Last updated: October 5, 2026 · 3 min read · By Ali Raza
Follow the 3-2-1 rule: keep at least three copies of your website (the live site plus two backups), on two different types of storage, with one copy off-site, away from your hosting server. Back up both files and database, as often as your content or orders change, keep several weeks of history, and test a restore at least every quarter. A backup you have never restored is only a hope.
Most business owners believe their website is backed up. Fewer know where the backups are, how old they are, or whether they would actually work. That question usually gets answered on the worst possible day: after a hack, a failed update or a hosting problem.
Here is how to set up a backup plan you can rely on.
The 3-2-1 backup rule
What should a website backup include?
- Database: pages, posts, settings, users, orders and form entries.
- Files: themes, plugins, uploads such as images and documents, and configuration files.
- Notes: where DNS is managed, hosting details and any custom server settings, stored securely.
How often should you back up?
Match backup frequency to how often the site changes. A brochure site edited monthly can be backed up daily with weekly copies kept for a few months. An online store taking orders all day needs at least daily backups, and ideally real-time database backups so no orders are lost. Always take a fresh backup before updates or big changes.
Where should backups be stored?
Not only on the same server. If the server fails, is hacked or the hosting account is suspended, on-server backups go with it. Store at least one copy with a separate cloud storage provider, with its own login protected by two-factor authentication. Hosting-company backups are a useful extra layer but should not be your only one.
How do you test a restore?
- Create a staging site or a local copy.
- Restore the most recent backup to it, both files and database.
- Check that pages load, images appear, forms submit and you can log in.
- For stores, check products, orders and customer accounts.
- Write down how long it took and any problems, so the real restore is faster.
How long should you keep backups?
Keep enough history to go back before a problem started. Hacks are often discovered weeks after they happen, so a backup history of only a few days may contain the infection too. Several weeks of daily backups, plus monthly copies for longer, is a sensible default.
What about Shopify?
Shopify manages the platform, but your store data (products, customers, orders and theme changes) can still be lost through mistakes, faulty apps or bad imports. Use a backup app or regular exports, and keep copies of your theme.
Backups are part of every routine in our maintenance checklist and essential in our hacked website recovery plan. Our website care plans include off-site backups and regular test restores.
Frequently asked questions
What is the 3-2-1 backup rule?
Keep three copies of your data, on two different types of storage, with one copy off-site.
How often should I back up my website?
As often as it changes: daily for most business sites, and more often, ideally real-time for the database, for online stores.
Are my hosting company's backups enough?
They are a useful extra, but keep your own off-site backups too, in case the hosting account or server has a problem.
How do I know my backup works?
Restore it to a staging site at least every quarter and check that pages, forms, logins and orders work.
