
Summary
If you’ve ever looked into how to properly back up your important files, chances are someone pointed you to the 3-2-1 backup rule. Keep three copies of your data, store them on two different media types, and keep one copy offsite. It’s simple, easy to remember, and just about every backup guide on the internet recommends it. I followed this rule for years, and I was confident my files were safe. However, when I needed to restore a backup, I discovered that the files I’d been dutifully copying for months were corrupted. The backup existed, sure, but it was useless. The 3-2-1 rule has a gap that probably doesn’t get the kind of attention it should. The rule tells you how many copies to make and where to put them, but it says nothing about checking whether those copies work. A backup is only as good as its restore process, and without regular testing and verification, you’re just hoping for the best. 3-2-1 only counts copies The most popular backup rule focuses on quantity, not quality The 3-2-1 rule has been around for a long time. Photographer Peter Krogh first popularized it in his 2009 book on digital asset management. He created it to protect his own photo archives, and the logic was that three total copies of your data (the original plus two backups), stored across two different types of media (say, an external hard drive and a cloud service), with at least one copy kept offsite, is enough to protect against fire, flood, or theft. The logic itself is not bad. If your laptop dies, you have an external drive. If your house floods and takes both the laptop and the drive, you still have an offsite copy in the cloud. Each layer covers a different kind of failure, which is why the rule has survived for over a decade and still gets recommended everywhere. However, it only counts copies. It assumes that if you have your data in three places on two media types with one offsite, you’re covered. What it doesn’t address is whether any of those copies can be restored to a working state. You could follow 3-2-1 to the letter and still be in trouble if your backup files are corrupted, incomplete, or stored in a format you can no longer read. When a backup is not a backup If you’ve never tested a restore, you don’t have a backup plan The missing step that can turn 3-2-1 from a good habit into a complete strategy is verification and testing. If you’re not regularly checking whether your backups can be restored, you have files sitting on a drive somewhere, but not necessarily a backup plan. When backup software reports a successful job, all it confirms is that data was copied without an error the software noticed. What it doesn’t confirm is that the data can be read back, that it’s complete, or that it will turn into a working system when you need it. Files get corrupted during transfers and storage media degrades over time. Incremental backup chains break so that later backups depend on pieces that no longer exist. None of this shows up until you try to restore something. Backblaze’s 2024 Backup Awareness Survey, conducted by The Harris Poll with over 2,000 US adults, found that 84% of computer owners say they’ve backed up their data, yet fewer than 1 in 5 (15%) feel absolutely certain their most important files are securely backed up. That’s a massive confidence gap, and it tells you that most people know they should back up, and many do, but very few have tested whether their backups work. A simple fix involves picking a random file or folder from your backup and restore it. Open the files, confirm they’re intact, and make sure your backup tool can find and retrieve them without errors. And that should close the biggest hole in the 3-2-1 rule. One copy should stay unreachable Modern threats mean at least one backup needs to be untouchable If all your copies are reachable from the same network with the same login credentials, a single ransomware attack can wipe out everything, including the original data and every backup. So, we now have an updated rule: 3-2-1-1-0. The two new numbers address the threats that the original rule missed. The extra “1” means keeping at least one immutable or air-gapped copy. Immutable means the data can’t be changed or deleted for a set period, not even by an admin. Air-gapped, on the other hand, means the backup is physically disconnected from the network, like a drive you unplug after each backup or a tape you store offsite. Either way, the goal is the same: one copy that ransomware or a compromised account can’t touch. Tools like FreeFileSync can create an exact mirror of your files on a disconnectable drive, which you can then unplug and store separately. The “0” stands for zero errors, verified. This is where the testing step gets baked into the rule itself. Instead of treating verification as optional, 3-2-1-1-0 makes it a requirement. You achieve zero errors through regular integrity checks and restore practices. CISA, the US Cybersecurity and Infrastructure Security Agency, has noted that many organizations only discover their restores fail during an actual incident, which is the worst possible time to learn that lesson. Running a test restore every quarter, or automating checks on your backup files, is a better way to make sure your data is safe. The 3-2-1 backup rule is still standard, with one update The version of the rule I follow now is 3-2-1-1-0, and it’s not much harder to set up than the original. The difference is that when something goes wrong, I’ll know my backups work because I’ve already tested them, not because I assumed they would.