The quickest high-return move for any website owner is to set up automated, frequent backups, keep at least one copy offsite and offline, and test restores on a schedule rather than hoping they work. Follow the 3-2-1 rule: three copies, two storage types, one copy away from your main environment. Lock down backup access with multi-factor authentication and encrypted storage so the copies themselves can’t become the weak point.
TL;DR: A complete backup must include site files, uploads, a full database dump, configuration files, certificates, DNS records, scheduled jobs, and any site related email archives. Match backup frequency to site activity: ecommerce and membership sites need hourly or daily copies, while static portfolios can use daily or weekly schedules. Keep one copy offline or disconnected, secure backup accounts with multifactor authentication, enable versioning, and retain historical versions for at least a month. Schedule regular file level and full site restore tests in a staging environment, record each result, and confirm recovery credentials and keys remain accessible.
TL;DR:
A backup that only saves your web files will not rebuild a working site. Databases hold your content, user accounts and settings, and without a full SQL dump alongside the files, a restore leaves you with an empty shell.
A complete backup set covers:
Keep a separate, off-network note of host logins and support contacts. If your main systems go down, you still need a way to reach the people who can help you recover.
There is no single correct method, only the right combination for how your site changes and what you can afford to lose. Most resilient setups blend two or three of the following.
Mixing an automated daily job with a weekly offsite cold copy covers most of what a small or mid-sized site needs.
How often you back up should follow how often your site changes, not a fixed calendar habit.
Rolling backups overwrite older versions and suit day-to-day recovery, while snapshot archives preserve a fixed point in time and suit ransomware recovery or compliance needs. Match your retention length to how long you’d realistically need to notice a problem and still have a clean copy to restore.
Backups are now a direct target for attackers, not an afterthought. Ransomware that reaches a connected backup system can encrypt your recovery path along with your live site.
Keep at least one backup offline or logically disconnected, and limit the number of systems and credentials with backup access.
That’s the core principle from NCSC’s ransomware-resistant backup guidance, and it changes how you should set permissions. Fewer backup clients and tightly scoped credentials mean fewer paths for malware to spread into your archives.
Encrypt backups both in transit and at rest, and switch on multi-factor authentication for every account with backup or cloud storage access. Favour providers that support versioning or object immutability, since a backup that can be altered or deleted by a compromised account offers no real protection. Spreading copies across genuinely separate locations, rather than two folders on the same cloud account, closes the gap further.
Pro Tip: Give your cloud backup account its own login, separate from your main admin credentials, so a compromised website password can’t cascade into your backup storage.
A backup you’ve never restored is a theory, not a plan. Testing is where most backup strategies quietly fail, often because owners assume the job ran correctly rather than confirming it.
Many organisations only discover a backup is unusable when they try to recover from it during an actual incident, which is precisely the failure mode NCSC’s small organisations guidance flags as common and avoidable. A restore test that fails on a Tuesday afternoon is inconvenient. The same failure during a live outage is a crisis.
Backups fail quietly when no one owns them. Clear roles turn a vague hope into a repeatable process.
NCSC’s guidance for small organisations recommends storing this runbook and an up-to-date contact list off-network, so they’re reachable even if your main systems are down. Rotate who practises the restore occasionally. Knowledge that lives in one person’s head is a single point of failure just as real as a missing backup.
Use this as your starting sequence rather than a wish list.
Pro Tip: Set your first restore test for this week, not next quarter. The gap between “we have backups” and “we know they work” closes the moment you actually try one.
The backup failures we see most often aren’t about missing software. They’re missing database exports inside a “complete” backup, no one assigned to check the job ran, and restore steps that exist only in someone’s memory. Assigning clear roles and testing restores on a fixed schedule shrinks recovery time more reliably than any single tool choice.
— Rob
Setting up a resilient backup regime takes time most business owners would rather spend running their business. We build that regime into our website hosting and IT infrastructure management, so the checklist above becomes something we run on your behalf rather than another task on your list.
As part of ongoing support, we handle:
If you’d rather hand this to a team that already runs it for other sites, get in touch through our website development page and we’ll talk through what your site needs.
GoDaddy’s hosting plans typically include a managed backup option you can enable from the hosting dashboard, but you should confirm it captures your full database alongside files before relying on it alone. Pairing that with a separate offsite copy, such as a cloud storage export, follows the 3-2-1 principle rather than leaving every copy with one host.
Archiving a WordPress site means exporting the full database with a tool like WP-DBManager alongside the wp-content folder, themes and plugins, then storing that archive somewhere separate from the live server. A plugin such as UpdraftPlus can automate this on a schedule so the archive stays current without manual exports each time.
Without a backup, a server failure, hacking incident or accidental deletion can mean permanent loss of your site’s content, orders and customer data, with no way to recover it. NCSC’s ransomware-resistant backup guidance specifically warns that sites with only connected, live backups risk losing every copy at once if ransomware reaches the backup system too.
Export your database as a full SQL dump, copy your site files (themes, plugins, uploads and configuration files) using SFTP or a host’s backup tool, then store both somewhere offsite, ideally with versioning enabled. Test the restore afterwards. A backup is only confirmed once you’ve successfully used it to rebuild the site in a staging environment.
Book a Demo
Forgotten Password
Get your free SEO guide
Thank you, please check your email
Sign into Brainiac Media
Please sign-in using your email address and password.
Forget your Password?
no worries, click here to reset your password.