“A backup runs every night” sounds reassuring, but it does not prove that you can recover quickly after an incident. A backup may be incomplete, damaged, too old or encrypted together with the production server. A dependable strategy therefore describes not only how copies are made, but where they are stored, how long they are retained and how recovery is tested.

The 3-2-1 rule as a practical foundation
The classic 3-2-1 rule means keeping three copies of important data, using two different storage systems or media types and holding at least one copy in another location. For hosting this may combine production data, a fast local backup and an encrypted off-site copy on an independent storage platform.
A copy on the same server is convenient for recovering a deleted file, but it is not enough protection against hardware failure, account compromise or ransomware. Independence is the most important part of “off-site”.
RPO: how much data can you afford to lose?
Recovery Point Objective defines how far back you may need to go. An informational website might tolerate a daily backup. A shop or administration system could lose dozens of transactions in 24 hours, requiring more frequent database backups or continuous replication.
Base the decision on business impact. An RPO of one hour requires different technology, storage and monitoring from an RPO of one day.
RTO: how quickly must the site return?
Recovery Time Objective describes the maximum acceptable recovery time. A backup containing hundreds of gigabytes that must be retrieved from cold storage may not support a 30-minute RTO. Include download time, verification, DNS, configuration and communication. A realistic RTO prevents false confidence.
Retention protects against late discovery
Not every problem is discovered immediately. A faulty import, quiet breach or damaged table may be noticed weeks later. Keep several restore points: perhaps daily copies for a defined period, weekly copies for several months and monthly archives where regulation or business needs justify them.
What should a website backup contain?
- Files, uploads, themes and custom code.
- The complete database, including users, orders and settings.
- DNS, email and server configuration needed for recovery.
- Encryption keys and credentials managed through a separate secure process.
- A concise recovery runbook with responsibilities and contact details.
A restore test is the real proof
Do not stop at a successful task notification. Restore periodically into an isolated test environment, open pages, sign in, submit forms and test the key purchase steps of a shop. Measure the time required and document every manual dependency. This turns an assumption into demonstrable recoverability.
Backups do not replace security
Backups limit damage but do not prevent attacks. Combine them with updates, strong authentication, account isolation, malware detection and monitoring. Protect backup storage with separate credentials and, where possible, immutable retention so an attacker cannot easily erase both production and history.
Would you like to know which backup options are included with your plan or need help with a recovery? Check your plan or contact Gigatech Support.





