Skip to content
Maintenance & Security 6 min read Sajid Aslam

Website Backups: What a Proper Backup Strategy Looks Like

Having backups and being able to recover are different things. Here is how to make sure you have the second.

A website backup strategy showing frequency, off-site storage and retention

Short answer

A proper website backup strategy backs up both files and database automatically, at a frequency matched to how often the site changes, stores copies somewhere other than the hosting account, keeps at least 30 days of history, and is proven by regularly restoring a backup to a staging copy. Untested backups are an assumption, not a plan.

A proper website backup strategy is not "the host does backups". It is a short set of decisions: what gets backed up, how often, where the copies live, how long they are kept, and how you know they can be restored. Get those five right and a hack, a failed update or a deleted page becomes an inconvenience rather than a crisis.

The fifth one — proving a restore works — is the one almost everyone skips, and it is the only one that tells you whether the other four worked.

What needs backing up?

A WordPress site is two things that must be backed up together:

PartWhat it containsChanges when
DatabasePages, posts, settings, users, form entries, ordersEvery edit, order, comment or sign-up
FilesWordPress core, themes, plugins, uploaded images and documents, wp-config.phpUpdates, uploads, code changes

A database backup without the files, or the reverse, is not a complete recovery. WordPress core, plugins and themes can be reinstalled from their sources, but your uploads, custom code and configuration cannot.

Beyond the site itself, keep a record of:

  • DNS records — a screenshot or export of every record at the registrar or DNS provider. Losing these is how email stops working after a migration.
  • Logins and licence keys — in a password manager, not in the site.
  • Third-party configuration — form integrations, payment gateway settings, analytics IDs.

For a static or Next.js site, the code should already live in version control, so the backup focus shifts to any database, content management system or uploaded media the site depends on.

How often should you back up?

Match the frequency to how much change you could afford to lose. That figure — how much recent work you are prepared to redo — is the whole basis for the decision.

Site typeSensible frequencyWhy
Brochure site, edited monthlyDailyCheap, and catches the occasional edit
Lead generation site with form entries storedDaily, plus before every updateForm entries are hard to recreate
Blog publishing several times a weekDailyContent is the asset
WooCommerce shopSeveral times a day, or real-time database backupsA day of lost orders is a day of lost revenue and customer records
Membership or booking siteSeveral times a dayUser data and bookings change constantly

Separately from the schedule, take a manual backup immediately before any update, migration or significant change. That is the backup you are most likely to need.

Where should backups be stored?

Not only on the same server as the site. If the server fails, the account is suspended, or an attacker gets in and deletes everything they can reach, backups stored alongside the site go with it.

The widely used 3-2-1 rule is a good guide:

  • 3 copies of the data (the live site plus two backups)
  • 2 different types of storage
  • 1 copy off-site, somewhere the hosting company does not control

In practice, for a small business site that usually means: the host's own daily backups as the first layer, plus a backup plugin or service sending copies to independent cloud storage such as Amazon S3, Backblaze B2, Google Drive or Dropbox. Use separate credentials for that storage, so a compromised website cannot delete its own off-site backups.

How long should backups be kept?

Problems are often discovered late. A hack can sit quietly for weeks; a page deleted by mistake might not be missed for a month; a plugin can corrupt data gradually. If you only keep seven days of backups, all seven might contain the problem.

A sensible retention pattern:

Backup typeKeep for
Daily30 days
Weekly3 months
Monthly12 months
Pre-update manualUntil the next one, at least

Storage is cheap for most small sites. A short retention period is rarely a cost decision; it is usually just a default nobody changed.

How to test a restore

A backup you have never restored is a hope. Testing proves three things: the backup is complete, it is not corrupted, and someone knows the restore procedure before they need it under pressure.

  1. Create a staging site — most managed hosts offer one, or use a subdomain with search engines blocked.
  2. Restore the most recent backup to staging using the same tool and process you would use in an emergency.
  3. Check the site loads, including pages, images and the admin area.
  4. Check recent content is there — the last post, the last order, a recent form entry.
  5. Note how long it took. That is your real recovery time, and it is worth knowing before an outage.
  6. Delete or lock the staging copy afterwards if it contains personal data.

Monthly is ideal for a site that earns money; quarterly is the minimum. The WordPress maintenance monthly checklist puts the restore test alongside the other monthly jobs.

Two numbers worth knowing

IT teams talk about two measures, and they are useful at any size:

  • Recovery point — how much data you could lose. Daily backups mean up to a day.
  • Recovery time — how long until the site is back. Your restore test tells you this.

Say a shop takes orders through the evening and backs up at 2am. If the server fails at 9pm, up to 19 hours of orders exist only in emails and the payment provider's dashboard. Whether that is acceptable is a business decision. If it is not, the backup frequency needs to change — not the hope that it will not happen.

Website backup tools: plugin, host or service?

OptionProsCons
Host backupsAutomatic, no setup, fast restoresTied to the host; retention often short; lost if the account goes
Backup plugin (e.g. UpdraftPlus)Cheap or free, sends to your own cloud storageRuns on the same server, so a very large site can strain it; configuration is on you
External service (e.g. BlogVault, Jetpack VaultPress Backup)Stored off-site by design, often with one-click restore and stagingMonthly cost; another account to manage

Most small business sites are well served by host backups plus one off-site tool. Running three backup plugins at once does not triple the safety; it slows the site and multiplies the configuration to check.

Signs your backups are not working

Backups fail quietly. Watch for:

  • backup notification emails that stopped arriving and nobody noticed
  • backup files that are suspiciously small, or the same size every day on a site that changes
  • a plugin that reports success but whose off-site storage connection expired months ago
  • off-site storage that has hit its quota, so new backups are silently skipped
  • backups that exclude the uploads folder to save space

Each of these is caught by a restore test. None of them is caught by looking at a dashboard that says "last backup: successful".

Backups and personal data

Backups contain everything the site contains, including enquiries, customer accounts and orders. Under UK GDPR, that data needs the same care as the live site: stored securely, kept no longer than necessary, and accessible only to people who need it. Use storage with encryption and strong access controls, and do not leave old staging copies full of customer data lying around. UK website legal requirements covers the wider data protection picture.

Where this fits

Backups are the safety net under everything else in website maintenance. They are what makes it safe to update WordPress, what turns a hacked site into a recoverable one, and what you lean on when choosing or changing hosting.

If you would rather someone else ran the backups and proved the restores, that is a core part of the website maintenance service, where restores are tested to staging on a schedule.

Worked examples

Related services

Related reading

FAQ

Questions about this

If yours isn't here, send it over — I reply within one working day.

They are a good first layer, not the whole strategy. Host backups usually live in the same company's infrastructure, may only be kept for a short time, and can disappear if the account is suspended or closed. Keep at least one independent copy somewhere the host does not control.

There is no single best one. UpdraftPlus, BlogVault, Jetpack VaultPress Backup and similar tools all work; what matters is that the one you choose sends backups off-site automatically, keeps enough history, and that you have actually restored from it. Pick one, configure it properly, and test it.

At least 30 days for daily backups, and ideally a few monthly copies going back further. Hacks and data problems are often discovered weeks after they start, and you need a backup from before the problem began. Retention is limited mainly by storage cost, which is low for most small sites.

Usually not. Website backups cover the site's files and database. If your email is hosted with Microsoft 365 or Google Workspace, it lives with that provider and needs its own retention or backup arrangement. If email is hosted on the same server as the website, check explicitly whether the host backs it up.