How to Back Up Your Data: The 3-2-1 Rule
By NorwegianSpark Editorial · Published July 10, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
The cheapest insurance in computing is a backup, and the most common regret is not having one. Hard drives fail, laptops get lost or stolen, and ransomware can encrypt everything you own in minutes — and in every one of those cases, a good backup turns a disaster into an inconvenience. The framework worth learning is deliberately simple and endorsed by security agencies including US CISA (2026): the 3-2-1 rule.
3-2-1 means keeping three copies of anything important — the original plus two backups — on two different types of media, with one copy kept off-site. The logic is that no single event should be able to destroy every copy at once. A fire or theft takes the local copies but not the off-site one; a ransomware infection encrypts the connected drive but not a backup that was offline or in the cloud. That last point is the one people most often skip and most need: a backup drive left permanently plugged in can be encrypted along with everything else, which is exactly why an offline or off-site copy matters.
In practice that usually means one automated local backup — an external drive or a full disk image — plus one cloud or off-site copy. Dedicated backup software makes this reliable rather than something you keep meaning to do: EaseUS Todo Backup is a well-established tool for scheduled backups, full system images and file recovery, and we cover it in detail in our EaseUS Todo Backup review. Whatever you choose, the golden rule is to test a restore occasionally — a backup you have never actually restored from is a hope, not a plan.
The Rule, and Why Each Part Is There
Three copies, on two different kinds of storage, with one off-site. Each clause defends against a different failure, which is why dropping one quietly removes a whole category of protection:
| The clause | What it defends against |
|---|---|
| Three copies | A single drive failing, which is ordinary |
| Two kinds of storage | A common fault affecting one type or one batch |
| One off-site | Fire, flood, theft — everything local at once |
Modern practice adds a fourth clause worth taking seriously: one copy offline or otherwise immutable. Ransomware encrypts what the machine can reach, and a backup drive left permanently connected is something the machine can reach.
What Sync Is Not
The most common backup failure is believing you have one. A file-sync service keeps folders identical across devices — which means it faithfully replicates a deletion and an encryption to every device you own.
Sync becomes a backup only if it has:
- Version history, long enough to reach back past when the damage happened.
- A recycle bin or retention period for deleted files.
- A restore path you have actually used.
Check the retention window specifically. If it is thirty days and you notice a corrupted file in month three, the sync service has faithfully preserved the corruption.
Deciding What to Protect
Not everything deserves the same treatment, and sorting it makes the whole thing cheaper and more likely to happen:
- Irreplaceable — photographs, documents, work you created, correspondence. All three copies, one off-site, one offline.
- Expensive to recreate — configurations, project files, licence keys. Backed up, though not necessarily off-site.
- Replaceable — installers, media you can download again, operating system files. A full disk image is convenient rather than essential.
Most people back up everything or nothing. Backing up the first category properly beats backing up all three badly.
The Restore Test
An untested backup is a belief, and the failure is always discovered at the worst moment. Twice a year:
- Restore one real file from the oldest point your retention allows, not the newest.
- Restore to a different location so you do not overwrite the original.
- Open it and confirm it is intact rather than merely present.
- Time it. Knowing that a full restore takes a day changes what you plan for.
- Check the encryption key or password is stored somewhere you could reach it if the machine were gone. A backup you cannot decrypt is not a backup.
Backups and Ransomware
This is the layer that makes an attack survivable rather than catastrophic. The specifics that matter: keep a copy the machine cannot write to, keep versions long enough to predate a slow-burning infection, and never restore onto a machine you have not cleaned first — see ransomware: what to do and the ransomware protection guide.
Backup is the layer that makes ransomware survivable, which is why it sits at the heart of our ransomware protection guide, and it belongs alongside the other essentials in our best PC utility software roundup and general PC maintenance. If you also run a website or manage domains, the same discipline applies to that data — our sister site TopDomainAgent covers the domain and hosting side. Set up automatic backups once, keep one copy off your machine, and test a restore now and then. General guidance.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Sources
Factual claims above were checked against these primary sources. Verify directly on the source for anything time-sensitive before relying on it.
Continue reading
software
The Windows Settings Worth Ten Minutes of Your Time
A default Windows install shares more than most people realise. The settings that genuinely reduce data collection, and the ones that are not worth the disruption.
vpn
Is Public Wi-Fi Safe? How to Protect Yourself
Public Wi-Fi is safer than it used to be, but not risk-free. What actually threatens you on open networks in 2026 — and the habits and tools that help.
guides
NordVPN Review 2026: Security-First VPN, Tested
An in-depth NordVPN review for 2026: who it suits, how Threat Protection blocks malware and trackers, and how it fits alongside your antivirus.