The website works. It's worked fine for years, and you almost never think about what's "behind" it. Then something happens - an error after an update, a problem on the hosting server, or something else entirely - and the website stops working.
At that moment, one question becomes the most important thing in the world: is there a backup, and who's in charge of restoring it. This text won't teach you to make backups yourself - it'll show you what to ask, and who to ask, so you never have to ask that question in a panic.
Who's actually responsible - it's not always the same answer
This is the biggest source of confusion, because responsibility depends on how the website was originally set up, and that's rarely explained explicitly to the business owner.
The hosting provider. Many hosting plans include automatic backup as part of the service - but not all, and not always the same way. Some hosts run daily backups and keep them for 30 days, others only weekly, and some cheaper plans include no backup at all unless paid for separately.
The agency that built the website. Some agencies, on top of hosting, set up their own separate backup system (say, a plugin or an automated process that stores copies somewhere else, not just with the host).
Nobody, by default. If the backup question was never explicitly discussed with either the host or the agency, it's entirely possible that no backup currently exists - not because anyone forgot, but because it was never part of the arrangement in the first place.
The takeaway is simple, if a bit uncomfortable: don't assume a backup exists just because the business pays for hosting or paid to have the site built. This is a question to ask directly, not guess at.
What a backup actually saves
For the conversation with your host or agency to make sense, it's worth understanding what "website backup" actually means.
- Website files - all the code, design, images, and documents that make up the site itself
- Database - content that changes (text, products, user accounts, orders, if it's a store)
- Email accounts - this is often separate from the website backup, and it's worth specifically checking whether emails are included in the backup too
A complete backup includes all three. An incomplete backup (say, only files with no database) can restore the site, but without the most recent content or orders - which is why it matters to know exactly what's covered.
How often a backup is made and how long it's kept
This varies drastically depending on hosting, so a universal answer is impossible - but here are the typical ranges you'll most often run into.
- Frequency - most commonly daily on more serious hosting plans, sometimes weekly on cheaper ones
- Retention (how long it's kept) - usually between 7 and 30 days back, meaning that after that period, older copies naturally disappear to make room for new ones
This matters because if a problem is only noticed a month later (say, someone accidentally deletes part of the content and no one notices right away), a copy from before that moment may no longer exist.
What actually happens when a website "breaks"
"Breaking" can mean several different things, and a backup helps in most, but not absolutely all, scenarios.
An error after an update. A website uses various components (themes, plugins, background systems) that get updated from time to time. Sometimes an update causes an error and the site stops working properly. In this case, a backup from before the update allows a quick return to the state that worked.
A problem on the hosting server. Rare, but it happens - the server itself has a failure or loses data. Here it matters that the backup exists in a different location, not just on the same server, since a backup that's physically stored in the same place as the site doesn't help if that exact server is the problem.
Accidental content deletion. Someone on the team unintentionally deletes a page, a product, or a piece of content. A backup lets you restore that piece without having to rewrite or recreate everything.
A hacked website. This is a more complex scenario - a backup helps restore the site to its state before the attack, but doesn't by itself fix the reason the site was vulnerable in the first place. After restoring from backup, the "hole" the attack went through usually still needs to be found and closed, which is a separate, technical topic beyond the scope of this text.
Three questions to ask - today, not when you need them
You don't need to understand the technical side of backups. It's enough to get clear answers to these questions from your host or the agency managing the site.
- "Is my website backed up automatically, and how often?" - this gives you basic confirmation that a backup exists at all.
- "How long are old copies kept, and are they stored somewhere separate from the site itself?" - this tells you how far back you can go, and whether the backup is genuinely safe from problems on the server itself.
- "If something goes wrong, who initiates restoring the site, and how long does that usually take?" - this clarifies exactly who takes action in a crisis moment, instead of that becoming unclear right when it matters most.
If you don't get a clear answer to any of these, that's a sign it's worth considering an additional backup solution, rather than assuming everything is covered.
Why this isn't a "technical" topic, it's an organizational one
A business owner doesn't need to know how a backup is technically made, where it's stored, or what tool restores it - that's the host's or agency's job. What the owner should know is whether that process exists at all, and who's responsible for it.
The difference is similar to car insurance - you don't need to know how the insurance company processes a claim, but you should definitely know whether you have a policy, and who to call if something happens.
Frequently asked questions
Do I personally need to do anything for a backup to exist? No - if a backup exists, it runs automatically, in the background, with no involvement from you. Your only "job" is confirming that the system actually exists.
Does a backup protect the website from being hacked? Not directly - a backup doesn't prevent an attack, but it enables a quick recovery afterward. Preventing attacks is a separate, technical topic (security settings, updates, passwords).
Does backup cost extra? Depends on the hosting - some plans include it free, others charge for it as an add-on. It's worth checking exactly what's included in your current plan.
How fast does the site get back to normal after a problem, if a backup exists? Depends on the size of the site and who carries out the restoration, but for most standard websites, the process usually takes anywhere from a few hours to one business day.
Does email have a separate backup, apart from the website? Often yes - email accounts and the website can have completely separate backup systems, so it's worth asking about each one separately, rather than assuming one backup covers both.
What if I switch agencies - does the backup stay in place? Depends on whether the backup is tied to the hosting (in which case it usually stays, since the hosting stays the same) or to the agency itself (in which case it's worth clarifying with the new agency how it will be organized going forward).
In closing
A website backup is one of those things nobody thinks about until they need it - and by then, it's already too late to ask "does this even exist".
You don't need to become a backup expert. It's enough to ask these three questions today, get clear answers, and then stop worrying about it entirely - because you'll know exactly where you stand.