Off-site backups, and why location matters

Up Speed

Up Speed

Backups
Off-site backups, and why location matters

Plenty of WordPress sites have backups running perfectly. The jobs complete, the files are valid, the retention is sensible. And they are all sitting in a folder on the same server as the site they are supposed to protect.

Which works fine for the small problems and fails completely for the big ones. Location is not a technical detail. It decides which disasters your backup can actually survive.

The failures that take the backup with the site

Same-server backups protect you against exactly one category of problem: you broke something inside WordPress. Bad plugin update, deleted page, botched theme edit. For those, a local backup is genuinely useful and fast.

Here is what it does not survive:

  • Account suspension. A billing failure, an expired card, a chargeback or a terms-of-service flag locks the whole account. Site gone, backups gone, both behind a login you no longer have.
  • Malware. Serious infections spread across the filesystem. Your backup folder is part of that filesystem. Worse, if the infection sat unnoticed for weeks, your recent local backups are infected copies.
  • Ransomware. Encryption tools deliberately hunt for backup directories. Leaving the only copy where the site lives is leaving it where the attacker is already standing.
  • A host going down or going away. Providers get acquired, close down, or have genuinely bad days. If your only copy is on their hardware, you wait as long as they take.
  • Someone deleting the wrong thing. A cleanup script, a tidy-minded contractor, or you at 11pm. Local backups get removed along with everything else.

The pattern is simple. If the backup shares a fate with the site, it is a convenience feature, not protection.

What off-site actually means

Off-site is not another folder. It is not a subdomain. It is not a second server in the same hosting account. Off-site means a completely separate storage system, on separate infrastructure, reachable with credentials that are not your hosting login.

In practice that is object storage or cloud storage: S3-compatible buckets, Google Drive, Dropbox, or a dedicated backup provider. The test is straightforward. If your hosting account was suspended right now, could you still download your backup? If the answer is no, the backup is not off-site, wherever the control panel says it is.

The fix: log into your backup tool and find the storage destination. If it says "local", "server", or a path starting with /home/, you have same-server backups. Add a remote destination today, even a free Drive account is a massive improvement on nothing.

Different provider, not just different building

There is a subtler version of the same mistake. Some hosts offer "off-site backups" that are stored in a different data centre but still inside the same company and the same account. That covers a hardware or data centre failure. It does not cover the far more common problem, which is losing access to the account itself.

The old rule still holds up: three copies of your data, on two different types of storage, one of them somewhere else entirely. You do not need to be religious about it. Just make sure at least one copy is somewhere your host has no control over.

The other reason location matters: where in the world

If you handle personal data from customers in the EU or UK, backups count as personal data. They are subject to the same rules as your live database, including where they can be stored and how long you keep them. A backup quietly replicating to a region you never chose is a compliance problem hiding in a settings page.

Practical geography also affects restores. Restoring a large site from storage on the other side of the world adds real time to a bad day. Not a disaster, but worth knowing before you are watching a progress bar.

The fix: if you take payments or store customer accounts, check which region your backup storage uses and write it down somewhere findable. Future you, filling in a data processing form, will be grateful.

Off-site only helps if you can reach it

One last trap. An off-site backup you cannot access is the same as no backup. That happens when the storage account is under an old employee's email, when nobody knows the credentials, or when the developer who set it up three years ago is unreachable.

Ask yourself: if you had to restore your site today, on your own, do you know where the files are and how to get to them? If retrieving your backup depends on tracking down a person, that dependency is part of your recovery plan whether you like it or not.

Making it somebody's job

Every plan at Up Speed includes scheduled off-site backups, roughly four times a month, held for 30 days, with one-click restore. Off-site meaning separate storage, not a folder on your server, so a problem with your hosting account does not erase the copy that was meant to save you.

And because a backup you have never opened is only a guess, we test restores quarterly. That is the step most hosts skip entirely.

If you would rather not be the person tracking storage destinations and expiring tokens, the Starter plan handles it from $99 a month per site, and a real person runs the restore if you ever need one.

Share this post

Start with a free WordPress site audit.

Send us your site and we will check its speed, security, backups, and update status, then write up what we found. A real person does the review.

  • No credit card required

  • No contracts, cancel anytime