Why Now Daily.

Published

The 3-2-1 Backup Rule for Photos, Documents and Devices

The 3-2-1 rule keeps three copies of important data on two media types with one copy offsite; a usable plan also protects credentials, isolates a copy and tests restoration.

Timeline

  1. Initial setup: Identify irreplaceable data and create local and offsite backups.
  2. On a schedule: Run or verify automatic backups and review failures or storage limits.
  3. Periodically: Restore sample files and confirm recovery credentials are available.

The 3-2-1 rule is a design for avoiding one point of failure: keep three copies of important data, including the working copy; store them on two different kinds of media or systems; and keep one copy offsite. For a household, that might be files on a computer, an external drive backup and a protected cloud backup. The exact products matter less than independent failure paths. [1]

A synchronization service is useful but is not automatically a complete backup. If deletion, corruption or ransomware changes a synchronized file, the change may propagate to other devices. Version history and deleted-file retention can help, but limits differ by service and plan. Treat cloud sync as one layer only after confirming how long prior versions remain and how account recovery works. [2][3]

Local backups can restore large amounts of data quickly and may work without internet access. Use an external drive sized for multiple versions, enable the operating system's backup tool and store the drive safely. CISA advises disconnecting an external drive when it is not actively backing up because ransomware that can reach the drive may delete or encrypt the backup as well. [2]

An offsite copy protects against theft, fire, flood and other events that could destroy the device and a nearby drive together. A vetted cloud backup can fill that role, or a securely stored drive can be rotated to another location. Encrypt sensitive backups, secure the cloud account with a unique password and multifactor authentication, and preserve recovery codes somewhere separate from the protected device. [1][2]

Choose what to protect before choosing capacity. Prioritize original photos and videos, financial and legal records, creative work, device configuration and anything that cannot be downloaded again. Record where contacts, messages and application data live because some services back up only selected folders. Keep an inventory and note any encryption key or special software needed for restoration. [2][4]

A backup is only proven when it restores. On a regular schedule, recover a few files to a temporary location, open them and confirm dates and contents. Occasionally test the documented process for a larger restore without overwriting the originals. NIST recommends planning, implementing and testing restoration while keeping important backups secure and isolated from ransomware. [3][4]

Start small: protect the most valuable folder today, automate both local and offsite copies, and enable failure notifications. Then test one restore and write down the steps. Review the plan after a new phone, computer, account or major storage change. Three copies do not help if all share one password, remain continuously writable from one infected device, or cannot be decrypted when recovery is needed. [1][2][3]

Sources

  1. CISA/US-CERT — Data Backup Options
  2. CISA — How to Protect Data Stored on Your Devices
  3. NIST — Tips and Tactics for Dealing With Ransomware
  4. NIST — Protecting Data From Ransomware and Other Data Loss Events

Related stories