
Backup 3-2-1-1-0: backups must be paired with restore tests
Understand each part of 3-2-1-1-0 and test whether backups are usable when the primary system fails.
Tùng TEKVerifiedPrepare with testable controls, practical knowledge and regular exercises.

Understand each part of 3-2-1-1-0 and test whether backups are usable when the primary system fails.
Tùng TEKVerifiedNo.Ransomware.VN is the initiative's education and prevention branch. Adapt these checklists to each organization's assets, staffing and operational capabilities.
No Ransomware initiativeKeep multiple copies of data with appropriate separation. Test recovery regularly and record unresolved errors.
Reduce unnecessary functions and manage changes by asset.
Control remote access according to business needs.
Protect both the data and the device management interfaces.
Treat the hypervisor as a critical system component.
Apply MFA together with account lifecycle management.
Prepare roles, communication channels and decision-recording procedures.
Turn requirements into tasks with an owner and evidence of completion.
Practice decisions before handling a real incident.
Help people recognize reportable warning signs and know whom to contact.
Enable MFA, patch internet-facing systems, restrict RDP/VPN and control privileged accounts.
Segment networks, separate backup accounts and apply least privilege.
Apply 3-2-1-1-0, use offline or immutable copies and test restores regularly.
Understanding ransomware
No Ransomware knowledge for SMEs: encryption, data theft, decryptors, RAID and backups. Read indicators in context and avoid evidence-destroying reactions.
No.Ransomware.VNGuidance document
No Ransomware checklist: control connections, preserve evidence, assess backups and RFC for SQL, NAS, RAID, ESXi and Hyper-V before recovery.
No.Ransomware.VNGuidance documentEach source's scope and date are recorded separately when available. A citation does not independently verify every assessment.