Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7
Prevention

Backup 3-2-1-1-0: backups must be paired with restore tests

Understand each part of 3-2-1-1-0 and test whether backups are usable when the primary system fails.

Updated: · Vietnam time (UTC+7)

Illustration of backups on separate devices, including offline storage.
AI-generated illustration • Not evidentiary imagery of an incident.
Verified

The rule's meaning was checked against Veeam documentation. Review questions are editorial suggestions, not a security certification.

Original title (English translation): Backup 3-2-1-1-0

Source: No.Ransomware.VN · Original date: (the source records only the date)

Original URL: https://no.ransomware.vn/backup-3-2-1-1-0/

The original is retained for comparison. The update history below records changes to sources, scope and assessments.

  • 3: at least three data copies, including the working copy.
  • 2: store on two different types of storage media.
  • 1: keep one copy at another location.
  • 1: keep an appropriate offline, isolated or immutable copy.
  • 0: no unresolved errors in integrity and restoration checks.

CISA recommends maintaining offline, encrypted backups and testing them regularly. In actual operations, a successful backup status is only part of the assessment.

Teams need to know which copy contains the required data, who can access it, where encryption keys are managed and whether the application runs after restoration.

  • Select a critical system and identify the required recovery point.
  • Record versions, application dependencies, accounts and required permissions.
  • Restore in an isolated environment under an approved procedure.
  • Open and check the data in the actual application; add appropriate consistency checks for SQL.
  • Measure completion time, missing data and manual steps.
  • Record errors, remediation owners and the next test date.
Technical assessment

Separating backup administrator accounts from everyday accounts reduces the chance that one compromised account can affect every copy. Test immutability against actual permissions and retention periods, not just interface labels.

The goal is to know the operational level an organization can restore and how long it takes. Backup rules guide design; recovery capability must be demonstrated through tests.

Technical assessment

Copying individual live MDF/LDF files does not replace a consistent SQL backup. Preserve appropriate full/differential/log chains, keys and dependencies; exercise restores and consistency checks on restored databases.

RAID tolerates some hardware failures but is not backup against encryption or accidental deletion. NAS snapshots sharing administrator privileges can be deleted together. Independent copies, separate permissions and retention tests with actual privileges are needed.

For ESXi/Hyper-V, verify application consistency and entire virtual-disk/snapshot/checkpoint chains. VM snapshots do not replace independent copies. Test boot, services and data in isolation.

RPO expresses time-based tolerable data loss; RTO is the target time to resume operations. Measure infrastructure preparation, key retrieval, restoration and application checks, not only copying.

Retention should cover business needs and environment-specific detection delays. Immutability matters only when compromised accounts cannot shorten retention or delete protected copies; keep keys and recovery privileges separate.

Explain each layer

3

One working copy and at least two independent copies. Snapshots on the same storage are not independent if they share administrator access.

2

Combine platforms/media with separate failure domains, such as local storage and object storage. Avoid shared firmware, accounts and failure points.

1

Locate it outside the primary site or production blast radius to protect against fire, theft, sabotage and widespread infrastructure failure.

1

A copy that operational accounts cannot alter/delete. Prefer Object Lock/WORM, a real air gap or devices connected only during backup windows.

0

A successful job is insufficient. Verify checksums, logs, readability and actual restores; leave no unresolved errors.

In-depth design

Separate administrator privileges

Use separate backup accounts, MFA and secret storage. Domain Admin or production NAS accounts must not be able to delete immutable copies.

Lock retention periods

Set retention long enough to cover ransomware dwell time. Control policy changes and alert on attempts to shorten retention.

Recover in a clean environment

Test restores in isolation, scan for malware, compare checksums and test applications. Return only clean data to production.

Recovery tests

“Backup Successful” confirms task execution, not recoverability. Each test should record RPO, RTO, data scope, checksums, application dependencies, encryption keys, accounts and time to restore service.

  • Review logs and address every warning, not only red errors.
  • Restore samples weekly; exercise complete-system recovery quarterly or according to criticality.
  • Randomly test both recent files and older retained versions.
  • Record the owner, results, timing and corrective actions.
PreventionBackup
Veeam — Protect: the 3-2-1-1-0 backup ruleThe vendor's backup design guidance.
CISA — #StopRansomware GuideGuidance on prevention, response and recovery.
No.Ransomware.VN — Original Backup 3-2-1-1-012/09/2026 · The original date is retained in source code. The consolidated article preserves immutability, retention, administrator permissions and recovery tests.

Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.

· Consolidated No.Ransomware.VN technical material (original date 12/09/2026), adding SQL MDF/LDF, NAS/RAID, VMs, retention and RPO/RTO. Retained the Ransomware.VN URL and publication date.

· Initial publication with sources and verification limits.

Corrections policy
T
Tùng TEK

TUNGTEK · IT and data recovery. Focused on technical evidence, data integrity and the ability to resume operations.