Backup & Redundancy

Backup and redundancy protect the photographic record of a collection by maintaining recoverable, independent and verified copies. The objective is not simply to own several drives or to see the same folder on several screens. It is to ensure that no single failure - deletion, corruption, theft, fire, account loss, ransomware or the death of the person who understands the system - can erase every usable route to recovery.

Collection photographs may be the only surviving evidence of condition, completeness, ownership, identifying marks, seller packaging, restoration or an object's state at a particular date. The physical collectible may be carefully preserved for generations while its digital history remains exposed on one phone, computer, external drive or online platform. A collector-grade backup system corrects that imbalance.

Collector scenario: the photograph that cannot be retaken

A collector photographs a sealed parcel, the packaging layers, a damaged corner discovered during unpacking and the serial number of the object inside. The files remain on the laptop and in a synchronised folder. Months later the item is sold, the laptop is infected with ransomware and the encrypted files synchronise to the cloud.

The object itself still exists, but the original acquisition sequence does not. Retaking a clean catalogue photograph cannot recreate the parcel, the damage as first found or the evidence that the numbered object arrived in that package. What was lost was not illustration; it was collection history.

The preservation problem

Why collection photographs become irreplaceable records

A photograph is only repeatable when the object, its condition, its arrangement and the relevant event all remain available. In collecting practice, those conditions often disappear.

An unopened parcel and the seller's original packing arrangement.

Damage discovered during unpacking or a defect visible before treatment.

A serial number, signature, label or ownership mark on an object later sold.

The contents of a complete set before components were separated.

A pre-restoration state that no longer exists after intervention.

A room, cabinet or shelf before theft, fire, flood or relocation.

Evidence that an accessory, insert or certificate accompanied an acquisition.

Insurance photographs of an object subsequently stolen or destroyed.

This changes the preservation question. The collector is not merely protecting convenient copies of pictures; they may be protecting the only surviving record of a temporary state, transaction or evidential detail. Backup priority should therefore follow significance and irreversibility, not file size alone.

Terms that are often confused

Backup, redundancy and synchronisation solve different problems

A resilient system normally uses all three, but none should be mistaken for another.

RECOVERY

Backup

An additional recoverable copy created so that deleted, overwritten, corrupted or historically changed files can be restored. A useful backup normally includes version history and the contextual data needed to reconstruct the library.

CONTINUITY

Redundancy

More than one functioning copy, device, location or system so that one failure does not immediately remove access. Redundancy improves resilience, but a mirror can still reproduce deletion, corruption or ransomware.

CONVENIENCE

Synchronisation

A process that keeps folders aligned between devices or services. It is useful for access, but it may faithfully copy unwanted edits, deletion and encrypted files everywhere.

STEWARDSHIP

Digital preservation

The continuing work of keeping files authentic, intact, understandable and usable through storage management, fixity, metadata, security, migration and periodic review.

The central diagnostic question

What single event could destroy, alter or make inaccessible every usable copy?

If one computer, account, building, password, proprietary database, connected network or person remains capable of defeating the whole system, a single point of failure still exists.

Failure domains

Copies are meaningful only when they fail independently

Two files can be separate yet remain exposed to the same event. Independence is a judgement about shared risk, not physical file count.

Device failure

Internal drive failure, controller faults, damaged memory cards, cable failure or a computer that no longer starts.

Human error

Accidental deletion, mistaken replacement, poor deduplication, bulk renaming errors or reformatting a card too soon.

Shared technical failure

Ransomware, malware, faulty synchronisation, filesystem corruption, electrical surge or a failed migration affecting all connected copies.

Site loss

Fire, flood, burglary, structural damage or loss of every device stored in the same building.

Account failure

A locked cloud account, lost recovery email, subscription lapse, compromised credentials or an unavailable encryption key.

Platform dependency

Service closure, policy changes, reduced image quality, incomplete export or loss of the relationships between image files and catalogue records.

WEAK SEPARATION

Multiple copies, one failure domain

  • Two folders on the same drive
  • Two drives permanently attached to one computer
  • A working folder and a cloud mirror with no version history
  • A NAS and computer in the same room with no off-site copy
  • Encrypted backups whose only key is stored on the encrypted computer

STRONGER SEPARATION

Copies divided by device, location and control

  • Versioned local backup on separate storage
  • Encrypted off-site copy under a separate service or location
  • Offline or immutable snapshot protected from routine deletion
  • Recovery keys stored separately from the systems they unlock
  • Written instructions available to an authorised second person

Baseline architecture

From 3-2-1 to a collector-ready recovery system

The familiar 3-2-1 rule is a minimum: at least three copies, across two storage systems or media, with one copy away from the main location. Modern practice often adds an offline or immutable copy and requires zero unverified errors through restore testing.

3
copies
2
storage systems
1
off-site copy
1
offline or immutable
0
unverified errors
1

Working library

The active image files, edited masters, catalogue database, sidecars and current exports on the main computer or managed storage.

Primary role: Day-to-day access and organised work.

2

Automatic local versioned backup

A separate device or repository that runs regularly and retains earlier states rather than only mirroring the latest folder.

Primary role: Drive failure, deletion, bad edits and catalogue corruption.

3

Off-site encrypted copy

A remote backup service or physically separate drive kept far enough away to escape the same local disaster.

Primary role: Theft, fire, flood and complete loss of the primary site.

4

Offline or immutable snapshot

A disconnected drive, protected snapshot or write-locked copy that routine accounts and connected computers cannot immediately change.

Primary role: Ransomware, account compromise and synchronised corruption.

5

Verification and recovery documentation

Restore tests, checksums, logs, a storage inventory, credentials, encryption recovery and written instructions for another authorised person.

Primary role: False confidence, inaccessible copies and knowledge existing only in one person's memory.

Boundary with Storage and Security

Backup media still require suitable physical storage, periodic replacement and protection from heat, damp, impact and unauthorised access. Those physical questions belong partly to the Storage domain.

Encryption, strong passwords, multi-factor authentication and controlled sharing belong partly to Security. Backup protects availability; it does not by itself prevent disclosure. Creating more copies without access control can multiply the number of places from which sensitive collection information may leak.

Critical sequence

Protect the session before the memory card is reused

The period between capture and verified backup is one of the most vulnerable moments in the life of a photograph. The source card should remain untouched until the session exists safely elsewhere.

1

Capture

Photograph the collectible and leave the files on the camera card or source device for the moment.

2

Copy

Transfer the complete session into the organised working library without changing or deleting the source files.

3

Verify

Confirm file counts, open a sample, check sidecars and, for important records, compare checksums.

4

Protect

Create or confirm a second independent copy and allow the remote or protected backup to complete.

5

Release the card

Reformat or reuse the card only after at least two verified copies exist elsewhere.

Memory cards are transfer media, not archives

Cards and phone storage are designed for capture and active use. They are exposed to accidental reformatting, loss, controller failure, filesystem corruption and device replacement. Leaving the only copy on a card converts a temporary carrier into an unmanaged archive with no integrity checking, indexing or geographic separation.

Collector judgement

Set backup frequency by the amount of work and evidence you can afford to lose

The recovery point objective is the most recent point in time to which the library must be recoverable. It should reflect the rate of change and the significance of the work, not a universal calendar rule.

Occasional collector

A few new photographs each month may justify automatic daily or weekly local backup, daily remote protection and periodic offline snapshots.

Risk question: could the last session be repeated?

Active cataloguer

Large inventory sessions should gain a second verified copy immediately, with the catalogue database protected at least daily.

Risk question: how many hours of classification could disappear?

Dealer or evidence-heavy archive

Current sales, claims and acquisition evidence may need near-continuous local versioning, prompt off-site replication and protected milestone copies.

Risk question: what must be available tomorrow?

Preservation value

Not every image deserves identical treatment

Tiering controls cost without pretending that thumbnails and irreplaceable evidence carry the same consequence.

Highest priority

Treat these as evidence records. Preserve the original file, metadata, context and a protected copy.

  • Irreplaceable condition and unpacking photographs
  • Serial numbers, identifying marks and authenticity details
  • Insurance, provenance and acquisition evidence
  • Pre-restoration and treatment-stage photographs
  • Images of objects later sold, stolen, altered or destroyed

Standard priority

Protect through the routine versioned and off-site system, with enough retention to recover unnoticed mistakes.

  • Routine catalogue views
  • General display and reference photographs
  • Repeatable object photography
  • Ordinary working edits and current exports

Regenerable or temporary

These may receive lighter retention when they can be recreated from protected masters without loss of meaning.

  • Automatically generated thumbnails
  • Temporary web exports
  • Test exposures and rejected setup shots
  • Duplicate social-media versions without unique context

Authoritative files

Protect the master, not merely the most visible copy

A library may contain several forms of one photograph. Recovery becomes unreliable when nobody knows which file is the source, master, working version or derivative.

SOURCE

Camera original

The captured RAW, JPEG or other original file. It should not be overwritten merely because a processed export exists.

MASTER

Preservation or edited master

The highest-quality managed version used for future rendering, correction or evidential reference. Protect it from casual editing.

WORKING

Current edit

A changeable production file that may evolve. Versioning is important because mistakes can remain unnoticed for weeks or months.

OUTPUT

Derivative

A thumbnail, web copy, crop, annotated image or published form. Some are regenerable; others become historical records because of their exact crop, annotations or use.

RAW files require deliberate protection

A JPEG export does not back up a RAW original. RAW files may preserve exposure, white-balance, shadow and sensor information needed for later reprocessing, forensic enlargement or publication. Where camera-specific formats create future-access concerns, retain the RAW alongside a high-quality rendered master and sufficient metadata to explain the processing history.

Complete recovery

Back up the catalogue and meaning, not only the image binaries

A folder of intact photographs can still become an unusable archive when filenames, sidecars, catalogue records, captions and object relationships disappear.

Image files

  • Camera originals, including RAW files where retained
  • Preservation and edited masters
  • Derivatives with unique annotations, crops or historical use
  • Embedded metadata and colour profiles

Context and relationships

  • Catalogue or database files
  • Sidecar metadata and edit instructions
  • Folder hierarchy and stable filenames
  • Links between photographs and individual objects

Associated records

  • Condition reports, receipts and provenance documents
  • Insurance schedules and claim material
  • Presets or configuration needed to reproduce important outputs
  • Exportable metadata in an open, intelligible form

Recovery knowledge

  • Account names and recovery routes
  • Multi-factor recovery codes and encryption keys
  • Software or licence details needed to open the catalogue
  • Instructions for heirs, executors or authorised representatives

Database and image storage may be separate

Collection systems often separate structured records, original images, documents, thumbnails and indexes. A database backup may preserve file references without the image files; an image-directory copy may preserve pixels without the object relationships. A complete recovery test must reconstruct the system rather than prove that one component exists.

Integrity

Verification distinguishes a backup from an assumption

A completed copy job proves that software reached the end of a task. It does not prove that the right files were included, remained unchanged or can be restored on another computer.

COPY CHECK

Verify the transfer

  • Compare file counts and total byte sizes
  • Open representative images
  • Confirm sidecars and hidden files
  • Review warnings and error logs

FIXITY

Detect silent change

A checksum is a calculated fingerprint of file contents. Comparing checksums after transfer and over time can reveal incomplete copies, silent corruption or unexpected alteration. A checksum detects damage; another known-good copy is still required to repair it.

RESTORE TEST

Prove recovery

Restore an individual image, an older version, a complete folder and the catalogue to a temporary location. Check filenames, metadata, RAW readability, object links and the time required. An untested backup is a belief, not evidence.

Do not overwrite every copy when a mismatch appears

A checksum mismatch or damaged preview should trigger investigation. Blindly synchronising the newest file may spread corruption into every repository. Preserve the differing copies, identify a known-good source and document the repair before normal replication resumes.

Recovery planning

Availability has a time dimension

The recovery time objective asks how quickly information must become usable again. A deep cloud archive may be suitable for historical RAW files but unsuitable for an insurance claim or auction listing needed tomorrow.

Immediate access

Current sales photographs, active claim evidence, acquisition records and the working catalogue. Keep locally recoverable or rapidly restorable.

Near-line access

Full collection photography, historical condition records and ordinary reference images. Recovery within hours or a day may be acceptable.

Deep archive

Older RAW sessions, superseded exports and completed project snapshots. Slower retrieval can be reasonable when integrity and documentation remain strong.

Myth versus reality

Common statements that create false assurance

MYTH

The files are on an external drive.

REALITY

That may still be a single copy on a single failure-prone device. A manual drag-and-drop copy also has no inherent version history.

MYTH

They are in the cloud.

REALITY

The service may only synchronise. Deletion, corruption or account compromise can still remove access unless versions, retention and recovery are understood.

MYTH

The NAS uses RAID.

REALITY

RAID improves availability after certain drive failures. It does not normally reverse deletion, ransomware, site loss or database corruption.

MYTH

The photographs are still on the memory card.

REALITY

A card is transfer media exposed to reformatting, loss, controller failure and corruption. It is not a managed archive.

MYTH

The backup runs automatically.

REALITY

Automation improves regularity, but successful-looking logs do not prove that files, metadata and catalogues can be restored.

MYTH

I have thousands of duplicates.

REALITY

Duplicates in one folder, account or synchronised system share the same failure domain. Redundancy depends on independence and recoverability, not file count.

Diagnostic review

Warning signs that require action

Any one of these may justify immediate review. Several together indicate that the library has copies but not a dependable recovery capability.

All important images exist on one device or in one account.

The only backup is permanently connected to the working computer.

There is no copy outside the home, office or collection site.

A synchronised cloud folder is assumed to be a backup without checking version retention.

Memory cards are reformatted before two copies have been verified.

No file, folder, catalogue or full-system restore has ever been tested.

The image catalogue, database, sidecars or metadata exports are excluded from backup.

Passwords, multi-factor recovery codes or encryption keys exist only in the collector's memory.

Drives are unlabelled, undated or have not been connected for years.

Nobody can state which file is authoritative or which copy should be restored first.

Export from the collection platform has never been tested at original quality.

A migration, bulk rename or format conversion is planned without a verified pre-change snapshot.

Action hierarchy

A minimum viable system for a collection currently held in one place

Do not delay basic protection while designing an ideal institutional system. Each step below removes a major class of risk.

1

Consolidate

Bring important originals, masters, catalogues and sidecars into a clearly organised working library.

2

Create a separate copy

Copy the complete library to a labelled external drive or other independent local storage.

3

Automate versioning

Configure regular local backup that retains earlier states and reports failures.

4

Add off-site protection

Use an encrypted remote backup or a securely stored drive at another location.

5

Protect the account

Enable multi-factor authentication and store recovery codes separately.

6

Change the ingestion habit

Keep source-card files until two copies have been verified.

7

Test recovery

Restore several files and the catalogue to a temporary location.

8

Document the system

Record what each repository contains, where it is and when it was last verified.

9

Add a protected milestone

Create an offline or immutable snapshot after important cataloguing, insurance or restoration work.

Control record

Maintain a simple backup inventory

The inventory should identify the role of each repository, not merely list devices. Keep it concise enough to review and update.

RepositoryRoleLocationLast verified
Main computerWorking libraryHomeWeekly
External drive AVersioned local backupHomeMonthly restore test
Remote serviceEncrypted off-site backupRemoteMonthly review
External drive BOffline milestone archiveOff-siteAnnual

Due diligence

Questions to ask before trusting a backup or cloud service

File quality

  • Are the original bytes preserved without recompression?
  • Are RAW, TIFF and sidecar files supported?
  • Are filenames, timestamps, folders and metadata retained on restore?

Versioning and deletion

  • How long are deleted files retained?
  • How many earlier versions remain available?
  • Can a compromised administrator erase all historical copies immediately?

Portability

  • Can the entire library be exported in bulk?
  • Can metadata and object-to-image relationships be exported?
  • Are retrieval delays, egress charges or proprietary formats involved?

Continuity and security

  • Is multi-factor authentication supported?
  • What happens after failed payment, inactivity or death of the account holder?
  • Can ownership or authorised access be transferred without losing the archive?

A platform copy is a layer, not the whole strategy

A collection-management application may store photographs reliably, but the collector should still be able to export original-resolution files, filenames, captions, metadata and the relationships between objects and images. Service closure, account suspension, subscription lapse or incomplete export should not erase the collection's visual record.

Social-media posts, marketplace listings, email attachments and printed contact sheets can provide useful traces after loss. They are not preservation-quality substitutes because they may be compressed, stripped of metadata, scattered or impossible to export in bulk.

High-risk changes

Create a verified snapshot before operations that can alter the whole library

Routine backup protects ordinary work. A deliberate milestone copy protects the state immediately before a consequential change.

Bulk renaming or metadata rewriting

A single incorrect rule can break thousands of filenames or database links.

Format conversion

Wrong quality, colour or metadata settings may silently replace the best files.

Deduplication

Automated tools may remove files that look similar but carry different context or evidential value.

Catalogue or software migration

Image files may survive while links, edits, ratings or captions are lost.

Changing cloud providers

A transfer may flatten folders, alter timestamps or omit historical versions.

Selling, donating or dividing a collection

The milestone may be the final complete photographic record of the collection as assembled.

Migration does not replace redundancy

Moving a library from an old computer to a new one is not a backup when the old source is erased immediately. Preserve the source, copy to the destination, verify completeness and integrity, test the catalogue, confirm independent backups and only then retire the old system securely.

Security and succession

A technically intact archive can still become inaccessible

Recovery depends on accounts, keys, knowledge and authority as well as stored bytes.

Protect credentials and keys

  • Store passwords in a managed password system
  • Keep multi-factor recovery codes separately
  • Back up encryption and recovery keys
  • Document software and licence dependencies
  • Avoid storing the only key inside the archive it unlocks

Make the archive estate-ready

  • Identify the primary library and each backup
  • Explain how objects and photographs are linked
  • State which subscriptions must be maintained
  • Define who may obtain authorised access
  • Record what should be retained, transferred or deleted

Encryption protects access but can create permanent self-lockout

Encryption is appropriate when images reveal addresses, storage locations, serial numbers, security arrangements or financial records. Its benefit depends on recoverable keys. An encrypted backup whose key dies with the collector is effectively a destroyed backup.

Specialist threshold

When informal household backup is no longer enough

A more formal preservation design is justified when the consequences of loss exceed the collector's ability to reconstruct or absorb them.

  • The photographs support high-value insurance schedules or active claims.
  • The archive documents museum-quality, unique or culturally significant objects.
  • A business depends on rapid access to image files and catalogue records.
  • The library contains large volumes of RAW, TIFF or video material.
  • Several people can edit, delete or administer the repository.
  • The collection system uses proprietary databases or complex integrations.
  • Legal, privacy or contractual obligations affect retention and deletion.
  • Repeated corruption, failed restores or unexplained file differences have appeared.

At this threshold, specialist input may be warranted for immutable storage, geographic replication, formal retention policies, automated fixity monitoring, role-based permissions, disaster recovery and documented restoration exercises.

Periodic review

Digital storage requires active management

No device, connector, software licence, file format or cloud service should be assumed to remain usable indefinitely.

Every routine review

  • Check the last successful backup and investigate warnings
  • Confirm available capacity and retention status
  • Restore a small sample to a temporary location
  • Verify that new folders and catalogues are included

At major milestones

  • Create a dated offline or immutable snapshot
  • Record checksums for evidence-grade records
  • Update the repository inventory
  • Confirm off-site access and recovery credentials

During annual review

  • Read older drives and inspect storage health
  • Review obsolete connectors, formats and software dependencies
  • Test a broader restoration on a replacement device
  • Update estate and succession instructions

Before retiring storage

  • Migrate files to supported media
  • Verify file counts, metadata and checksums
  • Confirm at least two independent current copies
  • Dispose of the old device securely after approval

Key takeaways

  • Backup is a recovery capability, not the act of making one extra copy.
  • Redundancy depends on separation across failure domains: device, account, location, control and human knowledge.
  • Synchronisation, RAID, social media and collection platforms can be useful layers, but none is automatically a complete backup.
  • Preserve originals, masters, metadata, catalogue relationships and the credentials needed to restore them.
  • Versioning, checksums and restore tests protect against corruption and mistakes that many copies might otherwise reproduce.
  • Evidence-grade and irreplaceable photographs deserve stronger protection than regenerable derivatives.
  • A resilient archive must remain understandable and accessible after migration, service failure, incapacity or death of the collector.

The deeper principle is simple: the photographic record should not remain more fragile than the collectible it was created to document. A good system preserves the image, its quality, its context, its integrity and the practical knowledge required to recover it.

Continue learning

Related topics