Website Backup Strategy for Canadian SMBs That Survives Ransomware

Share it:

The right website backup strategy combines multiple locations and media types, at least one offline or immutable copy, encryption, and scheduled restore tests, following the 3-2-1 model (or 3-2-1-1-0 for higher-risk sites). Set your recovery time and recovery point objectives first, since they determine how often you back up and how long recovery takes.


TL;DR:

  • Offline or air-gapped backups are essential to protect against ransomware targeting connected storage and cloud drives.
  • The backup strategy should include at least three copies stored on two media types, with one copy off-site or offline, depending on the site’s risk level.
  • Regular restore tests, ideally monthly, verify backups are functional and prevent reliance on untested copies during emergencies.
  • For high-risk sites, adopting the 3-2-1-1-0 model with daily incremental backups, offline storage, and zero error confirmation is recommended.
  • Storing encryption keys and source code separately from backups minimizes recovery delays caused by credential loss or compromise.

Courimo
Build A Stronger Online Presence
Courimo helps small and medium-sized businesses strengthen their websites and digital marketing with SEO, web development, and measurable growth strategies.

Table of Contents

Why backups matter and the threat landscape for websites

A backup is only as good as the disaster it survives, and websites fail in more ways than most owners expect.

  • Ransomware encrypts or deletes live files and often searches connected drives and cloud folders for backups to destroy them too.
  • Human error wipes a database table, overwrites a config file, or deletes the wrong plugin during an update.
  • Hosting outages or account suspensions can lock you out of both your site and any backups stored in the same account.
  • Malicious plugin or theme code can sit undetected for weeks, meaning a backup created after the compromise brings the problem back with it.

Ransomware behavior specifically changes how you should think about storage. Attackers who gain access to a server often hunt for backup files and connected cloud drives before triggering encryption, which is why an isolated, offline copy matters more than a second copy sitting in the same account. The Canadian Centre for Cyber Security’s ransomware playbook recommends maintaining multiple offline copies and scanning backups before restoring them, precisely so a restore doesn’t reintroduce the malware that caused the outage.

The Canadian Centre for Cyber Security recommends testing backups on a recurring basis, such as monthly, in an isolated environment, to confirm that restores actually work before you need one.

The 3-2-1 rule and modern variants for higher risk

The 3-2-1 backup rule is the baseline nearly every serious data protection framework builds on: keep at least three copies of your data, store them on two different types of media, and keep at least one copy off-site. Applied to a website, that typically looks like:

  • Copy one: the live site on your production server.
  • Copy two: an automated cloud backup or snapshot stored with a different provider than your host.
  • Copy three: an offline copy on an external drive or cold storage, disconnected from any network.

Ransomware’s habit of hunting down connected backups pushed the model further. The 3-2-1-1 variant adds a requirement that one copy be offline or air-gapped, and 3-2-1-1-0 adds a zero, meaning zero errors confirmed through regular restore testing. CISA’s StopRansomware guide points to the same core ideas: offline encrypted backups, regular testing, and immutable storage that attackers can’t quietly delete.

Which variant fits depends on what you’re protecting. A brochure site with no database beyond basic content can usually run safely on 3-2-1 with monthly testing. An ecommerce site processing orders and payment data needs 3-2-1-1 at minimum, with daily backups and an offline copy refreshed weekly. A SaaS product or membership site with constant user data changes should run 3-2-1-1-0, treating restore testing as a scheduled operational task rather than an occasional check.

What exactly to back up on a website

Most backup failures aren’t caused by missing backups. They’re caused by incomplete ones. A full, restorable website backup needs more than the files a visitor sees.

  1. Website files: themes, plugins, custom code, and the core CMS installation.
  2. Uploaded media: images, PDFs, videos, and any user-generated content.
  3. Database dumps: every table, including orders, users, and custom post types.
  4. Environment variables and config files: server settings, .env files, and application configuration.
  5. Scheduled tasks: cron jobs and any automation tied to the site.
  6. DNS zone files: records for your domain, mail routing, and subdomains.
  7. SSL certificates and private keys: needed to restore secure connections without a reissue delay.
  8. API keys and third-party credentials: payment gateway configs, email service keys, analytics IDs.
  9. Logs: server and application logs, useful for both recovery and forensic review after an incident.

The most common pitfall is backing up files but not the database, which leaves you with a shell of a site and none of its content or orders. A close second is relying entirely on hosting-provider snapshots stored in the same account: if that account is compromised or suspended, the backup goes with it.

Pro Tip: Keep a copy of software license keys and a snapshot of your source code somewhere offline, separate from your hosting and cloud accounts, so a rebuild doesn’t stall on a licensing lookup you can no longer access.

Storage and ransomware defenses that actually hold up

Where you store a backup matters as much as how often you make one. An encrypted backup sitting in the same cloud account as your production site is still one stolen password away from being deleted.

Offline, air-gapped backups solve the connectivity problem directly: a drive that isn’t plugged in when ransomware hits can’t be encrypted by it. A practical workflow is to export a full backup weekly or monthly, copy it to an external drive, disconnect the drive, and store it separately from your main office or server room. The Cyber Centre’s ransomware playbook also recommends keeping golden images of critical systems and considering where your offsite storage physically resides when choosing a provider.

Immutable storage and object lock features, available from several cloud storage providers, prevent a backup from being altered or deleted for a set retention period, even by an account administrator. That protects against both attackers and accidental deletion, though it’s worth confirming the retention lock actually applies to the backup tier you’re paying for, not just to the storage class’ default settings.

Automatic backups tied to your production hosting account carry a specific risk: if credentials are stolen, an attacker can potentially reach and remove those backups too, or an automatic sync can overwrite good backups with already-encrypted files. Mitigations include:

  • Using a separate backup account with its own login, not linked to the main hosting or cloud account.
  • Storing at least one copy with a different provider than your host, so a single compromised vendor relationship doesn’t take out everything.
  • Confirming your provider’s data residency and security practices before trusting them with sensitive backups.

Pro Tip: Turn on multi-factor authentication for every account that touches your backups, not just your main hosting login: backup storage is often the weaker link attackers go looking for.

Encryption and access control round this out. Encrypt backups both in transit and at rest, restrict who can access backup storage on a least-privilege basis, and review that access list whenever someone leaves the team.

Setting RTO and RPO before you set a backup schedule

Two numbers should drive every decision about backup frequency: recovery time objective (RTO), how long you can tolerate being down, and recovery point objective (RPO), how much data you can afford to lose measured in time. A four-hour RPO means you can lose up to four hours of orders or content changes; anything more and the business impact grows.

These targets should shape your backup cadence directly, not the other way around:

  1. Low-traffic brochure site: RTO of 24 to 48 hours, RPO of one week, supported by weekly full backups.
  2. Small ecommerce store: RTO of a few hours, RPO of 24 hours or less, supported by daily full backups plus incremental backups through the day.
  3. Membership or SaaS platform: RTO under an hour where possible, RPO of minutes to hours, supported by continuous or near-continuous database backups alongside daily file backups.

Retention windows matter as much as frequency. Keeping only the most recent backup means a malicious or accidental change that goes unnoticed for a few days overwrites your last clean copy. Versioned retention, such as keeping daily backups for two weeks, weekly backups for two months, and monthly backups for a year, gives you room to roll back to a point before the damage happened rather than just the most recent snapshot.

Backup testing in an isolated environment is the step most guidance treats as non-optional, since a backup that has never been restored is really just an assumption.

Isolated backup restore test process

Building the plan step by step

A backup strategy is only as strong as the process behind it. Here’s a sequence a small team can realistically follow and maintain.

  1. Inventory every asset and assign criticality. List files, databases, DNS records, SSL certificates, third-party credentials, and integrations. Mark which ones must come back online first: for most sites, that’s the database and core files, followed by media and configuration.

  2. Select your storage mix and access model. Pick at least two media types and two locations, with one offline or immutable. Decide who has access to backup storage and require multi-factor authentication on every account involved.

  3. Set retention per your RTO and RPO. Match backup frequency to how much data loss you can tolerate, and set a retention schedule that keeps enough historical versions to roll back a bad change discovered days or weeks later.

  4. Automate full and incremental backups. Full backups capture everything; incremental backups capture only what changed since the last one, which keeps storage costs down for sites with frequent updates. Schedule the offline snapshot separately, since it usually can’t be fully automated if it requires physically disconnecting a drive.

  5. Set up alerting for failed jobs. A backup job that silently fails for three weeks is worse than no backup plan at all, because it creates false confidence. Route failure alerts to email or a monitoring dashboard someone actually checks.

  6. Write a restore runbook. Document the exact order of operations: which network segments to isolate if it’s a security incident, how to verify a backup’s integrity before restoring it, database restore before file restore, certificate and key reissue or restoration, then reconnecting dependent services and validating transactions and logs. A runbook turns a stressful recovery into a checklist.

  7. Test restores in isolated staging, not production. Spin up a staging environment, restore your most recent backup into it, and confirm the site actually works: pages load, forms submit, checkout completes if applicable. Scan restored files for malware before ever promoting them back to production, particularly after a ransomware event.

  8. Document every test, including failures. A test that reveals a broken restore is more valuable than one that passes, because it caught the problem before an actual outage did. Log what failed, what you fixed, and when you last confirmed a clean restore.

  9. Maintain golden images and keep backup hardware current. A golden image of your server or application stack shortens rebuild time significantly compared to reconstructing configuration from memory. Keep the firmware and software on any backup appliance or NAS device updated, since outdated backup software is itself a vulnerability.

  10. Review the plan after every incident, near miss, or major site change. A new plugin, a platform migration, or a payment gateway swap can quietly break what your backup captures. Revisit the inventory and runbook whenever the site’s architecture changes meaningfully.

Pro Tip: Schedule restore tests on a recurring calendar invite, the same way you’d schedule a security patch, so testing survives staff turnover instead of depending on one person remembering to do it.

If your site runs on WordPress or another CMS with frequent plugin updates, pair this with the prelaunch checks that protect search rankings during a migration, since a restore is effectively a small migration and can quietly undo SEO work if redirects or metadata aren’t preserved.

Where Courimo fits for teams that build and maintain sites

Courimo is a Montreal-based digital marketing agency, and its website development services include hosting, website maintenance plans, and global web strategy work built around keeping client sites running and recoverable.

  • Website Development and Web Hosting, for teams that want their backup and recovery infrastructure managed by the same team that built the site.
  • Website Maintenance Plan, covering the ongoing technical upkeep that a solid backup strategy depends on.
  • A free website quote within 24 hours, for businesses evaluating whether their current setup needs a rebuild or a managed maintenance arrangement.

Before restoring a site after any incident, it’s worth checking the basics that keep it fast once it’s back, including caching and CDN configuration, since a restore sometimes reverts performance settings along with content.

What a defensible minimum looks like

Most small businesses overthink the technology and underinvest in the habit. A defensible minimum is daily offsite backups, a weekly offline snapshot, and a monthly restore test, documented each time. That combination catches the overwhelming majority of real-world failures: accidental deletion, a bad plugin update, a compromised account.

Faster recovery, hot failover, or SLA-backed hosting is worth paying for once downtime has a direct revenue cost, not before. Automation and a written runbook do more to prevent a bad day than any single tool, because most recovery failures come from a step someone forgot under pressure, not from a missing backup.

— Ruthwik

A managed option if you’d rather not run this yourself

Running a compliant backup strategy takes ongoing attention: scheduling, encryption, access reviews, and restore tests that actually get done instead of postponed. For businesses that would rather hand that off, Courimo’s website and hosting services are built around keeping a site both running and recoverable.

Courimo

A managed maintenance arrangement typically covers the operational aspects of scheduled backups with encrypted storage aligned to recovery needs, restore testing and documentation to verify recovery plans, and ongoing hosting and maintenance support for teams seeking to outsource backup management.

If you want a specific assessment of what your current site needs, you can request a free website quote within 24 hours and get a direct answer on what a managed setup would look like for your site.

Where to go for official backup and ransomware guidance

For policy-level guidance on structuring a backup strategy, the Canadian Centre for Cyber Security’s tips on backing up your information covers the 3-2-1 rule, encryption, and testing cadence in plain terms.

Sources

FAQ

What is the 3-2-1 rule for backing up?

The 3-2-1 rule means keeping at least three copies of your data, stored on two different types of media, with at least one copy kept off-site. The Canadian Centre for Cyber Security recommends this as a baseline, paired with encryption and regular restore testing.

What is the 3-2-1-1-0 backup rule?

The 3-2-1-1-0 rule builds on 3-2-1 by requiring that one of your backup copies be offline or air-gapped, and it adds a zero representing zero errors confirmed through recurring restore tests. It’s aimed specifically at ransomware resilience, since offline copies can’t be reached or encrypted by malware operating on a live network.

What are the three types of backup strategies?

The three common backup types are full backups, which copy everything each time; incremental backups, which copy only what changed since the last backup; and differential backups, which copy everything changed since the last full backup. Most website backup plans combine full backups on a set schedule with incremental backups in between to save storage space and time.

How do you back up a website?

Backing up a website means capturing your files, database, configuration settings, DNS records, and SSL certificates, then storing copies in at least two locations with one kept offline or immutable. Automate the process where possible, encrypt the backups, and test a full restore in an isolated environment on a recurring schedule to confirm it actually works.

How often should I test my website backups?

Restore testing should happen regularly, and more often for sites handling frequent transactions or sensitive data. The Canadian Centre for Cyber Security recommends testing in an isolated environment so a failed restore never surfaces for the first time during an actual outage.