The 3-2-1 backup rule on Windows 11 and Windows 10: a setup that survives ransomware
The 3-2-1 rule means keeping three copies of your important files, on two different kinds of storage, with one copy offline or off-site. On Windows 11 and Windows 10 you can build it with tools you already have: File History to an external disk, OneDrive with version history, and one disk that stays unplugged between backups.
What the 3-2-1 rule means
The rule is a simple checklist for making sure no single event can take all copies of your files at once.
- 3 copies. The working files on your PC plus two backups. One backup is not enough, because a backup can fail just when you need it.
- 2 different kinds of storage. For example the PC's internal drive and an external disk, or an external disk and a cloud service. Different storage fails for different reasons.
- 1 copy offline or off-site. At least one copy that the PC cannot reach all the time, such as a disk you unplug after each backup, or a cloud backup with version history that a program on the PC cannot erase.
The third point is what makes the rule work against ransomware. Ransomware encrypts everything the PC can write to, including a backup disk that stays plugged in. A disk in a drawer, or versions held by a cloud service, is out of its reach. US government guidance from CISA describes the same approach, and many organisations extend it to 3-2-1-1-0: one copy that cannot be changed and zero errors in restore tests.
Why backups matter more than any removal tool
Removing malware stops further damage. It does not undo damage already done. When ransomware has encrypted files, they come back only from a key or from another copy, and for most families no free key exists: see how ransomware works and free ransomware decryptors.
Ransomware is not the only reason. Wipers destroy data on purpose, a trojan can delete files, an SSD can fail without warning, a laptop can be stolen, and a Windows update or a reset can go wrong. A good backup answers all of these with the same action: restore the files and carry on.
With a working backup, the question of whether to pay a ransom does not come up. That alone makes a backup the most effective protection a home PC can have.
What to back up
You do not need to back up Windows itself or your programs. Both can be reinstalled. Focus on what cannot be replaced:
- Documents, Desktop, Pictures, Videos and Music, the default user folders.
- Folders you created elsewhere, such as a projects folder on drive D or a photo archive on a second disk.
- Program data you care about: e-mail archives if you use a desktop mail client, game saves, password manager exports, accounting files.
- Recovery information: two-step verification backup codes, the BitLocker recovery key, licence keys. Store these offline, printed or on a separate USB stick, not only on the PC.
Check where your apps save things. Some keep files in hidden folders under your user profile, which a backup of Documents alone will miss. If you are not sure, open the app's settings and look for a data or save location.
Also think about size and growth. Photos and videos take most of the space on a typical home PC, and they are also what people miss most after an attack. Buy a backup disk with room for several years of growth, and check the free space on it when you test your backups.
The backup tools built into Windows 11 and Windows 10
Windows has several backup features with similar names. They do different things, and a 3-2-1 setup usually combines two of them.
Windows Backup and OneDrive folder backup
The Windows Backup app, and in Windows 11 the page Settings > Accounts > Windows backup, backs up the Desktop, Documents, Pictures, Videos and Music folders to OneDrive, together with settings, app lists and credentials. In practice the folders are synced to OneDrive, so they are available on any PC where you sign in. A free Microsoft account includes 5 GB of OneDrive storage; more requires a paid plan.
OneDrive version history and Restore your OneDrive
OneDrive keeps earlier versions of files, so a file that was encrypted and synced can be rolled back to the version before. Microsoft 365 subscribers can also restore the entire OneDrive to any point in the last 30 days, which is the fastest fix after ransomware encrypted many synced files: Restore deleted or older files in OneDrive On uGetFix.
File History
File History copies changed files from your user folders to an external drive or a network location on a schedule, every hour by default, and keeps older versions. In Windows 11 it is in Control Panel > System and Security > File History. In Windows 10 you can also set it up from Settings > Update & Security > Backup > Add a drive. Its versions appear in the Previous Versions tab of files and folders.
Backup and Restore (Windows 7)
This older Control Panel tool can create a full system image. It still exists in Windows 11, but Microsoft lists it as deprecated and recommends other products for full-disk backups. Use it only as an extra, not as your only backup.
Step-by-step instructions for each tool are in Back up your files (Windows Backup, File History, Time Machine) On uGetFix.
Three ways to build a 3-2-1 backup on a home PC
Pick the setup that matches how you work. Each one meets all three parts of the rule.
Setup A: OneDrive plus one external disk
- Turn on folder backup in Windows Backup, so Desktop, Documents and Pictures sync to OneDrive. That is copy two, on a second kind of storage, with version history.
- Buy an external disk at least twice the size of your files. Turn on File History to it, or copy your folders to it with a backup program.
- Plug the disk in once a week, let the backup finish, then unplug it and keep it away from the PC. That is copy three, offline.
Setup B: two external disks, one kept elsewhere
Without cloud storage, use two disks. Back up to disk one every week and to disk two every month, and keep disk two at another address, such as a relative's home or your workplace. Swap them now and then so the off-site copy stays fresh.
Setup C: a NAS with snapshots plus a cloud or offline copy
A network storage box with snapshot support keeps versions that the PC cannot delete, as long as the NAS administrator password is not saved on the PC. Add a cloud backup of the NAS, or an external disk that you connect to the NAS and then unplug, for the off-site copy.
Whatever you choose, the disk that holds your offline copy must be unplugged when you are not running a backup. A permanently connected disk counts as online storage.
If you use an encrypted external disk, for example with BitLocker To Go, store its password or recovery key somewhere other than the PC. A backup you cannot unlock after a reset is no better than no backup.
Test your backup before you need it
A backup you have never restored is only a hope. Test it when nothing is wrong, so you find problems while the originals still exist.
- Every few months, pick a few files of different types, for example a document, a photo and a spreadsheet.
- Restore them from each backup to a new folder, not over the originals.
- Open them and check that they are complete and current.
- Check the date of the newest backup. If it is older than you expected, the schedule is not running.
Windows does not always warn loudly when a backup stops. File History pauses when its drive is missing, and OneDrive stops syncing when storage is full. A quick look at the dates once a month catches both.
Restoring safely after ransomware or other malware
The order matters. Restoring onto an infected PC can get the restored files encrypted or infected again.
- Remove the malware first, and confirm with a full scan and an offline scan: Run a Microsoft Defender Offline scan. If the infection was serious, reset Windows instead: clean up or reset Windows after malware.
- Keep the encrypted files on a separate drive until you have checked the restored copies. A decryptor released later may still be useful.
- Connect the offline backup disk only after the PC is clean, and restore to a new folder first.
- For files synced to OneDrive, roll back to a time before the attack instead of copying files one by one.
- Do not restore program installers or downloads from the backup without scanning them. The program that brought the malware in may be among them.
The full recovery checklist after ransomware, including identification and decryptors, is in Ransomware: first steps, finding a decryptor and recovering files.
Common backup myths
- Sync is a backup. OneDrive, Google Drive and Dropbox copy changes everywhere, including encryption and deletion. They protect you only through version history and the recycle bin, which have time limits.
- A second internal disk is a backup. It is in the same PC, so ransomware and power faults reach it just as easily.
- Restore points are a backup. System Restore and Previous Versions snapshots sit on the same drive and are deleted by most ransomware: see shadow copies after ransomware.
- RAID or a mirrored disk is a backup. Mirroring copies mistakes and encryption instantly to both disks.
- One cloud backup is enough. A single online account can be locked, deleted or filled with encrypted versions after the retention period. Keep at least one copy you can hold in your hand.
Frequently asked questions
What is the 3-2-1 backup rule?
It is a rule of thumb for keeping data safe: keep three copies of important files, on two different kinds of storage, with one copy offline or off-site. On a Windows PC that could be the files on the PC, a copy in OneDrive with version history, and a copy on an external disk that you plug in only for backups. Each copy protects against a different problem: disk failure, theft, accidental deletion or ransomware. Losing all three at once becomes very unlikely.
Does Windows 11 have a built-in backup?
Yes, several. Windows Backup, found in Settings, Accounts, Windows backup, syncs your Desktop, Documents, Pictures, Videos and Music folders to OneDrive and saves settings and app lists. File History, in Control Panel under System and Security, copies changed files to an external drive or network location every hour by default and keeps older versions. The older Backup and Restore (Windows 7) tool can still create a system image, but Microsoft lists it as deprecated. Combining OneDrive with File History to an external disk covers the 3-2-1 rule.
Is OneDrive a backup or just sync?
Mainly sync, with backup features on top. When a file on the PC changes, OneDrive uploads the change, including encryption by ransomware or deletion. What makes it useful as a backup is version history, which keeps earlier versions of files, and the recycle bin. Microsoft 365 subscribers can also restore the whole OneDrive to any point in the last 30 days. Treat OneDrive as one of your copies, and keep another copy on a disk that is not connected all the time.
Can ransomware encrypt my backup drive?
Yes, if the drive is connected when the ransomware runs. A USB disk that stays plugged in, a mapped network drive and a NAS share the PC can write to are all encrypted like local folders. A disk that was unplugged during the attack cannot be touched. Cloud services with version history also keep earlier copies, even if the current files were overwritten. That is why the 3-2-1 rule requires one copy offline or off-site: plug the backup disk in, run the backup, and unplug it again.
How often should I back up my PC?
As often as the amount of work you are willing to lose. For most home users, continuous sync to OneDrive plus a weekly backup to an external disk is a good balance: OneDrive covers recent changes, and the weekly offline copy limits the loss to a few days in the worst case. If you work on important files every day, back up to the external disk more often, or use File History to a network location with snapshots. Check the date of the last backup once a month.
Should I restore my backup right after a ransomware attack?
Not right away. First remove the ransomware and confirm with a full scan and an offline scan, or reset Windows if the infection was serious. If you restore while the ransomware is still active, it can encrypt the restored files and the backup disk too. Connect the backup only after the PC is clean, restore to a new folder first and check the files. Keep the encrypted originals on a separate drive until everything you need is back and working.
Sources
- CISA: Data Backup Options (read 4 October 2026)
- Microsoft Support: Back up and restore with Windows Backup (read 4 October 2026)
- Microsoft Support: Backup and restore with File History (read 4 October 2026)
- Microsoft Support: Restore your OneDrive (read 4 October 2026)
- Microsoft Learn: Deprecated features in the Windows client (System Image Backup) (read 4 October 2026)
Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.