Website Backups: What a Proper Backup Strategy Looks Like
Having backups and being able to recover are different things. Here is how to make sure you have the second.

Short answer
A proper website backup strategy backs up both files and database automatically, at a frequency matched to how often the site changes, stores copies somewhere other than the hosting account, keeps at least 30 days of history, and is proven by regularly restoring a backup to a staging copy. Untested backups are an assumption, not a plan.
A proper website backup strategy is not "the host does backups". It is a short set of decisions: what gets backed up, how often, where the copies live, how long they are kept, and how you know they can be restored. Get those five right and a hack, a failed update or a deleted page becomes an inconvenience rather than a crisis.
The fifth one — proving a restore works — is the one almost everyone skips, and it is the only one that tells you whether the other four worked.
What needs backing up?
A WordPress site is two things that must be backed up together:
| Part | What it contains | Changes when |
|---|---|---|
| Database | Pages, posts, settings, users, form entries, orders | Every edit, order, comment or sign-up |
| Files | WordPress core, themes, plugins, uploaded images and documents, wp-config.php | Updates, uploads, code changes |
A database backup without the files, or the reverse, is not a complete recovery. WordPress core, plugins and themes can be reinstalled from their sources, but your uploads, custom code and configuration cannot.
Beyond the site itself, keep a record of:
- DNS records — a screenshot or export of every record at the registrar or DNS provider. Losing these is how email stops working after a migration.
- Logins and licence keys — in a password manager, not in the site.
- Third-party configuration — form integrations, payment gateway settings, analytics IDs.
For a static or Next.js site, the code should already live in version control, so the backup focus shifts to any database, content management system or uploaded media the site depends on.
How often should you back up?
Match the frequency to how much change you could afford to lose. That figure — how much recent work you are prepared to redo — is the whole basis for the decision.
| Site type | Sensible frequency | Why |
|---|---|---|
| Brochure site, edited monthly | Daily | Cheap, and catches the occasional edit |
| Lead generation site with form entries stored | Daily, plus before every update | Form entries are hard to recreate |
| Blog publishing several times a week | Daily | Content is the asset |
| WooCommerce shop | Several times a day, or real-time database backups | A day of lost orders is a day of lost revenue and customer records |
| Membership or booking site | Several times a day | User data and bookings change constantly |
Separately from the schedule, take a manual backup immediately before any update, migration or significant change. That is the backup you are most likely to need.
Where should backups be stored?
Not only on the same server as the site. If the server fails, the account is suspended, or an attacker gets in and deletes everything they can reach, backups stored alongside the site go with it.
The widely used 3-2-1 rule is a good guide:
- 3 copies of the data (the live site plus two backups)
- 2 different types of storage
- 1 copy off-site, somewhere the hosting company does not control
In practice, for a small business site that usually means: the host's own daily backups as the first layer, plus a backup plugin or service sending copies to independent cloud storage such as Amazon S3, Backblaze B2, Google Drive or Dropbox. Use separate credentials for that storage, so a compromised website cannot delete its own off-site backups.
How long should backups be kept?
Problems are often discovered late. A hack can sit quietly for weeks; a page deleted by mistake might not be missed for a month; a plugin can corrupt data gradually. If you only keep seven days of backups, all seven might contain the problem.
A sensible retention pattern:
| Backup type | Keep for |
|---|---|
| Daily | 30 days |
| Weekly | 3 months |
| Monthly | 12 months |
| Pre-update manual | Until the next one, at least |
Storage is cheap for most small sites. A short retention period is rarely a cost decision; it is usually just a default nobody changed.
How to test a restore
A backup you have never restored is a hope. Testing proves three things: the backup is complete, it is not corrupted, and someone knows the restore procedure before they need it under pressure.
- Create a staging site — most managed hosts offer one, or use a subdomain with search engines blocked.
- Restore the most recent backup to staging using the same tool and process you would use in an emergency.
- Check the site loads, including pages, images and the admin area.
- Check recent content is there — the last post, the last order, a recent form entry.
- Note how long it took. That is your real recovery time, and it is worth knowing before an outage.
- Delete or lock the staging copy afterwards if it contains personal data.
Monthly is ideal for a site that earns money; quarterly is the minimum. The WordPress maintenance monthly checklist puts the restore test alongside the other monthly jobs.
Two numbers worth knowing
IT teams talk about two measures, and they are useful at any size:
- Recovery point — how much data you could lose. Daily backups mean up to a day.
- Recovery time — how long until the site is back. Your restore test tells you this.
Say a shop takes orders through the evening and backs up at 2am. If the server fails at 9pm, up to 19 hours of orders exist only in emails and the payment provider's dashboard. Whether that is acceptable is a business decision. If it is not, the backup frequency needs to change — not the hope that it will not happen.
Website backup tools: plugin, host or service?
| Option | Pros | Cons |
|---|---|---|
| Host backups | Automatic, no setup, fast restores | Tied to the host; retention often short; lost if the account goes |
| Backup plugin (e.g. UpdraftPlus) | Cheap or free, sends to your own cloud storage | Runs on the same server, so a very large site can strain it; configuration is on you |
| External service (e.g. BlogVault, Jetpack VaultPress Backup) | Stored off-site by design, often with one-click restore and staging | Monthly cost; another account to manage |
Most small business sites are well served by host backups plus one off-site tool. Running three backup plugins at once does not triple the safety; it slows the site and multiplies the configuration to check.
Signs your backups are not working
Backups fail quietly. Watch for:
- backup notification emails that stopped arriving and nobody noticed
- backup files that are suspiciously small, or the same size every day on a site that changes
- a plugin that reports success but whose off-site storage connection expired months ago
- off-site storage that has hit its quota, so new backups are silently skipped
- backups that exclude the uploads folder to save space
Each of these is caught by a restore test. None of them is caught by looking at a dashboard that says "last backup: successful".
Backups and personal data
Backups contain everything the site contains, including enquiries, customer accounts and orders. Under UK GDPR, that data needs the same care as the live site: stored securely, kept no longer than necessary, and accessible only to people who need it. Use storage with encryption and strong access controls, and do not leave old staging copies full of customer data lying around. UK website legal requirements covers the wider data protection picture.
Where this fits
Backups are the safety net under everything else in website maintenance. They are what makes it safe to update WordPress, what turns a hacked site into a recoverable one, and what you lean on when choosing or changing hosting.
If you would rather someone else ran the backups and proved the restores, that is a core part of the website maintenance service, where restores are tested to staging on a schedule.
Worked examples
Related services
Related reading
Maintenance & Security
Website Maintenance: The Complete Guide for Business Owners
What keeping a business website healthy actually involves, which jobs matter most, and how to decide who should do them.
Maintenance & Security
How to Fix a Hacked WordPress Site
A calm, ordered recovery plan for a compromised WordPress site — including the step most clean-ups miss, which is why so many sites get re-hacked.
Maintenance & Security
How to Update WordPress Safely (Core, Plugins, Themes)
Updates fix security holes and occasionally break sites. This is the routine that gets you the first without the second.
Maintenance & Security
Choosing Web Hosting for a UK Small Business
Hosting decides your site's ceiling on speed and reliability. Here is how to pick it on substance rather than the first-year price.
