The 3-2-1 Backup Rule: A Practical Data-Safety Plan
The 3-2-1 rule keeps three copies of important data, on two different media or storage systems, with one copy offsite. A useful plan also isolates at least one backup from routine access, runs automatically where possible and proves recovery through test restores.
Timeline
- During planning: Choose the important data, acceptable loss interval and two independent backup destinations.
- On a schedule: Automatic jobs create new versions while an offline or otherwise protected copy remains beyond ordinary device access.
- During verification: Restore sample files and record the steps, credentials and recovery time before an emergency.
The 3-2-1 backup rule means keeping three copies of important data: the working copy and two backups, stored on two different media or storage systems, with one copy offsite. NIST describes the rule as protection against different hazards, not a demand for three identical drives on one desk. A laptop file, an external-drive backup and a properly configured cloud backup are one common personal example. [1][2]
Each number addresses a failure mode. Multiple copies help when a device dies or a file is deleted. Two different systems reduce the chance that one hardware defect, account error or software bug destroys every copy. Offsite storage protects against theft, fire, flood or another event affecting the building. Independence matters: three folders on one disk, or three devices constantly mounted to the same compromised computer, do not provide the intended separation. [1][2][3]
Ransomware adds another requirement: at least one usable backup should be offline, immutable or otherwise beyond ordinary credentials and write access. CISA warns that ransomware often searches for accessible backups and deletes or encrypts them. An external drive should be disconnected when the backup is complete, or a service should offer protected versions and deletion controls. Ordinary file synchronization can rapidly copy corruption or unwanted deletion and should not be mistaken for a complete backup plan. [2][4]
Start with what cannot be replaced: family photos, financial and tax records, creative work, password-recovery material and local application data. Decide how much recent work you can afford to lose; that determines backup frequency. A daily automatic job may suit active documents, while a less frequent archive can cover older photos. Include the files and credentials needed to rebuild, but store recovery keys securely so encryption does not lock the owner out. [1][3]
Automation reduces missed backups, but review remains necessary. Check job failures, available capacity, retention history and whether newly created folders are included. Encrypt sensitive backup media and protect cloud accounts with unique passwords and strong multifactor authentication. Keep a small recovery note that identifies the service, device, account and restore sequence without exposing passwords in plain text. Replace failing media and services that no longer receive security support. [2][4][5]
A backup is only credible after a restore test. CISA and NIST both emphasize testing availability, integrity and recovery procedures. Periodically restore a sample folder to a separate location, open several file types and confirm dates and contents. For an important computer, also know how to reinstall the operating system and applications. Testing reveals expired credentials, incomplete selections, corrupted archives and download limits while the original files still exist. [1][2][5]
A practical home plan is one local automated backup for fast recovery, one versioned offsite service for location separation, and a periodically updated drive stored disconnected and safely away. Adjust that design for cost, data sensitivity and internet speed; “two media” can mean independent storage systems rather than obsolete technologies. Revisit the plan after a new computer, phone or cloud account is added. The aim is not merely three copies, but at least one verified recovery path that the same accident cannot erase. [1][2][3][4]
Sources
- NIST NCCoE — Protecting Data from Ransomware and Other Data Loss Events
- CISA — StopRansomware Guide
- NIST SP 800-34 Rev. 1 — Contingency Planning Guide
- CISA — How to Protect Data Stored on Your Devices
- NIST CSRC — Contingency Planning