Ask a business owner who backs up their website and the answer comes fast: “the hosting company does that.” Ask what happens if the site goes blank tomorrow afternoon and the answer slows down. Most people have never tested the assumption, and it is doing a lot of work.

Your website is usually the largest marketing asset you own outright. It holds years of pages, photos, forms, and search rankings you paid for. Treating it as something your host quietly handles is like keeping your only copy of the company books in a warehouse you rent. Probably fine. Not a plan. Our own site runs on WordPress, so this is not theoretical for us either.

Your Host Backs Up Their Server, Not Your Website

Hosting backups are real. They are built for a different purpose than yours. Your host is protecting their infrastructure so that if a drive fails or a data center has a bad night, they can bring customers back online. Your site rides along.

The WordPress Advanced Administration Handbook puts the limitation plainly. It notes that most hosts back up the entire server, including your site, but that it takes time to request a copy from their backups, and a speedy recovery is critical. Its conclusion is direct: you need to learn how to back up your own site files and restore them.

There are practical gaps too.

  • The copy lives with the problem. If your account is suspended or a billing dispute puts hosting on hold, the backups sit on the other side of the door you just got locked out of.
  • Restoring is often all or nothing. Many host restores roll the whole site back to a point in time. If you only need one deleted page, you may trade last week’s form submissions to get it.
  • You do not control retention. Whatever window the host keeps is the window you have. A problem noticed five weeks late may be older than the oldest copy.
  • You are in their queue. A restore request is a support ticket, and on a bad day you are not the only one filing one.

Keep the host backups as a useful first layer. Just stop treating them as the answer, the same way we argue about depending on any single platform in The Cloud Can Go Down: What That Means for Your Business.

What a Complete Website Backup Actually Includes

This is where most do it yourself backups fall apart. The WordPress Advanced Administration Handbook describes two parts to backing up a WordPress site, the database and the files, and states you need both to fully restore a typical site. The halves hold very different things.

  • The database is the words. The handbook describes it as holding posts, pages, comments, and settings. It is not a folder you can drag somewhere. It has to be exported, and the handbook notes that restoring an export still requires importing it back into the database system.
  • The files are everything else. The handbook describes WordPress files as what sits in your WordPress directory on the web server, including WordPress core, themes, plugins, uploads, wp-config.php, and .htaccess. Your photos and your theme customizations live here.
  • Configuration counts as content. The handbook names wp-config.php and .htaccess specifically. Both are small and hidden, easy to skip, and they carry settings a rebuilt site needs.

The handbook is explicit that a database backup does not include your WordPress files. Half a backup restores half a website: text with no images or theme, or design with no content. Get both, in the same run, on the same schedule.

Where the Copies Live and How Often to Make Them

A backup sitting on the same server as the website is not a second copy. It is the same copy twice, in the same building.

The WordPress Advanced Administration Handbook recommends keeping several recent backups, at least three to five, in different locations: one on your hosting server, one on cloud storage such as Google Drive or Dropbox, and one downloaded to your local computer. The specific services do not matter. What matters is that one copy sits somewhere your hosting account cannot reach or take down with it.

The same handbook ties frequency to how much the site changes, suggesting weekly backups for smaller sites with fewer posts and daily backups for high activity sites. The honest test is simpler: how much work are you willing to redo? Publishing twice a month, weekly is plenty. Taking orders or bookings, daily is the floor, because a week of lost submissions cannot be retyped.

One more thing. Whatever cloud account holds your offsite backup needs multi factor authentication. A backup archive is a full copy of your business website sitting in a personal storage account, exactly the kind of quiet target we describe in why cybersecurity is no longer optional for mid sized businesses.

A Backup You Have Never Restored Is a Guess

Here is the uncomfortable part. Almost nobody tests. Backups run for years, a green checkmark appears nightly, and the first restore anyone attempts is during a real emergency, the worst possible time to discover the archive has been skipping the uploads folder since spring.

Test on a staging copy. A staging site is a duplicate of your website living where the public cannot see it, and most hosting plans include one or will create one on request. Restore your backup onto it, then look at it like a customer would.

  1. Does the site load at all? A blank page or a database connection error means you have half a backup.
  2. Do the images appear? Missing photos usually mean the uploads folder was excluded, the most commonly skipped piece.
  3. Is your recent content there? Check the newest page you published against what restored.
  4. Do the forms and checkout work? Submit one. The parts that make money deserve a real test.
  5. How long did it take? Write it down. That number is your real recovery time, and the only honest answer to “how fast can we be back up.”

Do this twice a year. Put it on the calendar like an oil change.

The Habit to Build Before Any Big Change

Scheduled backups protect you from disasters. A different habit protects you from Tuesday.

Most website damage is not dramatic. A plugin update breaks the contact form. A theme change wrecks the phone layout. A contractor edits the wrong file. Nobody notices for a week, and by then nightly backups have rotated the good version out.

So take a manual backup right before anything significant: updates, a redesign, a new plugin, a developer starting work. The WordPress handbook makes the same point about the database, strongly recommending a backup at regular intervals and before an upgrade. Label it with what you were about to do, and keep those change point copies longer than routine ones.

If you hire someone to work on the site, put this in writing. Your backup runs before their work starts, taken by you, stored where you control it. Good contractors expect that question.

The Bottom Line

Owning a backup means restoring your website without asking permission. Keep the host’s backups as a convenience, then run your own on top: files and database together, at least one copy somewhere your hosting account cannot touch, on a schedule matching how often the site changes. Restore onto a staging copy twice a year so you know it works and how long it takes. Take a manual copy before every meaningful change, because quiet breakages cause more grief than dramatic ones.

None of this is expensive. It is just something nobody owns until the day it matters.

If you are not sure what your website backups contain, or whether anyone has restored one, that is worth an hour of someone’s attention. Harrison Ward Technology helps small and mid sized businesses across Denton County set up backups they control, test the restore, and document who does what when something breaks. Contact us today


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).