The 3-2-1 Backup Rule in Plain Language
Keep multiple copies on different storage with one independent location and verify restoration. Adapt the principle to cloud services and document who can recover each system.
Preparing your experience
Topic collection
Practical security and privacy habits for websites, accounts and small-business systems.
10 guides
Keep multiple copies on different storage with one independent location and verify restoration. Adapt the principle to cloud services and document who can recover each system.
Prepare contacts, evidence, containment, recovery and communication steps before a security emergency. After recovery, document the cause, impact and preventive actions with clear owners.
Plan tested updates for operating systems, frameworks, plugins and applications before unsupported versions become urgent. Assign an owner and maintenance window before a critical advisory appears.
Understand what encrypted transport protects and which application, account and operational risks remain. Treat HTTPS as one necessary layer inside a broader security program.
Collect only necessary personal information and define purpose, access, retention and secure delivery. Document processors and integrations so privacy reviews include the complete data journey.
Give people and systems only the access needed for current responsibilities and review it regularly. Design an escalation path so people can request additional access without bypassing controls.
Protect administration, updates, plugins, backups and hosting without relying on one security plugin. Review the full stack after every compromise, not only the visibly changed page.
Pause suspicious email, chat and login requests and verify them through an independent channel. Use MFA and role-based payment approval to reduce damage if one message succeeds.
Reduce account takeover risk with suitable second factors, recovery codes and an accountable rollout. Review enrollment and recovery after role or device changes.