Life Tips

Never Lose Your Photos — The 3-2-1 Backup Rule

Never Lose Your Photos — The 3-2-1 Backup Rule

You lose your phone, your laptop won't boot, or you delete the wrong folder. The first thought is always the same: “my photos.” Hardware can be replaced with money — data that isn't backed up is simply gone.

Backing up isn't hard. But without knowing what counts as a real backup, people lose everything while believing they were protected.

1. What the standard is. The widely used 3-2-1 rule3 copies · 2 different media types · 1 kept in another location. Note though that “3-2-1” appears nowhere in the agency documents — what CISA actually requires is offline, encrypted, and regularly tested.
2. What people get wrong. Cloud “sync” is not a backup. It is a live mirror — delete a file locally and it disappears there too, and ransomware uploads the encrypted versions. It copies mistakes and attacks faithfully.
3. What to do. The last step of a backup is a restore test — that is what separates a backup from believing you had one. Do a real restore at least once.

The phrase “3-2-1” does not appear in the agency document

3-2-1 is spoken like standard vocabulary. So we went looking for what an agency actually writes.

We read the US Cybersecurity and Infrastructure Security Agency's ransomware guide through, and the expression “3-2-1” is not in it. What it does do is repeat three demands.

What CISA requiresThe wording
Offline“Maintain offline, encrypted backups of critical data”
EncryptedWritten into the same sentence
Restore testingregularly test the availability and integrity of backups in a disaster recovery scenario” / “Test backup procedures on a regular basis.
Do not put every cloud copy with one vendor“Consider using a multi-cloud solution… in case all accounts under the same vendor are impacted”

The document explains its own insistence on “offline.”
It is important that backups are maintained offline, as many ransomware variants attempt to find and subsequently delete or encrypt accessible backups to make restoration impossible unless the ransom is paid.
That is the agency basis for what section 2 of this article argues — cloud sync is not a backup. If it is connected, it goes down with you.

Bar chart of the 3-2-1 backup rule: three copies, two different media, one off-site and offline
Each number blocks a different failure — 3 for file corruption, 2 for device failure, 1 for fire, theft and ransomware. We could not find the name “3-2-1” itself in agency documents.

So this article borrows the name but puts the agency's two demands firstthe last copy must be offline, and a backup you have never restored from is not a backup. That is why section 6 exists.

1. Why 3-2-1?

RuleMeaning · what it prevents
3 copiesOriginal + two backups → one failing still leaves one
2 media typese.g. external drive + cloud → survives one type failing
1 offsiteFire, theft, flood → survives losing the whole house

Backing up to a single external drive that then dies is remarkably common. Backup media fail too.

2. Cloud sync is not a backup

Sync is a live mirror. Delete a file on your computer and it's deleted in the cloud. If ransomware encrypts your files, the encrypted versions sync upward. Sync faithfully copies your mistakes and your attackers.

AspectSync / backup
PurposeSame files everywhere / preserve past states
On deletionGone from both / backup survives
RansomwareSpreads / restore an earlier point
VersioningLimited / point-in-time recovery

Most cloud services do keep a trash and version history, typically around 30 days. Past that window recovery ends — so keep a separate backup rather than relying on sync.

Table comparing cloud sync and backup across purpose, deleting a file, ransomware and versions: sync deletes on both sides and is encrypted along with the attack, while a backup restores an earlier point
Sync is a live mirror — it copies your mistakes and the attack along with the files. A trash bin and version history last about 30 days; past that, nothing comes back.

3. Comparing methods

MethodPros / cons
Cloud storageAutomatic, offsite by default / paid above free tiers, lost account means lost access
External drive or SSDCheap, large / manual, fails or gets stolen, sits in the same building
Home NASLarge, automated / upfront cost and setup, still onsite
USB stickConvenient / poor for long-term storage, easily lost

The practical combination is cloud plus an external drive — the cloud satisfies “offsite” automatically and the drive satisfies “different medium.”

4. What to back up first

1stPhotos and videos — irreplaceable, the most-regretted loss
2ndScans of IDs and contracts
3rdWork and study files, creative projects
4thContacts, notes, calendars (usually account-synced already)
5thInstallers, media — downloadable again

The fifth row doesn't really need backing up at all. If space is tight, drop it first. “Can I get this again?” is the only test that matters.

The five backup priorities from section 4, sorted by how much they need from you. Photos and video, scans of key documents, and work or study files are yours to do. Contacts, notes and calendar are usually saved to the account already. Installers and films can simply be downloaded again
One test decides it all: can you get it again — and if space is short, cut from the bottom.

5. A 30-minute setup

1Turn on automatic photo backup on your phone
2Check cloud storage space — tidy up or review plans
3Copy photos and documents to an external drive
4Enable 2FA on the cloud account — losing it loses the backup
5Add a quarterly reminder to your calendar

Step four matters: if the cloud is your only backup and the account is compromised or lost, so is the backup.

6. Test your restore

The most-skipped step. “The backup is running” and “the backup restores” are different claims. Silent failures for months are common.

  • Once a year, actually pull a few files out and open them
  • Confirm photos display and documents aren't corrupted
  • Check that the external drive still mounts at all
  • Glance at the last successful backup date regularly

7. What to do when things break

Lost or broken phoneRestore from cloud backup on the new device
Accidental deletionCheck trash or recently deleted first (usually 30 days)
Drive failureRestore from the other medium — 3-2-1 earning its keep
RansomwareDisconnect from the network, restore an earlier version
Account compromiseChange password, enable 2FA; offline copies stay safe

Questions that remain

Isn't cloud alone enough?

Convenient, but exposed to account problems, deletions and ransomware. Keep at least one external copy.

How long do external drives last?

Years typically, but failure timing is unpredictable — which is exactly why one copy isn't enough. Migrate old drives.

My photo library is too large.

Clearing duplicates, screenshots and blurry shots usually frees a surprising amount. Beyond that, a paid plan is the realistic answer.

How often should I back up?

Photos automatically, documents weekly, a full backup quarterly.

You can't create a backup after the accident. Turn on automatic photo backup today — that single switch prevents the loss you'd regret most.

Sources

  • US Cybersecurity and Infrastructure Security AgencyRansomware Guide (checked July 2026). Source for “offline, encrypted backups,” “regularly test the availability and integrity of backups,” “Test backup procedures on a regular basis,” the reason offline matters, and the multi-cloud recommendation.
  • US Cybersecurity and Infrastructure Security AgencySecure Our World (checked July 2026). Source for the update advice and “flaws in software can give criminals access to files or accounts.”

Where to check further

  • Where the name “3-2-1” comes from. The phrase does not appear in the CISA ransomware guide — it is universally used but we could not trace it to an agency. This article borrows the name while leading with what the agency actually requires (offline, encrypted, tested).
  • How often to run a restore test. The source says only “regularly” and sets no interval, so the cadence here is our suggestion. What matters more than the interval is whether you have ever actually restored anything.
  • Guidance from your own national agency. Everything here rests on US CISA material. National cybersecurity agencies publish equivalent ransomware guidance, usually alongside local reporting procedures if you are hit.

As of July 2026. The offline, encryption and restore-testing requirements come from CISA source text; the name “3-2-1” we could not find in agency documents. For account security see passwords and MFA, and for accounts opened in your name see the identity theft check. To keep the device itself going, see phone battery life and cutting your mobile bill. The cash-side equivalent is our emergency fund article.