Why Backups Are Part of Digital Security—and How 3-2-1 Works with SimpleumSafe

A SimpleumSafe safe on a Mac is backed up to a separate external drive, with files moving along an arrow between them.

An encrypted safe protects important documents from prying eyes. A backup protects them from being lost altogether. Both belong together: encryption provides confidentiality, while a good backup helps you recover after a hardware failure, accidental deletion, lost device, or attack.

The most important recommendation fits into one sentence:

Keep your working copy and two independent backups, use at least two storage types or independent storage systems, and keep one copy in a different location.

This is the 3-2-1 backup rule. It may sound technical at first, but it can be integrated into everyday life with little effort. You do not need to build the perfect solution immediately. What matters is starting with one reliable backup and improving it step by step.

What You Can Do Today

If you use SimpleumSafe on your Mac, these four steps are a good place to start:

  1. In SimpleumSafe, open Settings > Backup.
  2. If possible, select an external drive as the backup location and enable a suitable automatic backup schedule.
  3. Create another independent copy—for example, an encrypted, versioned backup stored in a different location.
  4. Occasionally check whether you can actually open a backup or restore selected data from it.

Even the first backup on a separate drive is a major improvement. Adding a second copy in a different location turns it into much more resilient protection.

You Decide How Deep You Want to Go

This article deliberately moves from the essentials to the details. If the four steps above are enough for you, you have already learned the key points and can stop here with confidence. If you continue reading, you will find additional background, examples, and guidance for improving your backup strategy further.

Why Are Backups a Security Issue?

When people think about digital security, they often think first of strong passwords, encryption, and protection against unauthorized access. That is correct, but incomplete. Information security is commonly described through three objectives:

  • Confidentiality: Only authorized people can read the data.
  • Integrity: The data remains complete and unaltered.
  • Availability: Authorized people can access the data when they need it.

Encryption is especially important for confidentiality. It does not, however, prevent a storage device from failing, a file from being deleted accidentally, or a device from being stolen. Nor can it recover data damaged by a technical error.

This is where backups perform their security function: they provide an independent route back to an earlier, working state. NIST includes confidentiality, integrity, and availability among the fundamental objectives of information security. A backup is therefore not an inconvenient extra task, but part of a complete protection strategy.

The 3-2-1 Backup Rule Explained

The numbers do not refer to specific software or a particular product. They stand for three simple rules.

Three-stage illustration of the 3-2-1 backup rule: an active safe on a Mac, a local backup on an external drive, and a second backup in a different location.
One working copy on your Mac, one local backup on a separate drive, and another backup in a different location.

3 – Three Copies of Important Data

This means:

  • one active working copy,
  • one first backup,
  • one second backup.

The original and a single backup can be affected by the same incident. If both are on the same drive, for example, a failure of that drive can destroy them together. Two independent backups reduce this risk considerably.

2 – Two Storage Types or Independent Systems

The copies should not all depend on the same device, account, or storage system. For personal use, this might be a combination of a Mac, an external drive, and a trustworthy encrypted offsite backup.

The important point is an independent failure path. Two folders on the same drive are not two resilient backups. Two backup methods on the same physical drive are also of little help if that particular drive fails.

1 – One Copy in a Different Location

A geographically separate copy provides additional protection against theft, fire, water damage, or electrical surges. It can be kept on an encrypted drive in another secure location or stored through a carefully selected backup service.

CISA also describes 3-2-1 as three copies on two different media, with one copy kept offsite. The rule is a robust guideline, not a guarantee: backups must also be current, protected, and recoverable.

A Practical 3-2-1 Model for SimpleumSafe on Your Mac

Here is one straightforward approach:

Role
Practical example
Working copy
Your active SimpleumSafe safe on your Mac
First backup
An automatic SimpleumSafe backup on an external drive
Second backup
An encrypted, versioned backup through another system
Different location
The second backup is offsite or sufficiently separated through technical controls

1. Use SimpleumSafe’s Automatic Backup

On a Mac, SimpleumSafe can automatically create backups of a safe. Under SimpleumSafe > Settings > Backup, you can configure the backup location, frequency, and number of backups to retain.

If possible, do not select a folder on the same internal drive that holds the active safe. An external drive separates the first backup from a failure of your Mac’s internal storage. Connecting the drive only for a backup and disconnecting it afterward also reduces the period during which an error or attack could reach both copies.

After setup, check whether the first backup completed successfully. Selecting a folder does not by itself mean that a current backup already exists.

2. Use Time Machine as an Additional Layer

The SimpleumSafe safe format is designed to work with Apple Time Machine backups. Time Machine can automatically preserve earlier file versions on an external drive or a suitable network destination. Apple recommends using storage other than your Mac’s internal drive for the backup.

Time Machine can complement SimpleumSafe’s own backup. If both methods use the same physical drive, however, they still share one point of failure. A truly independent copy needs another destination.

Whenever possible, enable encryption when setting up the Time Machine backup. Store the required password securely and separately. Without it, an encrypted Time Machine backup cannot be restored later.

3. Keep One Copy Offsite

There are two common ways to create the third copy:

  • With a backup service: A trustworthy backup system stores an encrypted, versioned copy in another location. Review the provider’s privacy practices, encryption, access protection, retention period, and recovery options.
  • Without cloud storage: Use a second encrypted drive, update it regularly, and then keep it in another secure location. Rotating between two drives can make the routine easier.

The second option may use the same type of storage medium as the first backup. It is therefore not the strictest interpretation of “two media,” but it does separate devices and locations and represents a major security improvement for many people.

Synchronization Is Useful—but It Is Not a Backup

SimpleumSafe can synchronize safes between your own devices. This is convenient because current data is available on more than one device. Synchronization, however, has a different purpose from backup: it keeps data states in sync.

If a deletion or damaged state is propagated, it can affect several synchronized devices. A backup, by contrast, deliberately preserves earlier, independent states. Therefore:

Multiple synchronized devices improve everyday availability, but they do not replace a versioned and independent backup.

A cloud folder is not automatically a cloud backup either. What matters are features such as version history, protection against permanent deletion, separate access rights, and a recovery process that has been tested in practice.

Why a Separated Copy Matters During an Attack

Backups do not only help with hardware failures and mistakes. They are also an important precaution against ransomware and other destructive attacks. Malware can encrypt or delete files. If a backup is permanently accessible with the same extensive permissions, it may be affected as well.

At least one backup should therefore be separated from normal working access. This can be a disconnected drive. Modern backup services may also provide immutable versions, deletion protection, and separate accounts that create such a barrier. The UK’s National Cyber Security Centre explicitly recommends using multiple backup locations and assessing the resilience and recoverability of online backups.

This does not mean every backup has to remain offline all the time. It means that all copies should not be reachable through the same failure, account, or attack path.

How Often Should You Back Up?

The right frequency is not determined by one fixed rule, but by a simple question:

How many changes could you afford to lose in an emergency?

If you add content to your safe every day, a daily automatic backup is sensible. If the contents change only rarely, a longer interval may be sufficient. What matters is that the backup happens automatically or through a realistic routine. A plan that nobody remembers will not protect you when it matters.

The UK National Cyber Security Centre recommends creating backups regularly and testing that they work as expected. Match the schedule to your actual use and set a recurring reminder for manual offsite backups.

A Backup Is Valuable Only If Recovery Works

A green status indicator or an existing backup file is reassuring, but it is not complete proof. Problems can remain unnoticed for a long time: the wrong folder may have been backed up, the drive may have been unavailable, or the required password may be missing.

Occasionally test a recovery. For a manageable test, select a small, known set of data and verify that it can be recovered from the backup in readable form. Perform the test without overwriting your active working copy.

Also record:

  • where the backups are stored,
  • which password or recovery material is required,
  • when a backup last completed successfully,
  • when recovery was last tested.

Store passwords and recovery material securely. Do not leave them unprotected next to the drive. They need to be available in an emergency without becoming a shortcut for unauthorized people.

A Note for iPhone and iPad

The built-in SimpleumSafe backup described in this article is available on the Mac. There is currently no equivalent built-in backup function on iPhone or iPad. If you use SimpleumSafe on several Apple devices, a synchronized Mac can serve as the starting point for independent backups. Synchronization itself remains only the transfer path and does not count as a backup.

If you use a safe exclusively on an iPhone or iPad, check especially carefully before deleting original documents which independent backup or export method is available for your particular setup.

Your Backup Checklist

Good Protection Can Be Simple

A good backup does not have to be complicated. Start with an automatic backup on a separate destination. Then add a second copy in another location and occasionally test whether you can recover your data.

SimpleumSafe protects the confidentiality of your important documents. Your backup routine adds something equally important: confidence that you can get back to work after a failure, mistake, or attack.

The SimpleumSafe Security Center helps you keep the backup status and other important safeguards for your safes in view.


Information current as of August 21, 2026. Product features and operating-system interfaces may change.