
For decades, the 3-2-1 backup rule has been the mainstay of data protection: keep three copies of your data, on two different types of media, with one copy stored offsite. It was a sound framework for a world where the primary threats were hardware failure, natural disaster, and human error.
That world is gone. Well, sort of. People and organizations still follow the rule. I see it all the time. But the punch it packed, the protection the formula once provided, is gone.
Modern ransomware doesn’t just encrypt production data. It hunts backups first because attackers know that a company with no way to restore its data is far more likely to pay a ransom. The 3-2-1 rule tells you how many copies to keep. It offers no guidance on whether those copies can survive a determined attacker who has already compromised your network.
Kirill Meshyk, Head of AI Data Collection at Unidata, tells SmarterMSP.com that following the 3-2-1 rule simply means you have three copies of your data. “Following a ransomware policy means you pick a target. If all the copies of your data are reachable and writable from the same network, then a ransomware attacker will access all copies of your data.”
The math is self-evident and sobering: three copies that are all network-accessible are not three layers of protection. They are three targets.
Backups are now a primary target
Andy Maus, Head of Cyber Recovery Services at DriveSavers Data Recovery, tells SmarterMSP.com that he sees the consequences of this reality every day. “Backups have been deleted in most of the ransomware data recovery jobs DriveSavers has taken thus far in 2026,” he says.
The pattern is consistent, and the mechanisms are specific.
In one common scenario, attackers obtain administrative credentials and compromise backup management software, allowing them to remove backups regardless of immutability settings. “Once that management layer is compromised,” Maus explains, “backups are deleted or encrypted at the host level.”
In another recurring pattern, backup administrator turnover leaves behind orphaned retention policies. The person who originally configured the system leaves the company, and their replacement inherits a setup that nobody re-tests. The gap often goes undiscovered until an incident exposes it.
Perhaps most ominous is what Maus reports about clients who paid the ransom. “Clients who paid the ransom demand still needed a data recovery service because the decryptor supplied did not work, or it corrupted the file while attempting to decrypt.”
Paying, in other words, is not a recovery strategy. It’s a gamble with no guaranteed payout.
Why immutability and air-gapped storage matter
Meshyk learned the inadequacy of writable backups firsthand while building data protection infrastructure. “I had to learn this the hard way,” he says, “by building data protection infrastructure with the assumption that it would survive a data breach.”
His solution was architectural: one copy of data should be air-gapped and offline, while another should be immutable and unchangeable for a defined retention period. “Even admins can’t delete this copy,” he says, “which means attackers can’t rely on their usual tricks and tactics.”
That last point is critical. Immutability that an administrator can override isn’t true immutability. It’s simply a setting.
Maus reinforces this directly, recommending that MSPs penetration test immutability controls just as they would any other security measure. He also advises asking vendors a specific question: Can an administrator with full privileges override the immutability setting on the platform? “In these cases,” he says of incidents DriveSavers has handled, “immutability was configured and believed to be fail-proof.”
Believed, but not verified.
For MSPs with concerns about cost when discussing immutable storage with budget-conscious SMB clients, Meshyk says the concern is often overstated. “The fear of increased costs with immutable storage is unwarranted at the SMB scale.”
Maus notes that storage costs are often only a few cents per gigabyte per month. As a result, a small business with a few terabytes of data may only spend a few dozen dollars each month for an immutable storage tier and the one-time cost associated with offline media rotation.
Compared to a ransomware demand, which Meshyk notes often “runs in the six-digit range with a business disruption of more than two weeks,” the additional expense is negligible.
Recovery is only as good as your last test
The question of what effective recovery looks like is one Meshyk addresses with equal clarity. “When recovery from a cyber intrusion is clean, a business is able to verify the integrity of the storage and spin business operations from an immutable storage point ahead of the cyberattack. This results in just a few hours of business operations being lost.”
The failure scenario, however, is all too familiar. “When the recovery is not clean, the silence of an untested recovery or the writable storage is discovered, and the production storage is left encrypted.”
Meshyk emphasizes that simply having a backup solution does not guarantee a successful recovery. “Recovering cleanly is the result of routine tests of the recovery process.”
Maus adds one practical step that MSPs consistently overlook: adding a data recovery provider to the incident response plan before an incident occurs. Cyber insurers, he notes, are increasingly asking whether data is recoverable before negotiating a ransom payment. Having a pre-established relationship with a data recovery provider can accelerate recovery efforts when time matters most.
Solutions like Barracuda Backup include immutable cloud storage and offsite replication. This gives MSPs a straightforward path to delivering the air-gapped, tamper-resistant architecture experts recommend without forcing clients to piece together multiple tools on their own.
Photo: one photo / Shutterstock
This post originally appeared on Smarter MSP.

