Skip to main content

Website protection

Website Backups

A backup is useful only if it contains everything required, remains available after an incident and can be restored within the time the business needs.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

Websites can be lost through compromise, human error, failed updates, provider problems or accidental cancellation. Files alone may not contain database content, configuration, uploaded media, DNS information or external service settings.

Recovery objectives make backup decisions concrete: how much recent work can be lost and how long can the service be unavailable? Those answers determine frequency, retention and restore design.

Know the exposure

Common risks

01

Incomplete coverage

A copy may omit the database, uploads, environment configuration, encryption keys or provider settings needed to operate.

02

Shared failure

A backup stored only in the same account, server or credentials can disappear with the live site.

03

Untested recovery

Corrupt archives, missing permissions or undocumented dependencies are often found only when a real restore is attempted.

Investigate, do not ignore

Warning signs

  • Nobody can state what is backed up, how often or for how long
  • The only backup sits on the live server or inside the same hosting account
  • Backup failures do not alert a named person
  • Restoration requires a former developer or undocumented credentials
  • No restore has been tested in an isolated environment

Reduce likelihood and impact

Practical steps

  1. 01

    Define recovery needs

    Agree the acceptable data loss and downtime for the website, forms, orders, accounts and connected services.

  2. 02

    Map everything required

    Include code, databases, uploads, configuration, secrets handling, DNS records and instructions for external dependencies as appropriate.

  3. 03

    Separate copies and access

    Keep multiple copies with suitable off-site or immutable protection and credentials that a compromised website administrator cannot alter.

  4. 04

    Monitor backup jobs

    Send failures, capacity warnings and retention changes to a named owner. Review success reports rather than assuming scheduled means completed.

  5. 05

    Practise a clean restore

    Restore into an isolated destination, verify critical journeys and record the time, missing steps and updated runbook.

Defined website support

How AHANIX can help

AHANIX can help define and test website-level backup and restore arrangements using the capabilities of the chosen platform and providers.

  • Inventory website files, data and provider dependencies in the agreed scope
  • Configure or coordinate an appropriate website backup schedule and destination
  • Run a controlled restore test and document the website recovery steps

Clear limits

What this cannot guarantee

  • Backup success messages do not guarantee that every item is recoverable, current or free from malicious changes.
  • AHANIX cannot guarantee provider availability or business-wide recovery and is not a substitute for organisation-wide continuity planning.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Website backups questions

How often should a website be backed up?

Frequency should match how often important data changes and how much loss the business can tolerate. A frequently updated shop or membership site usually needs a different schedule from a static brochure site.

Does my hosting backup count?

It may be a useful layer, but confirm coverage, retention, access, separation and restore terms. Keep an additional suitably independent route where the business risk justifies it.

Can I restore a backup after a hack?

Possibly, but first establish whether the copy is clean and whether the original entry point has been removed. Preserve relevant evidence and rotate compromised credentials and secrets.

A scoped next step

Know whether your website can actually be restored

AHANIX can map backup coverage, provider dependencies and a practical restore test for the website.

Plan a restore test

Continue in the Security Centre