Security & Privacy
How to Back Up Your Data Securely
A reassuring, jargon-free guide to backing up your data securely, covering the simple 3-2-1 rule, cloud and local options, encryption, and testing backups.
Security & Privacy
A reassuring, jargon-free guide to backing up your data securely, covering the simple 3-2-1 rule, cloud and local options, encryption, and testing backups.
A secure backup means three copies of your files, on two different kinds of storage, with one copy stored somewhere your house keys cannot reach it and encrypted so a thief who steals the drive gets nothing readable. That single sentence is the whole plan; the rest of this guide turns it into concrete settings, real tools, and the mistakes that quietly ruin backups people thought they had.
The 3-2-1 rule is the industry baseline: 3 copies of the data, on 2 distinct media types, with 1 copy off-site. Your working files on your laptop count as the first copy. An external SSD on your desk is the second, on a different medium. A cloud backup in a data center is the third, and it satisfies the off-site requirement.
Modern practice extends this to 3-2-1-1-0. The added 1 is an offline or immutable copy that ransomware cannot reach, and the 0 means zero errors on your last verified restore. Those two additions exist because the threat changed. A decade ago the enemy was a dead hard drive; today it is just as likely to be malware that encrypts every file it can write to, including the backups your computer is actively connected to.
Consumer hard drives do not last forever. Backblaze, which runs hundreds of thousands of drives and publishes the numbers, reports annualized failure rates in the low single-digit percentages that climb sharply after year three to five. SSDs fail not from spinning wear but from write exhaustion, rated in terabytes written (TBW), while a USB stick or SD card left in a drawer can lose its charge and corrupt silently. No single device is a plan. The redundancy is the plan.
A local backup restores in minutes rather than the hours a large cloud download takes, and it costs nothing after you buy the drive. Buy a drive at least twice the size of the data you are protecting so version history has room to grow.
Use Time Machine. Plug in an external drive, then go to System Settings > General > Time Machine > Add Backup Disk. Critically, tick Encrypt Backups during setup; without it, anyone who picks up the drive can read every file. Time Machine keeps hourly snapshots for the past day, daily for the past month, and weekly until the disk fills, which is what lets you recover a file as it existed last Tuesday, not just its latest version.
Windows 11's built-in File History (Control Panel > System and Security > File History) versions your Documents, Pictures, and Desktop folders to an external drive. For a full disk image you can restore a dead machine from, use the legacy Backup and Restore (Windows 7) tool or a dedicated app like Macrium Reflect. To encrypt an external drive, use BitLocker To Go (right-click the drive in File Explorer), available on Windows Pro; BitLocker uses AES-128 or AES-256.
A local drive that lives permanently plugged into your PC faces the exact same lightning surge, theft, flood, and ransomware as the computer. Keep it disconnected between backups, and never treat a same-desk drive as your only safety net.
The cloud handles the hardest part of 3-2-1, the off-site copy, automatically. But there is a distinction that trips up nearly everyone.
Dropbox, Google Drive, OneDrive, and iCloud Drive are sync services. They mirror a folder, which means a deletion, corruption, or ransomware encryption on your PC syncs up to the cloud and overwrites the good copy. Sync is convenient and useful, but on its own it is not a backup because the failure travels with your files.
What saves you is version history. Dropbox and OneDrive retain 30 days of prior versions on standard plans; Google Drive keeps versions for 30 days or 100 revisions. If ransomware hits, you can roll back, but only inside that window, which is why sync alone is fragile.
True backup services keep independent, versioned copies designed to survive what happens to your machine. Backblaze Personal backs up one computer for a flat monthly fee (roughly the price of a coffee) with no storage cap and offers extended version history as an add-on. IDrive covers multiple devices under one plan. These run continuously in the background and, importantly, are not a live-synced folder, so a local disaster does not immediately propagate.
The trade-offs are honest ones: a subscription, a dependence on upload bandwidth (a first full backup of 500 GB can take days on home internet), and the need to trust a provider. Choose one that offers a private encryption key, discussed next.
A backup concentrates your entire digital life into one place, so its security matters more than any single device's. Encryption scrambles files with a key so that a lost drive or breached account yields unreadable noise. The standard to look for is AES-256.
Turn this on regardless of your backup plan. On macOS, enable FileVault in System Settings > Privacy & Security > FileVault. On Windows Pro, enable BitLocker in Control Panel > System and Security > BitLocker Drive Encryption. Store the recovery key somewhere safe, such as a password manager, because if you lose it the data is gone for good, which is precisely the point.
Ask whether your cloud provider offers end-to-end (zero-knowledge) encryption, where you hold a key the provider never sees. Backblaze lets you set a Private Encryption Key; Apple's Advanced Data Protection (Settings > your name > iCloud > Advanced Data Protection) extends end-to-end encryption to iCloud backups. With zero-knowledge, even a breach of the provider or a rogue employee cannot read your files. The catch is real: forget the key and no one, including the provider, can recover your data. If you want to encrypt files before they ever leave your machine for any cloud, Cryptomator and VeraCrypt are trusted, open-source options.
Protect any backup account with a long, unique passphrase from a password manager, and turn on two-factor authentication. Prefer an authenticator app (TOTP) or a hardware security key (FIDO2, such as a YubiKey) over SMS codes, which can be intercepted through SIM-swap attacks.
The number one cause of missing backups is not hardware; it is that a manual backup gets skipped during a busy month and silently lapses. Every tool above can run on a schedule. Time Machine backs up hourly, File History defaults to hourly, and cloud services run continuously. Switch automation on once and stop relying on memory.
An unverified backup is a hope, not a safety net. Twice a year, actually restore something: pull a specific file from last month out of Time Machine or File History, or download a folder from your cloud service and open it. This is the 0 in 3-2-1-1-0, confirming the backup is not silently corrupt. People discover dead backups at the worst possible moment, when the original is already gone.
No, because those are sync services, not backups. A ransomware infection or accidental deletion propagates to the cloud copy, and version history typically protects you for only about 30 days. Pair one with a true backup that keeps independent, longer-lived versions.
Plan to retire spinning hard drives around the three-to-five-year mark, since failure rates rise steeply after that. Do not wait for a drive to die; migrate to a new one while the old one still reads. SD cards and USB sticks are for transfer, not long-term storage.
Full-disk encryption (FileVault, BitLocker) protects the drive inside or attached to your computer while in use. Backup encryption protects the copy sitting in the cloud or on a disconnected drive. You want both, because a thief who steals a backup drive should get the same unreadable noise as one who steals your laptop.
Yes, if ransomware worries you. Malware and a compromised account can reach anything your machine or credentials can write to, including live cloud storage. A disk you physically disconnect, or an immutable backup the service protects from deletion, is the copy that survives an attack the others cannot.
Keep reading
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
A calm, jargon-free guide to protecting your privacy on your phone, covering app permissions, location sharing, lock screens, and trimming back data tracking.