Cybersecurity-based backup. Recovery you can prove.
Cyber Resilience · Backup & Recovery
Cyberattacks are a daily, global reality — and modern ransomware targets your backups first. QNAP’s 3-2-1-1-0 architecture is engineered as a security control, so when prevention fails, recovery is a certainty, not a hope. Our goal: zero data loss, total recovery confidence.
Immutable / air-gapped
One copy is unreachable to attackers — locked by WORM, Object Lock, or physically air-gapped.
Tap each number to learn what it defends against.
Attackers destroy the backup first
Ransomware is now a leading cause of business disruption — a daily, global event. Modern campaigns no longer just encrypt production data; they hunt down backup repositories, destroy them, then start the ransom clock. A backup that cannot defend itself is no backup at all.
The stakes are existential. A single breach can trigger regulatory penalties and expose the personal data of customers and employees — and when the backups are destroyed too, businesses have been forced to close for good. Cyber insurers now require provable, isolated, recoverable backups as a condition of coverage. Resilient backup is no longer an IT line item; it is a condition of staying in business.
of organizations attacked had their backup repositories targeted by ransomware actors.
Attackers know the backup is the only thing standing between them and a paid ransom. Destroying it is now part of the playbook.
Veeam 2025 Ransomware Trends Report
of victims recover more than 90% of their data.
More than half recover less than half of what they lost. Recovery outcome — not backup count — is what decides whether the business survives.
Veeam 2025 Ransomware Trends Report
is the average cost of a data breach.
And that is the average. For mid-market firms without working recovery, the outcome is often operational shutdown — sometimes permanent.
IBM Cost of a Data Breach Report 2025
Network Breach → Lateral Movement → Encryption
Japanese beverage & food group (Asahi Group)
After network devices were breached in 2025, attackers moved laterally and detonated ransomware — halting automated ordering and shipping and exposing roughly 1.9 million personal records.
Source: Asahi Group public investigation report, 2025-11
Encrypted → Unrecoverable → Bankruptcy
German mobile-device insurer unable to restore
Production and backup data were both encrypted. Without a recoverable copy the business filed for bankruptcy — the ultimate cost of “no trusted backup”.
Source: industry incident reporting, 2023
The classic rule, hardened for the ransomware era
Peter Krogh proposed the 3-2-1 rule in 2005 — when the threat was a failed disk or a physical disaster. Ransomware changed the threat model, so the industry added two security controls: +1 a copy attackers cannot reach, and +0 proof that every copy is recoverable.
| Rule | Requirement | Defends against | In 3-2-1? |
|---|---|---|---|
| 3 |
Three copies of dataProduction data plus at least two independent backups. |
Single-point failure of a drive, file, or backup job. |
Yes — original rule |
| 2 |
Two different mediae.g. NAS + cloud, or NAS + tape — avoid same-class faults. |
Whole-batch drive failures, file-system corruption. |
Yes — original rule |
| 1 |
One copy off-siteGeographically separated from production. |
Fire, flood, theft, regional outage. |
Yes — original rule |
| +1 |
One copy immutable or air-gapped NEWLocked by WORM / Object Lock, or physically isolated. |
Ransomware that attacks the backup itself. Once an attacker gains administrator access, every “online” copy can fall together. |
Missing |
| +0 |
Zero recovery errors NEWEvery backup is automatically tested for restorability. |
The false comfort of “backup succeeded” messages. Most failed restores are discovered during the disaster, not before. |
Missing |
3-2-1-1-0 doesn’t replace 3-2-1 — it extends it. The first three remain your baseline. The last two are the difference between “we have backups” and “we can recover after an attack”.
One NAS, every workload
Back up into the NAS
-
PCs · servers · VMs Windows · VMware · Hyper-V
HDP for PC/VM Agentless · full image
-
SaaS apps Microsoft 365 · Google
HDP for SaaS Mail · Drive · Teams
-
File servers SMB · Rsync shares
HDP for Business File server backup
HDP for Business · All-in-one suite · Coming Soon Covers PC/VM · SaaS · file servers · databases -
Databases SQL Server · Oracle
HDP for Business Database backup
-
Websites WordPress
HDP for WordPress Core · DB · media
-
Macs macOS · Time Machine
HBS 3 Mac Time Machine target
-
Mail & calendar IMAP · CalDAV
QmailAgent · QcalAgent Mailboxes · calendars
-
Mobile devices iOS · Android
Qfile Pro File backup · sync
Copies & sync out
-
Snapshot Replica Snapshot copy
Another QNAP NAS NAS-to-NAS · cross-site -
HBS 3 RTRR · Rsync · encrypt · Airgap+
Another QNAP NAS NAS-to-NAS · cross-siteAir-gapped NAS Airgap+ · via Switch / RouterCloud & object storage Public cloud · myQNAPcloud One -
VJBOD Cloud Block-level cloud gateway
Cloud & object storage Public cloud · myQNAPcloud One -
Qsync File backup + 2-way sync
PCs · Macs · devices Windows · macOS · Linux -
SnapSync Real-time ZFS mirror
QuTS hero NAS Real-time mirror · RPO 0 -
HybridMount Mount cloud into NAS
Cloud / remote File-level gateway
Built for one job each — except one, built for them all
Each backup product is purpose-built for one layer. HDP for Business (coming soon) is the only one that natively covers all five — which is exactly what the enterprise integration value proposition delivers.
| Product | 3 Copies | 2 Media | 1 Off-site | +1 Immutable | +0 Verified |
|---|---|---|---|---|---|
|
Qsync
File sync + endpoint single-target backup
|
|||||
|
HDP for PC/VM
PC, Server & VM bare-metal backup
|
|||||
|
HDP for SaaS
M365 + Google Workspace SaaS backup
|
|||||
|
HDP for WordPress
Full-site WordPress backup
|
|||||
|
Hybrid Backup Sync
NAS ↔ NAS / Cloud + Airgap+
|
|||||
|
Snapshot Manager
Snapshot Replica · SnapSync · Immutable
|
|||||
|
HDP for Business (Coming Soon)
FLAGSHIP
Enterprise integrated data-protection platform
|
- Native support
- Possible via manual chaining
- Not the product’s role
One product. Five rules.
Today, QNAP covers all five rules of 3-2-1-1-0 with shipping products — HBS 3, QuTS hero WORM, QuObjects, Immutable Snapshot, and Airgap+. HDP for Business (Coming Soon) will bring them together under one control plane, so the entire 3-2-1-1-0 policy is managed, verified, and recovered from a single console. The five cards below show how each rule maps to a feature.
HDP for Business Every Workload
Every workload that lands is the first of your three copies.
VMware, Hyper-V and Proxmox plug in agentless. So do Windows / Server, MS SQL, Oracle, and any file source — one backup pipeline into the HDP for Business Backup Server. Plus the primary backup itself and the offsite copy that follows: three copies stand up.
HDP for Business Backup Copy (media handoff)
NAS + remote storage — two media, by design.
The primary backup sits on the HDP for Business Backup Server (block / file). Backup Copy mirrors the same backup out to a remote object store. Same data, two different storage types — the “2 media” rule is a by-product of the architecture, not a separate setting.
HDP for Business Backup Copy
One backup, many homes. Scheduled, encrypted, throttled.
A single Backup Copy chain writes simultaneously to QuObjects on-prem S3, myQNAPcloud Object, AWS S3, Wasabi, or any S3-compatible target (Cloudflare R2, Backblaze B2, MinIO, …). Multi-destination, encrypted in flight, bandwidth-throttled, scheduled — all in one console.
HDP for Business Airgap+ · Object Lock
Two walls — locked on arrival, off-net by schedule.
First wall: Backup Copy writes to Object Lock-enabled S3 destinations — with an Immutable protection policy, every object carries a retention period that administrators cannot bypass. Second wall: Airgap+ powers the Backup Server off on a schedule outside the backup window — even if ransomware reaches the attack surface, it can’t touch that machine.
HDP for Business Backup Verification · Instant Restore
Not “the backup is readable” — boot it as a VM, right now.
Backup Verification spins each backup up in a sandbox VM, waits for boot-complete, records the run on video, and writes an Activity Log — audit-ready evidence. When the real disaster hits, Instant Restore boots the backup directly as a VM (p2v and v2v, cross-hypervisor: VMware / Hyper-V / Proxmox → QVS). No copy-back, no waiting for storage to repopulate.
Three layers that hold your backup up
The matrix in the previous section scores products that produce backup copies. These three layers give those copies a trusted home, a cloud on-ramp, and a service that doesn’t go down.
Immutable Storage Targets
The certified landing zones.
These are the storage layers behind 3-2-1-1-0. Both are first-party QNAP — meaning one support relationship, one set of compliance certifications, and a guaranteed integration path for Veeam customers.
Hybrid Cloud Gateways
Bridge to cloud, two layers.
Mount cloud or third-party storage as if it were a local NAS volume. They don’t produce backups themselves — they give the destinations above a fast on-ramp.
High Availability
Keep the backup service up.
When the primary backup NAS fails, HA lets a passive node take over so backups never stop. It complements 3-2-1-1-0 — it does not substitute for it.
Engineered as security controls, not just storage
Every layer of a QNAP backup is a deliberate defense. This section zooms into the stack underneath: four security mechanisms at four different layers, each with its own use case. Airgap+ has two implementations at the same layer — scheduled power cycle (HDP for Business) and network-port isolation (HBS).
-
Immutable Snapshot
ZFS-based retention lock on volume or LUN snapshots. Self-protecting against ransomware on the same NAS, but local-only — the immutability attribute does not travel across Snapshot Replica.
-
Immutable Backup (WORM)
HBS 3 writes backups to a WORM Shared Folder on QuTS hero. Choose Enterprise mode (admin can release) or Compliance mode (nothing short of destroying the pool can remove it).
-
Object Lock
S3 retention applied per object. QuObjects gives you S3 + Object Lock on-prem (Veeam Ready certified); for cloud you can target myQNAPcloud One or Amazon S3.
-
Airgap+
Outside the backup window, the backup NAS is unreachable — either by switching off its NIC port via a QHora router / QSW switch, or by powering the unit off entirely (HDP for Business scheduled cycle — coming soon).
Frequently asked questions
Backup, ransomware, and cyber resilience
Yes. QNAP backup is engineered as a cybersecurity control. The 3-2-1-1-0 architecture keeps at least one copy immutable or air-gapped, so even an attacker with administrator rights cannot alter or delete it, and backup verification proves every copy is recoverable.
An immutable backup cannot be changed or deleted for a set retention period. QNAP supports it three ways: Immutable Snapshot (ZFS retention lock), Immutable Backup (WORM on QuTS hero), and Object Lock (QuObjects, Veeam Ready certified).
An air-gapped backup is disconnected from the network so online attackers cannot reach it. QNAP Airgap+ automates this by switching off the backup NAS network port (via a QHora router or QSW switch) or powering the unit down outside the backup window.
Three copies of data, on two media types, with one off-site, one immutable or air-gapped, and zero recovery errors — every backup verified.
Yes. Backup verification confirms a copy restores correctly before you need it — the zero (zero recovery errors) in 3-2-1-1-0.