restores or it does not exist
Run a documented restore at least quarterly. Restore to a separate environment, verify the data, and document the timing. The first time you discover your backups have been silently corrupting should not be during an outage.
Automate the test where possible. Veeam, Rubrik, and Cohesity all support scheduled restore verification. For self-built backup systems, write the verification step into your runbook.
Disaster recovery is not the same as backup
Backups handle data loss. Disaster recovery handles capability loss — datacenter on fire, region down, ransomware locking the production environment. DR requires a documented runbook, a tested failover environment, and a regular exercise.
The DR exercise should include the people, not just the technology. The first time your team rebuilds the production environment from backups should not be at 3 a.m. with the business losing money per minute.
Reader questions, answered
Cloud snapshots are backups, right?+
Not on their own. Snapshots inside the same account or region are not off-site. Copy them out for them to count.
How long should retention be?+
Driven by regulatory requirements (7 years is common for financial records). For operational recovery, 30–90 days plus quarterly archives is typical.

Raza Ahmad is a technology author and IT infrastructure specialist based in Melbourne, Australia. He writes practitioner-grade guides on cloud computing (Azure and AWS), cybersecurity, enterprise networking with Cisco platforms, Linux administration, DevOps, and virtualization. His work focuses on translating complex infrastructure topics into clear, accurate guidance that engineers, system administrators, and IT decision makers can put to work in production environments. Every article published under his byline is fact-checked against current vendor documentation, official standards, and Raza's own hands-on experience operating the technologies he covers.
More from IT Infrastructure

VMware vs Proxmox in 2026: An IT Infrastructure Comparison
Post-Broadcom VMware licensing has rewritten the virtualization decision for many organizations. Here is how Proxmox VE compares for real-world workloads.

Linux Server Hardening Checklist for 2026
A practical, current hardening checklist for production Linux servers — identity, kernel, network, logging, and the controls that actually reduce risk.

SAN vs NAS vs Object Storage: Choosing Enterprise Storage in 2026
Block, file, and object storage solve different problems. Here is how to match each to the workloads that actually need it.
One email. The technology stories that actually matter for engineers.
A curated digest of the week's most useful tutorials, reviews, and analysis — no clickbait, no AI summaries of someone else's work.
Free. Unsubscribe anytime. See our privacy policy.