What should a website backup cover?
A website has two parts: the files (software, images, uploaded documents) and the database (page content, form entries, orders, users). Backing up only one of them isn't enough to bring the site back. On top of that, server settings, DNS records and email configuration should be documented as well; in a crisis, these details are what waste the most time.
How often should you back up?
Backup frequency depends on how often your site changes. A brochure site updated every few months and an online store taking orders every hour can't use the same plan.
| Site type | Database | Files |
|---|---|---|
| Corporate brochure site | Daily | Weekly and before every change |
| Site that collects leads via forms | Daily | Weekly |
| E-commerce store or portal | Several times a day | Daily |
Then there's retention. Keeping only the latest backup is risky; if a problem is noticed a few days later, the latest backup may be corrupted too. That's why we keep daily, weekly and monthly backups together, each for a set period.
The 3-2-1 rule
The 3-2-1 rule, a widely used principle in information security, offers a simple framework: at least three copies of your data, on at least two different types of storage, with at least one in a separate location. For a website, that means the live data on the server, a local backup on the server, and an encrypted off-site backup with a different provider. Even if the server becomes completely unreachable, the off-site backup saves you.
Backups contain personal data too. So they are encrypted, access to them is restricted, and retention periods are set in line with KVKK compliance (KVKK is Türkiye's Personal Data Protection Law).
Restore testing
Many companies find out that their backup is corrupted or incomplete on the very day they need it. To prevent this, we periodically restore a backup to a separate test environment and check that the site actually loads and the data is complete.
Steps we follow in a crisis
- The scope of the problem is identified — when it started and what it affects.
- A copy of the current broken state is also taken and kept for investigation.
- The last good backup from before the problem is selected and restored.
- Any new data created in between (such as orders) is recovered separately.
- The root cause is fixed, and measures are taken so the same problem doesn't happen again.
Checklist
- Are files and the database backed up separately?
- Is at least one backup stored with a different provider?
- Are backups encrypted, with restricted access?
- When was the last restore test done?
Frequently asked questions
Our hosting company already takes backups. Isn't that enough?
It helps, but it isn't enough on its own. The provider's backup sits on the same infrastructure, and the restore conditions may not be under your control. We recommend an independent off-site backup.
How long does recovery take?
It depends on the size of the site and the type of problem. A site with a ready plan and backup recovers much faster than one that wasn't prepared.
For updates and protection against attacks, see the security and updates page; for the big picture, see the hosting and maintenance page, or get in touch with us.