The 12-point website backup checklist
Twelve checks that show whether your website backups will really save you: where they live, what they hold, how long they last and when they were last tested.
Why backups fail without anyone noticing
Most people have backups until the day they need one. The usual ways they fail are dull, and they are all common.
- The backup lives on the same server as the site. If the server fails, is wiped or is compromised, the backup goes with it.
- It is incomplete. Many tools copy the files but not the database, or the database but not the uploads. A site needs both.
- It has never been restored. A backup that has not been tested is a hope. Corrupt or empty backups are discovered at the worst possible moment.
- It is not kept long enough. If a site was infected three weeks ago and you only keep seven days, every backup you have is already infected.
- It stopped, and nobody was told. A full disk, an expired key or a changed password can stop backups for weeks.
What the twelve points check
The list below groups the questions you should be able to answer yes to: where the backup is stored, what is in it, how many versions are kept and for how long, who is alerted when one fails, and when someone last proved it restores. Each point is a plain yes or no.
How to run a restore test in about half an hour
- Ask for the most recent backup, or find it in your backup tool or host panel.
- Restore it to a separate place, not over your live site. A staging copy or a fresh test area is fine.
- Open the restored site. Check the home page, two inner pages, an image and a search or menu.
- Test a form and the admin login on the restored copy.
- Write down how long it took and anything missing. Delete the test copy when you are done.
If you cannot do this, ask your host or maintainer to do it and send you the result. If nobody has ever done it, that is your answer to point eight.
What good looks like
A sound setup keeps the backup away from your hosting server, encrypted, covering both files and database, with several versions kept long enough to get behind a slow infection, with an alert when one fails, and a restore test on a schedule. That last part is the one most setups lack.
A plugin, your host, or someone who owns it
A backup plugin that copies to the same server is better than nothing and is not enough on its own. Host backups are useful, but check how long they are kept and whether you can restore a single day without help. What matters is not the tool, it is that a named person owns the job and proves it works.
Our plans keep backups off your hosting server, encrypted, and test a restore every month. How often they run and how long they are kept depends on the plan, and the pricing page lists each. The checklist is below.
Most people have backups until the day they need one. Use this list with your host, your developer or your maintenance provider. Each point is a yes or a no, and every no is something to fix this month.
Where your backups live
- They are stored away from your hosting server. A server failure, a hack or a suspended account should not be able to take the backups with it.
- They are encrypted. A backup holds your customers' details, so it should be locked, not just copied.
- You know who can reach them. You can name the people with access and you know where the logins are kept.
What is copied
- The site files are included. Themes, plugins and the code that makes the site work.
- The database is included. Your pages, orders, users and settings live here, not in the files.
- Uploads and media are included. Images, documents and anything your visitors can download.
When and for how long
- Backups run on a schedule you can name. Daily for a store or a busy site, weekly at the very least for a quiet one.
- You can go back at least 30 days. A problem is often noticed weeks after it happened.
- A fresh backup is taken before every update or big change. So there is always a way back to the moment before it.
Proof that it works
- A restore has been tested in the last 30 days. Taking a backup and restoring one are different jobs. Only the second proves anything.
- Someone has written down how to restore. Including who to call and what they need from you.
- You receive a report that shows the result. If nothing tells you a test happened, assume it did not.
How did you score?
10 to 12 yes answers: you are well covered. 7 to 9: there are gaps to close this month. Fewer than 7: treat it as urgent, because a failure today could leave you unable to recover.
Every plan from WebXSentry covers these twelve points: encrypted backups away from your server, both files and database, 45 to 60 days of history, a recent backup confirmed before updates, and a restore test every month with the result in your report. See how our backups work.
Free checklists for every country
These checklists apply wherever your business is. Pick your country to see how we work with your time zone.
Ready when you are.
Tell us what your website needs. A real person replies by your next business morning, Eastern time, with how we would handle it and which plan fits.
- From $99/mo with hours included
- Month to month
- 30-day money-back guarantee
More free checklists: The website maintenance checklist: daily, weekly, monthly, quarterly and yearly · The WordPress update checklist (one page) · New to the terms? Read the glossary, or compare your options.
Straight answers
About this checklist
How often should a website be backed up?
As often as the site changes. A site that rarely changes can be backed up daily; a store taking orders needs its database backed up more often.
Where should backups be stored?
Away from the website's own server, and ideally in more than one place, so a server failure or a hack cannot take the backups with it.
How do I know a backup actually works?
Restore it to a separate copy of the site and check the pages, forms and checkout. A backup that has never been restored is an assumption.