· updated 2026-10-07
Almost every client says they have backups. During an incident it turns out that about a third of them are unusable for recovery.
Four requirements
- Stored off the server. A backup on the same machine protects against your mistake but not against a breach or a disk failure — the attacker deletes it along with everything else.
- Enough history. One day is not enough: infections are often found two weeks later. A practical minimum is 30 days.
- Complete scope. Files and database from the same moment. Separately scheduled copies can be out of sync.
- Verified restore. At least quarterly, restore into a staging environment and check it.
Two numbers worth knowing
RPO — how much data you can afford to lose. A daily backup means up to 24 hours. For a shop that is usually too much, because orders are lost.
RTO — how long recovery takes. If a backup exists but restoring takes a day, for the business that is close to not having one.
The infected backup problem
If malicious code went unnoticed for a month, every backup from that month is infected. After an incident, restoring is therefore not a solution but one tool — and only once the infection start date is known.
On our managed servers backups run daily with 30-day history and regular restore tests: webhostas.com.