My Actual Backup System When a Card Fails in the Field
A memory card failing mid-shoot is one of the few problems in adventure photography that has no creative workaround. There's no reshooting a moment that's already passed, no salvaging a corrupted file through skill or effort in the moment. The only real protection is a backup system built in before the failure happens, not a plan improvised after.
Here's what my actual backup system looks like in the field. If you want the full system I use for protecting a shoot from end to end, it's part of a bigger framework in The Adventure Travel Photographer's Playbook.
Redundancy Starts Inside the Camera
The first layer of protection happens before a card ever has the chance to fail catastrophically: shooting with dual card slots set to write simultaneously, so every frame exists in two places from the moment it's captured. This is the single most effective piece of the entire backup system, because it removes the most common failure point, a single card corrupting or failing, before it can ever become a real problem.
I treat this as completely non-negotiable on any shoot where the images actually matter, which in practice means essentially every shoot. The redundancy costs nothing in terms of workflow, it happens automatically once it's configured, and it's quietly prevented what would have been genuinely serious losses more than once without ever becoming a dramatic story, because nothing actually went wrong once the second copy existed.
Card quality itself is part of this first layer too. I use cards from manufacturers with a strong reputation for reliability rather than the cheapest available option, since the cost difference is small relative to the value of what's actually being recorded. A card failure is one of the few gear problems that can genuinely erase irreplaceable work, which makes this one of the easier places not to cut corners in a gear budget.
I also rotate cards out of active use once they've accumulated a meaningful amount of write cycles, rather than running the same handful of cards indefinitely. Card failure risk isn't purely random, it increases with wear, and treating cards as a consumable with a working lifespan rather than a permanent piece of gear is a small habit that meaningfully reduces the odds of a failure happening at all.
Redundancy Beyond the Camera
Once a card is full or a shooting session ends, the next layer of the system kicks in: getting footage off the original cards and onto at least two separate physical drives as soon as realistically possible. On a shoot with reliable access to power and time, this happens the same day, often the same night, rather than being allowed to accumulate across multiple days.
I never format or clear original cards until I've confirmed that the backup copies are verified and complete, not just copied. A copy that appears to have transferred but actually failed partway through is arguably worse than no backup at all, since it creates false confidence. Taking the extra few minutes to actually verify a backup, rather than assuming a transfer completed correctly, has caught real problems before they became actual losses.
On longer or more remote trips, I'll add a third layer when logistics allow: uploading to cloud storage when there's a connection available, or physically mailing a drive home from a town along the route if the trip includes any access to postal service partway through. Neither of these is always possible, but when they are, they add meaningful protection against a scenario where something happens to all the physical drives being carried together.
The physical drives themselves get treated with the same seriousness as the cards. I keep backup drives separated from each other during transport whenever practical, rather than packed together in the same bag, so that a single lost or damaged bag can't take out more than one copy of the same footage at once. It's a small logistical habit, but it directly addresses the most likely real-world failure scenario, losing or damaging a single piece of luggage.
What Changes on Bigger or Riskier Projects
On larger productions, this system scales up rather than staying the same. An assistant or dedicated digital technician often handles backups specifically, which means the redundancy process gets more disciplined and more separated from the actual shooting responsibilities, reducing the chance that backup steps get rushed or skipped at the end of a long day.
On projects in genuinely remote locations, where reshooting a missed or lost moment would be extremely difficult or impossible, I'm more conservative about backup timing, prioritizing getting footage onto multiple drives as quickly as possible rather than letting even a day pass with footage existing in only one physical location. The remoteness of a location should directly increase how aggressively backups happen, not just how carefully gear is protected in general.
I also think about backup redundancy differently depending on how replaceable a given piece of footage actually is. A specific weather window, a specific light, a specific access point that won't be available again on that trip gets prioritized for backup ahead of footage that could theoretically be reshot under similar conditions later. That triage only matters when time or power is genuinely limited, but it's worth having a clear sense of priority before that constraint actually forces a decision.
On client projects specifically, I'll sometimes build backup status into my own communication, letting a producer or point of contact know once a day's footage is safely backed up in multiple locations. It's a small thing, but it signals that protecting the work is being taken seriously, which matters on projects where the client has real financial exposure riding on that footage existing.
Why This System Has to Be Boring
The best backup system is one that's boring and consistent, not clever or improvised. Every piece of this system, dual card slots, prompt transfer to multiple drives, verification before clearing cards, additional off-site backup when logistics allow, is deliberately unremarkable. That's the point. A backup system that depends on remembering to do something extra under pressure is a backup system that will eventually fail exactly when it matters most.
I've found that the moments I'm most tempted to skip a step in this process, at the end of an exhausting shoot day, or when a next travel leg is starting early the next morning, are exactly the moments when skipping a step is most likely to actually cost something. Building the discipline to run the full system even when it's inconvenient is arguably more valuable than any individual piece of the system itself.
How I Test This System Before It's Ever Needed
A backup system is only as trustworthy as the last time it was actually verified to work, not the last time it was set up. I periodically test the full chain deliberately, confirming that dual card slots are genuinely writing to both cards correctly, that transferred files actually open and aren't silently corrupted, and that cloud or off-site backups are genuinely accessible rather than just appearing to have uploaded successfully.
I also test my own process under time pressure occasionally, running through the full backup routine as quickly as I reasonably can, the way I'd need to at the end of a long shoot day, to make sure the process actually holds up when I'm tired and rushed rather than only when I have plenty of time and full attention to give it. A system that only works when performed slowly and carefully isn't reliable enough for the conditions it actually needs to survive.
New gear gets tested into the system before it's trusted with real work. A new card, a new drive, a new housing, all get run through a low-stakes test shoot first, confirming the redundancy actually functions as expected, before that piece of gear is relied on for a shoot where the footage genuinely can't be recreated. Discovering a compatibility or reliability issue during a test shoot costs nothing. Discovering the same issue during an irreplaceable shoot costs everything the system was built to protect.
This kind of periodic testing might seem excessive for a system that, when it's working, is invisible and uneventful by design. But that invisibility is exactly why testing matters. A silent failure in a backup system can go unnoticed for a long time precisely because nothing dramatic signals that something's wrong, right up until the moment a card actually fails and the redundancy that was supposed to be there isn't.
What I'd Tell a Photographer Who's Never Had a Card Fail
It's easy to treat a robust backup system as unnecessary overhead when you've never actually experienced a card failure firsthand. I understand that instinct, since building and maintaining this level of redundancy does take real time and discipline, and it can feel like effort spent protecting against a problem that might never happen.
But card failures aren't a rare, freak occurrence in this line of work, they're a predictable eventuality given enough shooting volume, especially in the demanding conditions adventure photography often involves, heat, cold, moisture, dust, and repeated physical jostling that consumer electronics simply weren't designed to handle indefinitely. The question isn't really whether a card will eventually fail, it's whether a real backup exists when it does.
I'd also point out that the cost of building this system, in time and in the modest expense of extra cards and drives, is genuinely small compared to the cost of losing even a single significant shoot's worth of irreplaceable footage. A lost multi-day expedition shoot, or a lost once-in-a-lifetime moment with a client who can't simply be rescheduled, represents a loss that no amount of after-the-fact effort can undo. Measured against that risk, the discipline required to maintain a solid backup system is a genuinely small price to pay.
Documenting the System So It Doesn't Live Only in My Head
One thing I've added over time is a simple written record of exactly what the backup system involves, not just following it from memory but having it documented clearly enough that someone else, an assistant, a digital technician, or even a client's own production team, could pick it up and understand exactly what's supposed to happen and in what order.
This matters for a couple of reasons beyond just my own consistency. On larger productions where someone else is handling backups, a documented process removes ambiguity about what "backed up" actually means, confirming it means verified copies in specific locations, not just files that were dragged into a folder somewhere. It also means that if something happens to me mid-project, illness, injury, an unexpected complication, someone else can step in and keep the redundancy system running without having to reconstruct it from scratch.
Having it documented has also made me more honest with myself about whether I'm actually following my own system consistently, since a written process makes any shortcuts I might take under pressure more obvious, at least to my own reflection afterward, than an informal system that lives only in memory and can quietly bend under fatigue without ever being clearly noticed.
I'd encourage any photographer who hasn't written their own backup process down explicitly to take the time to do it, even if the system currently lives entirely in their head and has worked fine so far. The act of writing it out tends to reveal gaps that weren't obvious when the process was just a set of habits, and it turns something fragile and personal into something durable that can actually be relied on under real pressure.
If I had to boil this entire system down to one underlying principle, it would be this: never let the fate of irreplaceable work depend on a single point of failure, whether that's one card, one drive, one person remembering to do something, or one moment of good luck. Every layer of this system exists to remove exactly one single point of failure from the chain, and the cumulative effect of removing several of them is what actually makes the work safe.
How Client Contracts Sometimes Shape This System
On certain commercial and brand projects, clients have their own specific requirements around data handling, backup redundancy, and delivery timelines that shape how this system gets applied on that particular job. Some larger clients require documented proof that footage was backed up in specific ways, or that certain data security practices were followed throughout a project, which means the backup system sometimes needs to be adapted to satisfy contractual requirements on top of my own standard practices.
I've found it useful to treat these client-specific requirements as an opportunity to stress-test my own baseline system rather than as an unwelcome complication. A client's specific data handling requirement often turns out to be a genuinely good practice worth adopting more broadly, not just for that one project, even after the contractual obligation that originally prompted it has ended.
Reading through a contract's data and backup requirements carefully before a shoot begins, rather than treating that section as boilerplate to skim past, has become a standard part of my pre-project process on any commercial work. It ensures the redundancy system I'm actually running on a given shoot day matches what the client has been told to expect, rather than discovering a mismatch only after something has already gone wrong. That kind of careful alignment between contract and practice has become second nature, but it's a habit worth calling out explicitly for any photographer newer to commercial work, since it's an easy detail to overlook amid everything else a new contract involves, and it's exactly the kind of small oversight that only becomes visible after it's already caused a problem, which is precisely why it deserves deliberate attention rather than being left to chance or good intentions alone, especially on projects where the client's trust and their own budget are genuinely on the line.
Building this kind of redundancy into a shoot from the very start, rather than treating it as an afterthought squeezed in after the actual photography, is one of the least glamorous parts of this job and one of the most important. Protecting the work itself, not just capturing it, is part of the bigger field system I cover in The Adventure Travel Photographer's Playbook.
Reflection Questions
- Do you shoot with dual card slots writing simultaneously, or rely on a single card per shoot?
- How quickly do footage backups actually happen after a shoot, same day or does it accumulate?
- Do you verify a backup is complete before clearing original cards, or assume the transfer worked?
- How does your backup discipline change on remote shoots where reshooting isn't realistically possible?
Dalton Johnson is a professional adventure and editorial photographer with over a decade of experience shooting on all seven continents. His client work includes Patagonia, GoPro, Arc'teryx, Four Seasons, Nike, Rivian, Big Agnes, Ford Bronco, and 160+ other brands. He runs Dalton Johnson Media as a full-service studio, from pre-production through post and distribution.