Option 1: Do it yourself
Follow the steps in this guide. Free, and typically 30 minutes to a few hours of careful work.
Option 2: Just contact us
Skip every step below. $49/mo and it is sorted, or WhatsApp us right now.
Last updated: August 2026
What a complete backup contains
Two halves, and both are mandatory. Files: your themes, plugins, uploaded images and documents, and configuration files. Database: your pages, posts, products, orders, users, comments and settings. A files-only backup restores an empty shell of your website; a database-only backup restores your content with nothing to display it. Anyone offering "backups" should be asked which halves they mean.
The 3-2-1 rule, in plain terms
Keep three copies of your data, on two different types of storage, with one copy off-site. For a website that translates to: the live site, a backup on the host, and a backup somewhere completely separate such as Google Drive, Dropbox or Amazon S3. The off-site copy is the one that matters, because a backup living on the same server as your website disappears with the server, the account suspension or the compromise.
How often to back up
Match frequency to how much work you are willing to redo. A brochure site updated monthly can run weekly backups. A business site publishing regularly needs daily. An online store taking orders needs daily at minimum and real-time or hourly database backups, because every hour of lost orders is lost money and angry customers. Retention matters too: keep at least 30 days, because infections and corruption are often discovered weeks after they start, and a 7-day retention window means every copy you hold is already contaminated.
Setting it up on WordPress
Plugins that do this properly include UpdraftPlus, BlogVault, Jetpack VaultPress and Duplicator Pro. Configure four things: full backups of files and database, automatic scheduling, remote storage as the destination rather than the same server, and email notification on failure so a silently broken job cannot run unnoticed for months. Host-level backups are a useful second layer but a poor only layer, since they vanish with the account.
The step everyone skips
Test the restore. Once a quarter, restore your backup to a staging site and click through it: homepage, a few inner pages, a form, a login, and on a store, an order record. A backup nobody has restored is not a backup, it is a hope with a filename. In real recoveries we have seen backups that excluded the uploads folder, backups of an empty database, and years of nightly jobs that had been failing silently since a password change.
What good looks like
Daily off-site backups, 30-day retention, an extra snapshot taken automatically before every update, integrity verification, one-click restore, and a quarterly test. That is the standard we run on every site under maintenance, and it turns catastrophes into ten-minute inconveniences.
FAQ
Does my host already back up my site? Often yes, at unclear frequency, with limited retention, stored on the same infrastructure, and sometimes as a paid add-on. Treat host backups as a bonus layer, never the plan.
How much storage do backups need? Most business sites are 1 to 5 GB, so 30 days of retention with incremental backups fits comfortably in free or cheap cloud storage tiers.
Can I back up manually instead? You can, and you will, for about three weeks. Manual backups fail on human consistency, which is exactly what automation exists to solve.
What do I do if my only backup is corrupted? Stop overwriting anything, keep the corrupted copy, and get professional help. Partial recovery from a damaged database is often possible, but only if nothing else has been written over it.
You do not have to do any of this yourself
Skip the steps above. Our engineers handle security, updates, speed, backups and fixes for you, with a 12-minute average response and a 99.99% uptime target.