What Is Backup? Backup Types and the 3-2-1 Rule
What backup means and how it differs from a copy. Full, incremental and differential backups, the 3-2-1-1-0 rule, immutability, KVKK and restore tests.

Short answer: A backup is a copy of your data kept somewhere independent of the original system, in a form you can restore. The point is not to hold a copy but to be able to return to a known moment when something is lost. A good backup therefore meets three conditions: it is not affected by whatever breaks the original system, it includes at least one copy an attacker cannot delete, and restoring it has been tested on a regular schedule.
What does backup mean?
In IT, a backup is a copy of a file, a server or a database taken at a given moment and stored in a separate place. What separates a backup from an ordinary copy is time: a well-built backup routine lets you return to how things were yesterday, last week or last month.
Three concepts are often confused with backup:
- Snapshot: A record of a system's state at a point in time, but it lives on the same storage. If that storage is lost, the snapshot goes with it. It is handy for a quick rollback; it does not replace a backup.
- Replication: Copies data continuously to another target. It is good protection against losing a data center, but it copies deleted or encrypted data just as fast. On its own it does not protect against ransomware.
- Archive: Long-term retention of data that is no longer in active use. Its purpose is not to bring a system back but to keep the data and produce it when asked.
Types of backup
Backup software uses different names, but the methods come down to four basic types:
- Full backup: All selected data is copied every time. It is the simplest to restore, but it takes the longest and uses the most space.
- Incremental backup: Only the data changed since the previous backup is copied. It is the fastest method and uses the least space; a restore needs the last full backup plus every incremental after it.
- Differential backup: Everything changed since the last full backup is copied. It grows over time; a restore needs only the full backup and the latest differential.
- Synthetic full backup: The backup server merges the last full backup with the incrementals to produce a new full backup. Because it does not read from production systems again, it puts no extra load on them.
There is another distinction as important as the method: the level at which the backup is taken. A file-level backup protects individual files; an image-level backup brings back a whole virtual machine or server. Databases need application-consistent backups. Otherwise a copy taken in the middle of a write may refuse to open when it is restored.
The 3-2-1 rule and 3-2-1-1-0
The best-known yardstick for a backup strategy is the 3-2-1 rule:
- 3 copies: the original data and at least two backups,
- 2 different media: for example disk and tape, or local storage and cloud,
- 1 copy in another location.
The rule emerged to keep all copies from being caught by the same failure in the same place. Today the main threat is not failure but an attacker. That is why Veeam extended it to 3-2-1-1-0: one of the copies must be immutable or air-gapped, and restores must show zero errors. The zero comes from automated integrity checks and regular restore testing.
The numbers explain the extension. In Sophos's 2024 research, 94% of organizations hit by ransomware said the attackers also tried to compromise their backups, and 57% of those attempts succeeded. Where backups were compromised, the median recovery cost was 3 million dollars, against 375 thousand dollars where they were not: an eightfold difference. For the same reason, CISA's ransomware guide asks for offline, encrypted backups and regular testing of their availability and integrity.
A properly built backup is still the strongest defense. According to Sophos's 2026 report, 66% of organizations whose data was encrypted recovered it from backups, up 12 points in a year.
What is an immutable backup?
An immutable backup is one that nobody, not even an administrator account, can change or delete until a set period expires. It is built with object lock on object storage, or on local storage with designs that hand protection to the operating system kernel, such as Veeam's hardened repository. We covered the setup in How Veeam works.
The critical setting is the immutability period. Attackers wait in the environment for days before they start encrypting. If the period is shorter than that wait, the clean copies taken before the attack began fall outside the protection. We worked through how to choose the period, with the numbers, in our ransomware recovery playbook.
How often should you back up?
The answer is not on a calendar but in two targets: RPO and RTO.
- RPO (Recovery Point Objective): How much data loss you can accept. If the RPO is 24 hours, a daily backup is enough; if it is measured in minutes, you need frequent backups or replication.
- RTO (Recovery Time Objective): How long the system can stay down. The RTO decides where the backup is restored from and by what method.
Not every system needs the same target. The method for setting targets by business impact is in How to calculate RPO and RTO.
What does KVKK expect from backups?
Backups that contain personal data are personal data too, and the data security obligation applies to them as well. The Personal Data Security Guide from Türkiye's Personal Data Protection Authority (KVKK) recommends developing a backup strategy against ransomware and lists three concrete expectations: only the system administrator should be able to access backups, dataset backups must be kept off the network, and the physical security of backups must be ensured.
Two points are often missed. First, keeping backups in a cloud outside Türkiye raises the question of cross-border transfer; the details are in KVKK and cross-border data transfer. Second, the KVKK Board can fine the company that was attacked in a ransomware case; we examined one example in Why a ransomware victim was fined by KVKK.
Restore testing: the only proof a backup works
A "backup successful" report does not prove the backup will restore. In Veeam's 2025 research, only 10% of attacked organizations recovered more than 90% of their data. Almost all of them had backups.
A test does not end with a green check in the backup software:
- Restore randomly chosen files and check that they open.
- Bring a critical server or virtual machine up as a whole on an isolated network.
- Confirm the application actually works: does the database open, can a user log in?
- Measure the time it took and compare it with the RTO.
- Write the result down: what came back, when, and in how many minutes.
How to run a full recovery exercise is covered in our disaster recovery test guide.
An enterprise backup checklist
- Is it written down which system is protected with which RPO?
- Is at least one copy outside the production identity system (for example, Active Directory)?
- Is the immutability period longer than an attacker can wait in the environment?
- Is data in SaaS applications (email, file sharing, CRM) within backup scope?
- When was the last restore test, and how many minutes did it take?
- Who looks at a failed-backup alert outside business hours?
Frequently asked questions
What does backup mean? A copy of data kept in a separate place so you can return to it if the original is lost.
Is backup the same as archiving? No. A backup exists to bring a system back to a given moment and is refreshed regularly. An archive keeps data that is no longer in use for a long time.
Does a snapshot replace a backup? No. A snapshot lives on the same storage; if the storage is lost, so is the snapshot.
Is cloud backup safe? The cloud is a good option for the off-site copy in the 3-2-1 rule. Its safety comes from immutability, encryption and keeping backup access accounts separate from production accounts. If personal data is involved, you should also ask which country the data sits in.
How often should you back up? As often as the data loss you can accept (your RPO) requires. A daily backup is for systems where losing a day of data is acceptable.
Sources
- Sophos, The Impact of Compromised Backups on Ransomware Outcomes: share of attacks targeting backups and the cost difference (2024)
- Sophos, The State of Ransomware 2026: recovery from backups
- CISA, #StopRansomware Guide: the recommendation for offline, encrypted, tested backups
- Veeam, 3-2-1 Backup Rule: definitions of 3-2-1 and 3-2-1-1-0
- KVKK, Personal Data Security Guide: expectations for backups of personal data (in Turkish)
- How we build this layer: backup, replication and recovery