Web Host Lens

Web Host Lens field guide

Hosting backups and disaster recovery

A backup feature is useful only when retention, isolation, restore scope and recovery time match the risk.

Updated 17 July 2026Primary sources linkedAffiliate-neutral
Hosting backups and disaster recovery

Editorial verdict

The short answer

Maintain at least one backup outside the hosting account. Provider backups improve convenience, but terms can limit retention and responsibility. Test restoration before an incident and define acceptable data loss and downtime.

Before you buy

Questions the provider must answer

  1. 01How often are backups created?
  2. 02How many versions are retained?
  3. 03Are copies off-account and geographically separate?
  4. 04Does restoration cost extra?
  5. 05Can email and DNS be restored too?

Decision process

A practical, repeatable method

1

Define recovery objectives

Recovery Point Objective (RPO) is acceptable data loss; Recovery Time Objective (RTO) is acceptable downtime.

2

Map every data set

Include files, database, uploads, email, DNS, certificates, secrets and external services.

3

Use independent copies

Keep versioned backups outside the host and protect them with separate credentials.

4

Encrypt and restrict access

Backups contain sensitive data. Apply encryption, least privilege and retention deletion.

5

Test full restoration

Restore to an isolated environment, record time and verify application behaviour.

6

Review after changes

New stores, membership data or compliance requirements can make an old schedule insufficient.

Avoidable errors

Common mistakes

  • × Assuming snapshots are backups
  • × Keeping every copy in one hosting account
  • × Never testing restoration
  • × Backing up files without the database
  • × Ignoring ransomware and credential compromise

Frequently asked questions

What buyers ask next

Are daily backups enough?

Not for every workload. A busy store may require more frequent database protection.

How many versions should be kept?

Enough to recover from delayed discovery, not only yesterday’s error. Use daily, weekly and monthly layers where appropriate.

What does offsite mean?

A separate failure domain, ideally with distinct credentials and infrastructure.

Can a backup guarantee recovery?

No. Only a successful tested restore demonstrates recoverability.

Evidence

Primary and supporting sources

Prices and terms can change. Recheck the provider page and checkout before purchasing.

How to use this guide

Separate facts, estimates and judgement.

Provider documentation establishes product terms. Calculations explain their financial effect. Regional suitability requires checkout verification and testing from the intended audience. A recommendation is editorial judgement only after those layers agree.

Official termCalculated modelRegional verificationEditorial conclusion