Website Backups: What to Keep and How to Test Restores
By CodexierPublished 6 min read
Almost every website has a backup. Far fewer have a backup that has ever been restored, which is the only kind that counts. The gap shows up on the worst possible day: after a hack, a failed update or a hosting error, when the archive turns out to be incomplete, infected or from the wrong site. This guide sets a routine that closes the gap in an hour a quarter.
What to back up: files, database, email
| Component | What it contains | Common mistake |
|---|---|---|
| Files | CMS code, theme, plugins, uploaded images and documents | Backing up code but not the uploads folder, which holds every image |
| Database | Pages, posts, users, orders, settings | Taking file and database backups at different times, so they do not match |
| Mailboxes, if hosted with the site | Assuming the host backs up mail; many do not | |
| DNS and domain | Records, registrar login, renewal dates | Nobody has a copy of the DNS zone when the host disappears |
| Configuration | Environment variables, API keys, SSL, cron jobs | Restoring the site and finding payments and email are broken |
Frequency and retention
Frequency follows how often the site changes; retention follows how long a problem can go unnoticed. A shop taking orders needs a backup at least daily and ideally more often for the database, because every order between backups is lost on restore. A brochure site updated monthly can back up weekly. Retention is the one people get wrong: a hack discovered after three weeks is useless to fix with seven days of history.
- Active site or shop: daily full backup, database every few hours if orders matter, ninety days of history.
- Standard company site: daily or weekly, thirty to sixty days of history.
- Before every update or deploy: a manual snapshot, kept until the change is confirmed stable.
Retention also has a GDPR side. Backups contain personal data, so a retention period is also the period during which deleted customer data still exists somewhere. Keep it as long as the risk of a late-discovered problem requires, document the period, and no longer.
Storing copies off-site
A backup stored on the same server, or in the same hosting account, protects against a bad update and nothing else. If the account is compromised, suspended or the provider fails, the backup goes with it. The rule is at least one copy in a place with different credentials and a different provider.
Host's own backup
Convenient and fast to restore. Use it as the first line, but read the terms: how many days, whether it includes the database and email, and whether you can download a copy.
Plugin or platform backup to cloud storage
The CMS pushes archives to an object store or drive you control, with its own login. This is the off-site copy for most small sites.
Periodic download
A quarterly manual download to company storage, held by the owner of the routine. Slow, but immune to every automated failure above, and it doubles as the restore test material.
The quarterly restore test
This is the whole point of the article. A restore test takes a backup you did not make specially, restores it to a staging environment or a temporary subdomain, and checks that the result is a working site. It answers the questions that only an incident would otherwise answer:
- Pick last week's backup, not today's, so you test the routine and not a fresh copy.
- Restore files and database to a test environment; note how long it takes and what steps were unclear.
- Open the site: home page, a product or service page, the admin login, a form submission, an image that was uploaded recently.
- Check that configuration came with it: email sending, payment sandbox, integrations.
- Write down what failed, fix the routine, and record the date and result somewhere the owner and the management can see.
The first test almost always finds something: a missing uploads folder, a database from a different date, an archive that will not unpack. Finding it in a quiet hour is the entire value. It is also the test we run inside our monthly maintenance package, because a maintenance plan without a restore test is a plan that hopes.
Who owns the routine
Backups fail for organisational reasons more than technical ones: the plugin licence lapsed, the storage filled up, the person who set it up left. Assign an owner by name, give them a checklist and a calendar reminder, and have someone else confirm the quarterly result. If the owner is an agency or a maintenance provider, ask for the restore test date and result in writing; the answer tells you a lot about the provider.
When you do not need a maintenance plan for this: a small site on a reputable managed host with daily backups, thirty days of retention and a one-click restore you have tried once needs only the quarterly test and an off-site copy, which you can do yourself. A plan pays for itself when the site takes orders or leads every day, when nobody in the company will reliably do the test, or when the site has already had one incident. Our package price is on the pricing page; what to do if the incident has already happened is in the hacked website guide, and if you want us to check your current backup setup, book a short call.
Frequently asked questions
Does my web host back up my website?
Usually something is backed up, but check what and for how long: many hosts keep only a few days, some exclude databases or email, and some backups exist for their own disaster recovery rather than for you. Ask for the retention period and whether you can download a copy, then add your own off-site backup regardless.
How often should a website be backed up?
As often as you can afford to lose changes. A shop or a site collecting leads daily needs daily backups with the database more often. A site updated monthly can back up weekly. Always take a manual snapshot before updates or deploys.
What is a restore test and how long does it take?
Restoring an existing backup to a test environment and checking the site works: pages, admin login, forms, images, integrations. The first time takes an afternoon because it finds problems; after that, about an hour a quarter. It is the only way to know a backup is real.
Not sure your backups would actually restore?
Tell us your host and setup in a fifteen-minute call. We will say what is probably missing, whether you can fix it yourself in an afternoon, and what our maintenance package would cover.
Book a free 15-minute call