The 3-2-1 rule is about twenty years old, fits on a napkin, and is still violated by most setups that think they are following it.

01The Rule and What It Actually Says

Three copies of your data. Two different storage media. One of those copies kept off-site. That is the whole rule, and it came from Peter Krogh, a photographer and author who wanted something memorable enough to survive a conversation. It has. The reason it endures is not that three is a magic number — it is that the failure modes for any two copies sharing a location, a power circuit, or a vendor tend to overlap. The rule is a systematic way to separate your coincident risk.

Start with the number three. Two copies sound like a backup plan, but they are really just a bet that both copies do not fail at the same time. A laptop and an external drive sitting on the same desk share the same fire risk, the same flood risk, the same accidental-deletion event, and, if both are spinning, a non-trivial correlated failure rate during the period when a RAID or sync job is under load. A third copy, kept separately, means that two independent bad things have to happen simultaneously for you to lose everything. In practice, that is the difference between a recoverable situation and a permanent one.

The two-media requirement is often the least-understood part. It is not about brand loyalty or a checklist; it is about failure modes that cluster by technology. All external USB hard drives are vulnerable to the same class of mechanical failures: read heads, bearing wear, the shock of being knocked off a shelf. All optical discs fail by oxidation and disc rot over long timescales. All flash media shares write-cycle limits and, in some form factors, a tendency to go read-only rather than warn you. Keeping your backup on the same type of media as your primary means that a single root cause — a firmware vulnerability, a manufacturing batch, a price-driven decision to use cheaper flash — can take both copies at once. Two different media means two different failure trees.

The off-site requirement is where setups most visibly collapse. "Off-site" means genuinely physically separated — not the spare bedroom, not the garden shed, not the NAS in the office where the server lives. Off-site means that whatever event could destroy your primary copy cannot plausibly also reach your backup copy. A house fire is the obvious example, but burglary, flooding and the correlated power surge from a lightning strike are equally real. If you are a home user, off-site might mean a drive at a family member's house that you rotate every few months. If you are a small-office admin, it might mean a cloud tier plus a rotation of encrypted drives moved off-premises on a defined schedule. The medium matters less than the genuine physical separation.

3copies of the data — distinct copies, not windows onto one
2kinds of media, so one failure mode cannot take both
1off-site, in a different building
0errors on a restore you have actually performed

02Where Every Setup Falls Short

The 3-2-1 rule describes a minimum structure. It says nothing about what happens inside that structure, and that is where the actual losses occur.

The most common shortfall is the sync is not backup confusion. A folder mirrored to a second location in real time is not a second copy in any meaningful sense — it is a shadow of the first. Delete a file accidentally, or let ransomware encrypt your working directory, and the mirror reflects the damage within seconds. The same applies to cloud sync services: the moment your primary changes, so does the synced copy. What you need is a copy that has some temporal distance from the primary — a window of hours, days or weeks during which a deletion or corruption has not yet propagated. Versioning and retention windows are what give a backup its actual value; without them, you have redundancy, not recovery.

The second shortfall is untested restores. A backup that has never been tested is not a backup; it is a hypothesis. Storage media fails silently. Backup jobs fail silently. Files get written to a location that the restore script does not read. The only way to know whether your backup works is to restore from it — not a spot check, but a real restore to a real machine, at least once a year. The number of copies you have is irrelevant if none of them are readable when you need them.

The third shortfall is coverage gaps. People back up documents and photographs and then discover, after a failure, that they did not back up the application settings that made those documents useful, or the authentication keys that unlock the cloud storage where the backup lives, or the database files that were open and locked when the backup ran. A backup plan that has never been walked through as a restore exercise almost always has a gap somewhere.

The fourth shortfall, and in some ways the most dangerous, is letting the off-site copy go stale. A drive at your parents' house that has not been updated in fourteen months is not an off-site backup — it is an archive of who you were fourteen months ago. The off-site copy has to be on a rotation cycle that matches the value of your data and your tolerance for loss. For most people with active working files, that cycle should be measured in weeks, not quarters.

3 Copies of the data 2 Kinds of media 1 Buildings 1 Offline or immutable copies 0 Errors on a test restore
The rule as a target, tier by tier. The last two are the extension most setups never reach.

A folder mirrored to a second location in real time is not a second copy in any meaningful sense — it is a shadow of the first.

03Raising the Floor

Once the 3-2-1 minimum is genuinely in place — not aspirationally, but verifiably — you can think about extending it. Some practitioners now talk about 3-2-1-1-0: three copies, two media, one off-site, one offline or air-gapped, and zero errors verified on restore. The extra digit acknowledges that an internet-connected backup is vulnerable to the same ransomware that encrypts your primary; an offline copy, whether a cold drive in a drawer or a tape on a shelf, is not reachable by software. The zero is a reminder that the count of copies is a vanity metric if the copies contain errors.

LTO tape, which has been in continuous development since the late 1990s, remains the gold standard for offline archival precisely because a written tape cartridge sitting on a shelf has no attack surface. It cannot be reached by ransomware, it does not need power to retain data, and modern LTO generations carry enough capacity to make per-gigabyte costs competitive with spinning disk for bulk archival. It is not the right answer for everyone — the hardware cost and the procedural overhead make it a small-office solution at minimum — but it illustrates the principle: offline means genuinely unreachable.

For home users and small offices that are not running tape, the practical version of offline is a drive that is only connected during the backup window, then powered off and physically removed. A drive that is not on is a drive that ransomware cannot touch.

The number of copies that is "enough" is ultimately not a fixed answer — it is a function of how irreplaceable your data is, how recent your off-site copy needs to be, and what failure scenarios you have actually thought through. The 3-2-1 rule is the floor, not the ceiling. Most setups do not yet meet the floor. Start there, verify it works, and then ask whether the ceiling needs to be higher.

Off-site means a different building. A drive that lives beside the machine it backs up shares its power supply, its burglar and its flood.