Skip to main content
AD Academy
Cloud Computing: Architecture and Security
Beginner12 minLast updated: Topic 7 of 8

Storage, Backup, and Disaster Recovery (BCDR)

Redundancy levels, RPO/RTO, and the 3-2-1 rule in the cloud world.

Not read

What you will learn here

  • Storage Redundancy Levels
  • Recovery Metrics
  • Storage Tiers

Worth reading first:Cloud Security Controls: Zero Trust, MFA, and Conditional Access

In the cloud, it's easy to think that 'everything is automatically backed up.' This is not true: Redundancy protects against hardware failure, but not against accidental deletion, bugs, or Ransomware. For that, a separate Backup is needed.

Storage Redundancy Levels

  • LRS — Three copies within one Datacenter; cheap, does not survive a site failure.
  • ZRS — Copies between Availability Zones in the same region.
  • GRS — Replication to another geographical region (hundreds of km), for protection against regional disaster.
  • RA-GRS — Like GRS, with read access to the secondary copy.

Three redundancy tiers on top: LRS keeps three copies in one datacenter and survives a disk failure; ZRS spreads copies across availability zones and survives one datacenter outage; GRS replicates to another region hundreds of kilometres away for regional disasters. The red bar reminds you that redundancy is not backup — deletion, bugs and ransomware replicate too. Then two metrics: RPO is how much data you may lose, RTO is how long recovery may take. At the bottom the 3-2-1 rule: three copies, two media types, one offsite, plus immutability or soft delete.

Short and clear

  • Redundancy only covers hardware failure: LRS inside one datacenter, ZRS across zones, GRS across regions.
  • Redundancy is not backup — deletion, bugs and ransomware replicate into every copy.
  • RPO is how much data you may lose; RTO is how long recovery may take.
  • What actually saves you is the 3-2-1 rule plus immutability or soft delete.

Real-life exampleAfter ransomware, GRS simply replicated the encrypted files; the save was a vault with 14-day soft delete — restored in 6 hours (RTO) losing one hour of data (RPO).

Recovery Metrics

  • RPO (Recovery Point Objective) — How much data is allowed to be lost (e.g., 15 minutes).
  • RTO (Recovery Time Objective) — How long is downtime allowed (e.g., 4 hours).
  • 3-2-1 Rule: Three copies, two media types, one off-site copy — preferably Immutable.

Storage Tiers

  • Hot — Frequent access, high storage cost, low access cost.
  • Cool / Cold — Data accessed once a month-quarter.
  • Archive — Very cheap archive, but recovery takes hours (Rehydration).

Check yourself

What does an RPO of 15 minutes mean?

What does GRS redundancy not protect against?

Was this page helpful?