The 3-2-1-1-0 rule, audited honestly
The rule is taught everywhere: three copies of your data, on two different media, one offsite, one immutable, zero errors on verification. Good rule. The trouble is that most organizations grade themselves on the first three digits, which are easy, and wave at the last two, which are the ones that decide whether you restart.
The first three digits are logistics
Three copies, two media, one offsite. Procurement solves these. Any competent IT operation passes, and passing tells an attacker nothing about whether you will pay.
The "1" is where the audit gets uncomfortable
One immutable copy. Ask what enforces the immutability. In most estates the answer is a software setting: object lock on a cloud bucket, a retention policy on an appliance, reachable over the network and governed by credentials. Crews harvest those credentials before striking, and reporting across the industry puts attempts to compromise the recovery estate in the mid-nineties of percent of attacks. An immutable copy the attacker can reach is a claim, not a copy. The honest reading of the "1": immutability must be physics, and the copy must sit beyond every path and every credential the attacker can hold.
The "0" is where plans quietly become hopes
Zero errors, verified. Verified means a restore was actually run, recently, by the people who would run it under pressure, and the result checked clean. Not a checksum job. A rehearsal. Ask when yours last happened; the silence is the finding.
The five-question audit
The Restart Copy Test compresses this into five questions an auditor, an underwriter, or a board member can ask without technical training: path, credentials, physics, people, rehearsal. Five yes answers and your last two digits are real.