The 3-2-1 backup rule, applied to a real media library
Three copies, two kinds of media, one off-site. It's an old rule because it keeps being right — and it's more affordable to follow than most people assume.

The rule is compact: keep three copies of anything you care about, on at least two different types of storage, with at least one stored somewhere else. It comes from professional practice and survives because each part addresses a distinct way of losing data.
Three copies covers ordinary drive failure, because the chance of two failing simultaneously is small. Two media types covers systematic failure — a bad batch, a controller fault, a format going obsolete. One off-site covers the events that destroy everything in one building: fire, flood, theft.
Why one copy plus sync isn't enough
The common setup is files on a computer, synced to cloud storage, and that feels like two copies. It's closer to one and a half, because sync propagates deletion and corruption. If a file is destroyed locally, it's destroyed remotely shortly afterwards.
A backup differs from sync in one essential way: the copy is not automatically modified when the original changes. Versioning, or a copy that isn't continuously connected.
A workable setup for a few terabytes
Copy 1 — the working library. Your main drive or NAS. This is what you use daily.
Copy 2 — a local backup on different media. An external drive, ideally a different type or brand from the primary. Connect it, run the backup, disconnect it. That disconnection is the point: a drive that isn't plugged in can't be encrypted by ransomware or wiped by a mistaken command.
Copy 3 — off-site. Three realistic options:
- A drive at another address. Cheapest. A second external drive kept at a relative's house or the office, swapped every month or two. Perfectly valid, and the weak point is discipline — an off-site copy from a year ago is a year out of date.
- Cloud backup. Automatic, always current, recurring cost. For several terabytes of video this adds up, so it's often worth applying only to the irreplaceable subset.
- Both, split by importance. Cloud for photos and documents, off-site drive for the bulk media. This is what most people end up with and it's a sensible allocation.
Sort by replaceability first
Before designing anything, split the library into two piles. This decision does more for your costs than any tool choice.
Replaceable: ripped discs you still own, purchased downloads you can re-download, anything available from a subscription. Losing it costs time, not content. One backup is proportionate.
Irreplaceable: photos, home video, scanned documents, your own creative work. Exists nowhere else. Full 3-2-1, without negotiation.
The irreplaceable pile is usually far smaller than people expect — often small enough that cloud backup for that portion alone is inexpensive.
Automate it or it won't happen
Manual backups get skipped. Most operating systems include a scheduled backup tool, and free cross-platform options handle scheduling, versioning and verification.
For the off-site drive that has to be physically moved, automation can't help, so use a recurring calendar reminder. Monthly is a reasonable compromise between effort and exposure.
Test restores, or you don't have backups
This is the step everyone skips and it's the one that decides whether the whole arrangement was real.
Twice a year, restore a handful of files from each backup to a different location and open them. You're checking that the backup actually contains what you think, that you remember how to restore, and that the files aren't silently corrupted.
Backups fail quietly. A job that's been erroring for eight months looks exactly like one that's been working, until the day you need it.
Two things worth adding
Encrypt the off-site copy. A drive at someone else's house or in the cloud is outside your physical control. Full-disk encryption is built into every major operating system.
Keep some version history. Corruption and accidental changes often go unnoticed for weeks. A backup that only holds the current state can't help if the current state is already wrong. Thirty days of versions is a reasonable minimum for documents.