Opens in a new tab

Business website backup policy: retention, offsite copies and restore testing

Technician planning a business website backup policy
Technician planning a business website backup policy

Quick answer: A business website should have file and database backups, offsite copies, enough retention, periodic restore testing and a clean backup after each major incident.

Backup is not only for outages. It helps recover from failed updates, accidental deletion, malware, hosting issues and design mistakes.

This article connects with WordPress backup and restore after malware and the WordPress malware and error repair service cluster. The goal is to help business owners understand what requires immediate action, what needs technical handling and what evidence should be delivered afterward.

Quick checklist

Website typeSuggested retentionNote
Brochure site7-14 daysBack up before major updates
Lead/form site14-30 daysTest forms and email after restore
WooCommerce30 days or moreProtect orders and customer data
Previously infected site30 days + clean offsite copyDo not trust unverified backups
Ad-driven landing pages14-30 daysBack up before tracking or landing page edits

Backups must include files and database

Files contain themes, plugins and uploads; the database stores posts, settings, users, orders and form data. Partial backup is rarely enough.

Retention must exceed detection time

If malware is discovered after two weeks but backups are kept for only seven days, the clean copy may already be gone. Retention should match business importance.

Offsite backup prevents total loss

Backups stored on the same hosting can disappear with hosting failure, accidental deletion or compromise. Keep at least one copy outside hosting.

Restore testing matters more than backup count

Many backups are not useful if nobody has tested restore. Test whether files are complete, database matches, forms work and the site does not break.

Create a clean backup after incidents

After malware cleanup or a major fix, create and label a new clean backup. It becomes a trusted recovery point.

Assign ownership

A backup policy should define who checks, who receives alerts, who restores and who confirms the site works after restore.

Practical scenario

A website keeps only seven days of backups, but SEO spam began more than two weeks earlier. By the time the issue is discovered, every recent backup already contains junk URLs. Retention must exceed likely detection time, and a clean offsite copy should be created after incidents.

When should this be treated as a serious incident?

If the site has customer data, orders, active ads, Google warnings, hosting spam alerts or repeated failures after a fix, handle it as an incident rather than isolated small errors.

When should you involve IT Systems?

Involve IT Systems when the business does not know which backup is clean, has never tested restore, or needs a backup schedule based on site criticality.

Related articles in this cluster

Connection to long-term operations

For lead, ecommerce or ad-driven sites, combine this with WordPress maintenance and WordPress security services to reduce recurring risk.

FAQ

Is daily backup enough?

Frequency alone is not enough. Retention and restore ability matter.

Should I back up before plugin updates?

Yes, especially on lead, ecommerce or ad-driven sites.

Is hosting backup enough?

Not by itself. Keep an offsite copy.

How often should restore be tested?

At least quarterly, after major changes and after malware incidents.

Need a WordPress website check?

IT Systems reviews WordPress errors, malware, backups, security and maintenance with a clear business workflow.