Expertise · Platform and technology

Having a backup is not enough; it must be recoverable

Almost every web development agency claims to have backups. The right question is: when the site crashes at nine in the evening, how long will it take to get it back up, and to what point can it revert?

Quick summary

A secure website requires four things: regular backups stored separately from the live site, the ability to revert to a specific point in the recent past, periodic recovery tests to ensure the backup is usable, and an upgrade process that is tested on a backup before being applied to the live site, along with a rollback plan in case of failure. Without the recovery test step, backups are merely a belief, not a guarantee of safety.

Quick glance
Compatible with
the website receives forms, schedules, or ordersthe website updates content regularly

Website incidents rarely give advance notice: an upgrade can break the homepage, a plugin may be attacked, someone might accidentally delete an entire category, or the account hosting the website could be locked due to a missed renewal. At that point, the phrase "we have backups" is only valuable if the backup can be restored, at the right time, and quickly.

Two numbers you should ask

The industry operates with two simple concepts to measure safety. First is the ability to revert to a certain point: if backups are made weekly, an incident occurring on the weekend could result in a loss of an entire week’s worth of content and customer data. Second is how long it takes for the website to be back up: a few minutes, a few hours, or waiting for a technician to be available. These two numbers should be clearly stated, not just "there is a backup."

Five questions to ask the web development unit

  • Where is the backup stored? At least one copy should be located outside the site’s current environment.
  • How far back can you recover? Can you go back to yesterday, last week, or just the latest version?
  • Have you ever tried to restore? A copy that has never been tested for recovery is not guaranteed to be usable.
  • Is there a trial for the upgrade? The core software and utilities are tested on a copy before being applied to the live site.
  • How do you roll back if something goes wrong? Is there a way to revert to the running version, who clicks it, and how long does it take?

Signs of safety: automatic scheduled backups, multiple restore points, a copy stored offsite, periodic recovery tests, upgrades tested beforehand with a rollback option, and monitoring systems that alert when the site goes down.

Signs of risk: manual backups when remembered, only keeping the latest copy, backups stored on the same server, direct upgrades on the live site, and only knowing the site is down when customers report it.

Common errors

  • Turning off automatic upgrades for fear of breaking the site, then leaving old software for years, creating a security vulnerability.
  • Trusting the backup from the provider without knowing how to recover it.
  • No one is notified when the website goes down outside of working hours.
The tool brings back.

Decision checklist

Subject: Backup, recovery, and website upgrades: questions to ask. Sinh Vũ guide, sinhvu.com

0 more than 6 items

Select each item you find appropriate, then print or save as PDF to take with you.

Sign indicating that you should take action
Questions to answer before deciding

If you have marked most of the signs above, this is the time to discuss in more detail. Sinh Vũ can help you review and propose a direction.

References

NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems (concepts of recovery time objective and recovery time). The 3-2-1 backup principle (three copies, two types of media, one copy offsite). Practical experience in website operations.

Frequently asked questions

How often is a backup sufficient?

According to the pace of content changes. Websites that post news daily or receive continuous submissions need automatic backups every day or continuously. Websites with less frequent updates should back up at least weekly, plus one backup before each upgrade.

The provider where the website runs has backed it up, do you need anything else?

It is advisable to have an additional copy stored offsite. A backup stored with the same provider will be lost simultaneously if the account is locked, attacked, or if the provider experiences issues.

If the upgrade fails, does the website have to stop running?

Not necessarily. A good process is to test the upgrade on a backup, apply it to the live site, check immediately, and have a rollback option to the current version within a few minutes if there is an error. With a rollback option, customers hardly notice anything.

This article is for reference. The scope, pricing, and specific commitments of Sinh Vũ are detailed in the proposal and signed contract.

← Back to Websites and Digital Experiences