Quick answer: A business website should have file and database backups, offsite copies, enough retention, periodic restore testing and a clean backup after each major incident.
Backup is not only for outages. It helps recover from failed updates, accidental deletion, malware, hosting issues and design mistakes.
This article connects with WordPress backup and restore after malware and the WordPress malware and error repair service cluster. The goal is to help business owners understand what requires immediate action, what needs technical handling and what evidence should be delivered afterward.
Quick checklist
| Website type | Suggested retention | Note |
|---|---|---|
| Brochure site | 7-14 days | Back up before major updates |
| Lead/form site | 14-30 days | Test forms and email after restore |
| WooCommerce | 30 days or more | Protect orders and customer data |
| Previously infected site | 30 days + clean offsite copy | Do not trust unverified backups |
| Ad-driven landing pages | 14-30 days | Back up before tracking or landing page edits |
Backups must include files and database
Files contain themes, plugins and uploads; the database stores posts, settings, users, orders and form data. Partial backup is rarely enough.
Retention must exceed detection time
If malware is discovered after two weeks but backups are kept for only seven days, the clean copy may already be gone. Retention should match business importance.
Offsite backup prevents total loss
Backups stored on the same hosting can disappear with hosting failure, accidental deletion or compromise. Keep at least one copy outside hosting.
Restore testing matters more than backup count
Many backups are not useful if nobody has tested restore. Test whether files are complete, database matches, forms work and the site does not break.
Create a clean backup after incidents
After malware cleanup or a major fix, create and label a new clean backup. It becomes a trusted recovery point.
Assign ownership
A backup policy should define who checks, who receives alerts, who restores and who confirms the site works after restore.
Practical scenario
A website keeps only seven days of backups, but SEO spam began more than two weeks earlier. By the time the issue is discovered, every recent backup already contains junk URLs. Retention must exceed likely detection time, and a clean offsite copy should be created after incidents.
When should this be treated as a serious incident?
If the site has customer data, orders, active ads, Google warnings, hosting spam alerts or repeated failures after a fix, handle it as an incident rather than isolated small errors.
When should you involve IT Systems?
Involve IT Systems when the business does not know which backup is clean, has never tested restore, or needs a backup schedule based on site criticality.
Related articles in this cluster
- Strange admin users after a hack
- Choose a WordPress malware cleanup provider
- WordPress security monitoring
- Errors after plugin/theme/core updates
- Monthly WordPress maintenance checklist
Connection to long-term operations
For lead, ecommerce or ad-driven sites, combine this with WordPress maintenance and WordPress security services to reduce recurring risk.
FAQ
Is daily backup enough?
Frequency alone is not enough. Retention and restore ability matter.
Should I back up before plugin updates?
Yes, especially on lead, ecommerce or ad-driven sites.
Is hosting backup enough?
Not by itself. Keep an offsite copy.
How often should restore be tested?
At least quarterly, after major changes and after malware incidents.
Need a WordPress website check?
IT Systems reviews WordPress errors, malware, backups, security and maintenance with a clear business workflow.




