Security

You have a backup. Can you actually restore the website?

A backup matters when it can be restored. Decide what to save, where to keep copies and how to test recovery safely.

The CloudCity teamPublished 2 min read

A “backup completed” message confirms an operation, not the recovery of your business. Website files may be saved while the database is missing. A copy may be intact while the credentials needed to retrieve it are stuck on an affected computer. A useful backup plan starts with two questions: what must work again, and how much missing data could the business realistically reconstruct?

Save the complete service

A dynamic website needs its files, database and the information required to configure it. For a shop, check orders, uploaded documents and connections to external services. Email may follow a separate backup policy. Make an inventory before assuming one button covers everything. Keep recovery instructions and access to necessary keys in a protected place that remains available if the main system fails.

Match the frequency to changing data

A brochure website updated monthly and a shop receiving daily orders have different needs. Ask how much work disappears between copies: a day of articles or a day of orders? Set the interval accordingly and check retention. Daily copies without enough history may preserve only versions that are already compromised. Compare backup costs with the value of the data and the effort required to reconstruct it.

Separate copies from the incident

Keeping multiple copies on different media, with one separated from the main system, reduces dependence on a single point of failure. For ransomware, it matters whether an attacker can alter or delete the backups too. A folder on the same server is not equivalent to a protected copy in another system. Ask who can delete copies and what controls protect that operation.

Test in an isolated environment

Restore a copy into a test environment that cannot be indexed and cannot automatically send emails or payments. Check pages, images, sign-in and representative records. Record how long it takes and any missing steps. For a shop, make sure the test does not resend orders to delivery or accounting systems. The aim is to discover dependencies without changing the service customers use.

Decide who approves recovery

After a compromise, immediately restoring over the affected system may preserve the cause or destroy useful evidence. Work with the technical owner to decide which copy is safe, which access must be revoked and how the vulnerability will be addressed. After recovery, verify forms and essential business operations. Record the restoration time and any data that must be reconciled afterwards.

Sources and further reading

A CloudCity editorial guide informed by the documentation below. Check the official source for rules and procedures that may change.

Back to the blog