A website backup is a complete copy of everything needed to rebuild a website, normally the site’s files and its database, saved somewhere other than the live server so it can be restored if the site breaks, is hacked or is accidentally damaged. A backup only counts if it can actually be restored.
How website backups work
A typical WordPress site has two parts. The files include WordPress itself, the theme, plugins and the uploads folder with every image and PDF you have added. The database holds pages, posts, settings, user accounts, form entries and orders. A full backup captures both at the same moment. Back up only the files and you lose your content; back up only the database and you lose every image.
Backups are taken by your host, by a plugin, or by an external service that connects to the site. Each run is either full or incremental, copying only what changed since last time, which is faster and uses less storage on large sites. The backups are then kept for a set period, perhaps 30 days of daily copies plus monthly ones for longer.
A widely used rule of thumb is 3-2-1: three copies of your data, on two different types of storage, with one kept off-site. For a small business website, that usually means the live site, the host’s backups and an independent copy in separate cloud storage.
Why it matters for a UK business
Sites break for unglamorous reasons: a plugin update conflicts with the theme, a developer runs a search-and-replace on the wrong table, the hosting company has a hardware failure, or malware spreads through every file. Without a recent backup, recovery means rebuilding pages by hand. With one, it is often a matter of an hour or so.
Backups also carry legal obligations. If your site stores enquiries, orders or newsletter sign-ups, the backups hold personal data too, so UK GDPR applies to them. Keeping years of old backups can conflict with your data retention policy. When someone asks you to erase their data, the ICO’s guidance accepts that it may not be possible to remove one person from a backup straight away, but the data must be put beyond use, and must not be brought back into live systems if you restore.
Common mistakes
- Backups on the same server. If the server fails or the hosting account is compromised, the backups go with it.
- Never testing a restore. Corrupted or incomplete archives are discovered at the worst possible moment.
- Backing up an infected site. If malware has been present for weeks, every recent backup contains it. Keep older copies, and run a malware scan before restoring.
- Backup files left in a public folder. An archive in a web-accessible directory can be downloaded by anyone who guesses its name.
- Infrequent backups on busy sites. A shop taking orders daily cannot afford a weekly schedule.
How to act on it
Check what your host already does: how often, how long it keeps copies, where they are stored and whether restoring costs extra. Add an independent backup to separate storage that your business controls. Match frequency to how often the site changes: daily for shops and booking sites; weekly is often enough for a brochure site. Then restore a copy onto a staging site to prove it works.
Finally, write your backup retention period into your data retention policy so the two agree. A fresh, tested backup is also the first step before any redesign or host move, and it is the first thing I confirm when planning website migration SEO work.
