When a web provider tells you “we back up your site,” it sounds like a finished sentence. It isn’t. That phrase can mean a tested nightly copy you could restore in an hour, or it can mean a folder someone set up once and never checked again. A real website backup plan is the difference between a bad afternoon and a business that never fully comes back.
These stakes are real. In the Verizon 2025 Data Breach Investigations Report, ransomware showed up in 44% of breaches, and CISA warns that without backups, recovery “can take weeks or even months, and it may be impossible.” That is why it pays to know what a maintenance package actually covers before you sign off on it.
What a real website backup plan includes
Start with a plain definition. A backup is a recoverable copy of your files and your database, stored somewhere separate from the live site. If that copy sits on the same server as your website, it is not really a backup, because whatever takes down the site usually takes the copy with it.
From there, a real plan covers four things.
Files and the database, not one or the other. Your site is two parts: the files (design, images, code) and the database (pages, posts, orders, accounts). CISA lists “website and operational databases” among the data every business should back up. Miss the database and you restore an empty shell.
Frequency that matches how often the site changes. A brochure site that updates monthly does not need the schedule of a store taking orders hourly. In practice, backup frequency sets your recovery point, meaning how much data you can afford to lose between copies.
A retention window. One copy of last night is rarely enough, because corruption or a quiet compromise is not always noticed the same day. That is why CISA advises being able to roll back at least seven days. More history means more chances to reach a clean version.
An offsite and offline copy. This is the 3-2-1 rule, widely credited to photographer Peter Krogh: three copies, on two types of storage, with one kept offsite. CISA’s ransomware guidance adds why one copy should stay offline, noting that “many ransomware variants attempt to find and subsequently delete or encrypt accessible backups.”
The step everyone forgets: restore testing
Here is the part that separates a real plan from a false sense of security. A backup nobody has ever restored is not a backup yet. It is a hope.
Restore testing is now part of the standard, not a nice-to-have. NIST’s Cybersecurity Framework 2.0 says backups must be “created, protected, maintained, and tested,” and gives testing restores at least once a year as an example. As a result, a provider who tests restores can tell you the last time one worked and how long it took. That number is your real recovery time, not the one on the sales page.
Questions to ask your provider
You do not need to be technical to check for any of this. Ask these five questions before you buy:
- Do you back up both my files and my database, and how often?
- How long do you keep backups, and how many past versions can I restore?
- Is at least one copy stored offsite and offline?
- How do you test that your backups can actually be restored, and how often do you check?
- If my site went down today, how fast could you have it back, and how much data would I lose?
If a provider answers these clearly, you are in good hands. If they can’t, you have just found the gap before it found you. It is the same instinct behind checking whether a creative team has its systems in order] before you hire them.
Work with The Blue Mango. If you want a partner who treats backups as a tested promise rather than a checkbox, let’s talk.
