MB Bluejuice
Servers and hosting

Backups that actually work

A backup nobody has restored is not a backup. Four requirements it has to meet.

· updated 2026-10-07

Almost every client says they have backups. During an incident it turns out that about a third of them are unusable for recovery.

Four requirements

  1. Stored off the server. A backup on the same machine protects against your mistake but not against a breach or a disk failure — the attacker deletes it along with everything else.
  2. Enough history. One day is not enough: infections are often found two weeks later. A practical minimum is 30 days.
  3. Complete scope. Files and database from the same moment. Separately scheduled copies can be out of sync.
  4. Verified restore. At least quarterly, restore into a staging environment and check it.

Two numbers worth knowing

RPO — how much data you can afford to lose. A daily backup means up to 24 hours. For a shop that is usually too much, because orders are lost.

RTO — how long recovery takes. If a backup exists but restoring takes a day, for the business that is close to not having one.

The infected backup problem

If malicious code went unnoticed for a month, every backup from that month is infected. After an incident, restoring is therefore not a solution but one tool — and only once the infection start date is known.

On our managed servers backups run daily with 30-day history and regular restore tests: webhostas.com.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.