Does Anyone Actually Have a Website Backup?
A shop owner near Grant and Campbell called us in March because her site had stopped loading. Asked whether she had a backup, she said yes, her nephew had one. The nephew built the site in 2019 on a laptop that died sometime in 2022. That was the backup. She was not careless about it either. She had an answer ready for the backup question, which is more than most owners have, and the answer turned out to be a machine in somebody's garage.
A Copy Nobody Has Opened Is a Guess
Three conditions make a backup real. A complete copy, kept somewhere other than the server, that somebody has restored at least once.
Your hosting terms already answer the ownership question
They say the backups are a courtesy and the copies are your job.
Almost nobody does. A website backup is three things at once, and most owners have one of them. A complete copy of your files and any database behind them. Stored somewhere other than the server that runs the site. Restored at least once by somebody, so you know the copy opens. What most businesses have instead is a copy on the same hosting account that could disappear, or an archive in a folder nobody has touched since launch day.
Whose job is it? Yours. Read past the marketing page and the hosting terms say so plainly: the backups are a courtesy the host runs at its discretion, and keeping copies is the customer's responsibility. Your developer might keep copies out of professional habit, which is not the same as an obligation you could point to.
What Actually Counts as a Website Backup?
A complete copy of your site's files and any database behind them, stored somewhere separate from the server the site runs on, that somebody has restored at least once. Three conditions. Miss one of them and you have a file with good intentions, which behaves very differently in an emergency.
Files means everything the site is built from. The HTML or template files, the stylesheets, the scripts, and the images folder, which on most small business sites is by far the biggest part of the whole thing. A photographer's gallery page can be four kilobytes of code sitting on top of nine hundred megabytes of photos.
If the site runs on WordPress or anything else with a database, that database is the site. Page text, menus, plugin settings, form entries, all of it lives in there. A files-only backup of a WordPress site gets you a working theme with no content in it.
Then there is the surrounding material nobody thinks to copy. DNS records. Which registrar the domain sits at. The email accounts pointed at that domain. The license key for whatever paid plugin makes the booking calendar work. None of that is inside the site backup, and all of it has to be rebuilt by hand if the account it lived in goes away.
The third condition is the one that gets skipped, and the failure modes are boring rather than dramatic. A database export that stopped halfway through. An archive missing the uploads directory. A file that opens fine on the developer's machine and throws errors on a new server.
Close Enough Until It Is Not
Each of these is worth having. None of them is a backup on its own.
A ZIP File on Somebody's Desktop
The most common one, and better than nothing. Trouble is it is a single copy, it goes stale the moment the site changes, and it sits on a machine with a hard drive that has a life expectancy. Ask when it was made. If the answer is the year the site launched, it is a snapshot of a website you no longer have.
The Host's Nightly Snapshot
Useful and short-lived. Retention gets measured in days, the restore usually overwrites the live site, and the whole arrangement depends on an account in good standing.
The Wayback Machine
Not a backup at all. Public archives keep fragments, and how much they kept depends on how the site was built and how often anyone crawled it.
Whatever the Developer Has
Often the best copy in existence and completely outside your control. Worth one email to find out whether it exists, where it lives, and what happens to it if that person changes careers. Most developers answer honestly. The ones who never answer have told you something too.
Who Is Responsible for Backing Up Your Website?
You are, on paper and in practice. Large shared hosts describe their backups as a courtesy provided at their own discretion, with no guarantee and no liability for lost data, and they state that keeping copies is the customer's responsibility. Your developer may keep copies as a matter of habit. Habit does not survive a career change.
That sounds like a dodge and mostly it is not. Hosts run backups across shared servers holding thousands of sites. Promising a guaranteed restore for every one of them on an eight dollar a month plan would be a promise nobody could keep, so they hedge in writing and hand the risk back to the account holder.
Which would be fine if anyone read it. What happens instead is that the owner assumes the host has it, the host has already said in writing that the owner has it, and the developer assumes somebody set something up before they arrived. Every party in the chain has a reason to believe this belongs to someone else.
Invenio IT's 2026 roundup of business continuity data cites a U.S. Chamber of Commerce Foundation finding that only 26 percent of companies keep a documented disaster recovery plan, while 94 percent believe they would recover from a disaster.
For a five-page site for a barber shop on Fourth Avenue, a formal recovery plan is overkill. One note with the registrar login, the hosting login, and the location of the file copy does most of what a plan would do, and our breakdown of what hosting actually costs a Tucson small business covers where backup add-ons land on the monthly bill.
Everybody in the chain assumes somebody else has it.
The owner thinks the host does. The host has already said in writing that the owner does. The developer assumes somebody handled this before they got here.
Why Is an Untested Backup Just a Guess?
Because backup software reports on the job it ran, not on the restore you will eventually need. Veeam's April 2026 resilience report found 90 percent of leaders were confident they could recover inside their own targets, while only 28 percent of organizations hit by ransomware fully recovered all of their affected data.
Average recovery in that same survey came to 72 percent of affected data. Picture what 72 percent of a website looks like. Home page loads, four service pages return errors, gallery shows broken image icons in a neat grid.
Kaseya's writeup on backup testing puts over half of businesses at testing their disaster recovery plan once a year or less, with 33 percent testing infrequently or never at all. Those figures come from organizations that employ IT staff, which a salon in midtown Tucson does not.
Sophos surveyed 3,400 organizations that had been hit by ransomware for its 2025 State of Ransomware report. Only 54 percent used backups to restore their data, the lowest share in six years. Every one of those companies had some kind of backup arrangement in place before the attack.
A test does not need to be elaborate. Restore the backup to a temporary address nobody links to, click through every page, submit the contact form, check that the photos loaded. An hour, once a quarter. Do it on a slow Tuesday.
What the data says about restores
28%
Share of ransomware victims who fully recovered all their affected data, against 90 percent of leaders who said they were confident they could, in Veeam's April 2026 resilience report
1 day
Automatic backup history included by default on GoDaddy's cPanel web hosting, with 7, 14 and 30 day windows sold as a paid upgrade
How Long Does Your Host Actually Keep Backups?
Days, in most cases. GoDaddy's cPanel web hosting includes a single day of automatic backup history and sells 7, 14 and 30 day windows as a paid upgrade. Retention length decides everything, because website problems get discovered weeks after they start. A form that broke in June is outside every window by August.
Nobody watches their own site. The owner glances at the home page on a phone once a month, and anything past that gets noticed when a customer mentions it. A yard care contractor told us his contact form had been dead since spring, which he learned when a woman said she had sent three messages and then hired somebody else.
Delay is why retention windows fail people. The host still holds yesterday's copy of a site that has been broken for six weeks, which restores you neatly back to broken.
There is a harder version of this. If the hosting account lapses, or the person holding it walks away, the backups go with it, because they were stored on that same account. A server has no redemption period the way an expired domain does. We wrote up a Tucson job where the hosting disappeared along with the domain, and the site had to be reconstructed out of web archive fragments rather than restored.
Price does not track backup quality here either. A four dollar plan and a twenty-five dollar plan can both hold one day, and the expensive one might simply be faster. Ask the question directly: how many days do you keep, and what does it cost to keep more.
Web archives keep fragments. Fragments are not a website.
On one reconstruction, some pages came back whole, some came back as text with every image missing, and one came back as a headline with nothing underneath it.
Does a Static Website Change the Backup Question?
It changes the shape of the question. A static site carries no database and no visitor-generated content, so the whole site is plain files kept in version control, where every past version is recorded and any of them can be republished. Losing the hosting or the domain is still a live risk, and version control does nothing at all about either one.
Internet Crafters builds static sites. No CMS, no admin panel, no login for the owner to edit pages with, which sounds like a limitation and quietly removes a whole category of backup problem. Nobody overwrites a page at 11pm and loses the previous version, because content changes come through us and land in the repository as a recorded change with a date on it.
Version control also spreads the copy around. It exists on our machines, in the hosted repository, and in whatever deployment the live site runs from. Losing all of those in the same week takes a stranger sequence of events than losing one ZIP file on one laptop.
Version control holds the site's source and stops there. It does not hold your domain registration, and an expired domain makes the site unreachable no matter how many copies of the files exist. It does not hold your form submissions, which arrive as email and live in your inbox. It does not hold full-resolution originals of the photos you handed us, so keep those somewhere you can find them.
A static site also has less to compromise in the first place, which is a separate benefit worth naming. Fewer moving parts means fewer ways to get quietly modified, though as we covered in what SSL actually does and does not do, no architecture makes anyone immune, which is why the backup is the layer that matters after something has already gone wrong.
What Should You Do About This Before Something Breaks?
Find out where your files are and who can produce them. Ask that person to restore a copy somewhere you can click through yourself. Then get a copy into a drive or a cloud folder in your own name. Three steps, maybe two hours of your attention, and most of that is waiting on a reply.
Write down four things while you are in there. The registrar where the domain is registered. The host and the login. Where the file copy lives. Who to call when the site is down. Four lines, in whatever app already holds the plumber's number.
The stakes for a small business are not abstract. Invenio IT's continuity roundup cites FEMA data putting 43 percent of small businesses at never reopening after a disaster, with another 29 percent closing inside two years. Data loss is not all of that. It is one of the versions where the phone stops ringing and the business has no quick way to tell anyone it still exists.
Internet Crafters gets called for this after the fact far more often than before it. We can usually work out what still exists, and sometimes there is more left than the owner feared. Sometimes there is less. Our writeup on what it costs to fix a bad Tucson business website covers the pricing side of a rebuild when nothing is left to restore.
As for the shop owner and the nephew: we rebuilt her site from scratch, which took longer than a restore would have and cost more. In April she mentioned the laptop might still be in the garage. We asked twice. Nobody has looked.
Straight Answers
Eight Questions Owners Ask About Backups
How Do I Find Out If My Website Is Backed Up Right Now?
Ask three questions. Who has a copy of the files, where is that copy stored, and when was it last opened. If any answer is a guess, you do not have a backup yet. Start with whoever built the site.
Is My Web Host's Backup Enough for a Small Business Site?
Usually not on its own. Host backups run on short retention windows, live on the same account as the site, and are described in the terms as a courtesy with no guarantee. Keep a second copy somewhere you control.
How Often Should a Small Business Website Be Backed Up?
For a static five-page site that changes twice a year, a fresh copy after every change is enough. For a site with a blog, a store or form data in a database, nightly is the right answer and weekly is the minimum.
What Should Be Included in a Website Backup?
Every file the site is built from, the images folder, and the database if there is one. Keep the surrounding details too: registrar, DNS records, hosting login, and license keys for any paid plugin the site depends on.
How Do I Test a Website Backup Without Breaking the Live Site?
Restore it to a temporary address nobody links to, then click every page, submit the contact form and confirm the images load. Most hosts support a staging or subdomain restore. Budget an hour and do it quarterly.
Can the Wayback Machine Be Used to Restore a Website?
Not really. Public archives preserve fragments of pages, not a working site. We have rebuilt from them and it is detective work: some pages captured whole, some as text with images missing, some as a link with nothing behind it.
Do Static Websites Still Need Backups?
Yes, though the risk moves. A static site's source lives in version control, so past versions are recorded and republishing one is quick. That covers the files. It does nothing about a lapsed domain or a hosting account somebody else controls.
What Happens to Backups If I Stop Paying for Hosting?
They go away with the account, usually within weeks. Host backups live on the same infrastructure as the site, so a lapsed or deleted account takes both. A server has no redemption period the way an expired domain does.
Does Anyone Know Where
Your Site Files Live?
Internet Crafters can trace where your website actually lives, get a copy into your hands, and tell you straight what is missing. If there is nothing left worth restoring, we build the replacement. Tucson and Southern Arizona businesses, plus anywhere else that calls.
Static sites with the source kept in version control and a copy handed to you. The domain stays in your name and you can take it anywhere.
Written by Steve Bullis
Steve Bullis is the founder of Internet Crafters, a Tucson web studio building flat-rate websites for local businesses.
Sources
Veeam - Data Trust and Resilience Report 2026 (April 2026)
veeam.com
Sophos - The State of Ransomware 2025
sophos.com
Kaseya - Backup Testing: Why Most Businesses Find Out Too Late That Their Backups Do Not Work
kaseya.com
Invenio IT - Business Continuity Statistics 2026 (citing FEMA and the U.S. Chamber of Commerce Foundation)
invenioit.com
GoDaddy Help - Upgrade Daily Backups on Web Hosting (cPanel)
godaddy.com
External links open in a new tab. Internet Crafters has no affiliation with these publications.