Who Has Your Website Backup?
Updated 22 August 2026
Jump to section
If you cannot name who holds your website backup, the safest assumption is that nobody does. A real backup covers both the site files and the database. It lives off the live server, in an account your business controls, and it has survived a test restore. On typical cPanel shared hosting in Malaysia, a host-side copy may exist, but none of those four properties is guaranteed. Many owners find this out on the day something breaks.
Doesn't my hosting company back everything up?
Often yes, and with limits that only show themselves when you need the copy. Host backups are a convenience feature, and reading the fine print usually reveals three of them.
Retention is short: a rolling window of recent copies, so damage noticed late may already be baked into every backup that still exists. Storage often sits on the same server or account, so whatever took the site down can take the backups with it. And the terms are typically best-effort, with the responsibility worded back onto you.
None of that makes host backups worthless. It makes them one layer, and a layer someone else controls, on someone else's schedule, under someone else's terms.
What does a complete website backup include?
A complete backup is the site files plus the database, and the second half is the one people miss. For a WordPress site, the files hold the theme, plugins, and uploads; every page, order, and customer record lives in the database. A folder copy without the database saves the furniture and loses the building.
| What to keep | What is lost without it |
|---|---|
| Site files (theme, plugins, uploads) | The design and every image |
| The database | All pages, posts, orders, and customer records |
| Email, if hosted with the site | Correspondence your business may need |
| Credentials and license keys | Days of lockout while access is rebuilt |
| The domain and DNS record list | The address itself, if renewal or transfer goes wrong |
The bottom rows overlap with the ownership questions in who should own your domain and accounts, because a backup you cannot deploy, on accounts you cannot reach, is theater.
Where should backups live, and who should hold them?
At least one copy should live off the server, in storage your business owns, and that second clause is the one that bites. A copy your developer keeps is a courtesy, and courtesies end when relationships do.
We have seen businesses locked out of their own domain and accounts because a former vendor held everything. A backup that exists only in someone else's drawer sits on the same failure line.
The healthy arrangement is layered. Keep the host's rolling copies, and add an automated off-server backup in cloud storage registered to the business. If a maintenance provider holds a third copy, that is redundancy on top, never the foundation.
How often should you back up, and how do you know it works?
Match the frequency to how fast the site changes. Daily suits a store or an active blog, weekly suits a site that changes occasionally, and any major update deserves a fresh copy immediately before it. The real question is the second one, because an untested backup is a hope with a filename.
The only backup that counts is one that has been restored. A test restore to a temporary location proves the file is complete, the database is in it, and someone on your side knows the steps.
The arithmetic of skipping this is unkind. Take a site whose owner adds two content updates a week, with the last backup four months old. That is more than thirty rounds of work to redo by hand. At even RM200 of staff time per round, the rebuild costs roughly RM6,000, against minutes for a tested restore (illustrative arithmetic, not a client result).
Restoring a good backup is a quick job. Rebuilding a lost site is a slow one, and losing it entirely puts you back into full build-cost territory. That gap is the entire argument.
Frequently asked questions
Is a backup plugin on the website itself enough?
Better than nothing, and not enough by itself. Most backup plugins store their copies on the same server by default, where a hack, a disk failure, or an account suspension takes site and backups together. The fix is configuration: point the plugin at off-server storage, a cloud drive or bucket registered to the business, and confirm copies actually arrive there.
How many backup copies should a business keep?
More than one, in more than one place. A practical minimum is the host's own rolling copies plus an automated off-server backup you control, with several dated versions retained rather than one overwritten file. Versions matter because problems get noticed late; a single yesterday-copy faithfully preserves yesterday's damage.
My web developer says he keeps a copy. Is that fine?
As an extra copy, yes; as the only copy, no. Developers change, retire, and fall out with clients, and in our experience the businesses that end up locked out are the ones where a vendor held everything. Ask for a copy to be placed in storage the business owns, and treat that request as routine housekeeping, not distrust.
Does having backups protect me from hacking?
No. A backup is recovery, not prevention: it shortens the outage after something goes wrong and saves the rebuild cost, but it does not stop the break-in itself. Prevention is updates, licensed software, and access hygiene. You want both, because prevention lowers the odds and the backup caps the damage.
What does proper backup coverage cost in Malaysia?
Usually little or nothing extra, which makes the gap strange. Off-server storage at these sizes costs a few ringgit a month. Scheduled backups with restore testing are a standard line inside a website's normal running costs and any serious care plan. The expensive version is not having one.
Know your answer before you need it
Storming Solutions builds and maintains websites for Malaysian businesses from Kuala Lumpur, and backup discipline is part of how we define upkeep. Scheduled, off-server, restored on a test schedule, and stored in the client's own name. Our stance is that a backup nobody has restored is a rumor.
Cannot answer "who has our backup?" today? Ask your current provider this week, or ask us to check through the contact page. What ongoing care includes is on our web development service page.