A version of this question keeps turning up in charity forums: what insurance do we need for our website? Wrong question. Insurance covers you if something goes wrong. What people want to know is whether they can get the site back if it does, and that is a backup question, not an insurance one. You can answer it yourself this week.
"We have backups" usually means one thing checked, not three
A backup is not one fact. It is three, and most charities only have the first.
Does a backup exist? Nearly always yes. Most hosts and most WordPress security plugins take one automatically, and the confirmation email arrives on schedule, so this box gets ticked without anyone looking twice.
Does it live somewhere other than the site itself? This is the one people miss. A backup stored on the same server as the site protects you from nothing, because whatever takes the site down takes the backup down with it, whether that is a hack, a hosting failure, or a botched plugin update. Off-site means a genuinely separate location: a different provider, cloud storage, somewhere the failure cannot reach.
Has anyone actually restored it? Almost never, and this is the gap that matters. "The backup plugin says successful" is not evidence the backup works. A backup file can be incomplete, corrupted, or missing the database half of the site without anyone finding out until the day it is needed and it fails.
What the official guidance actually says
NCSC's own guidance on this is specific: organisations should know how to restore their backups, check that a backup contains what it is supposed to, and test restoration regularly. Most small charity websites tick the first box, taking a backup, and never find out whether it works.
A test you can run this week, free
Three questions. If you cannot answer all three with a date, not a shrug, this is worth 20 minutes of your time.
- Where does the backup live? Name the provider. If the answer is "the same host as the website," that is the gap.
- When was it last confirmed to exist? Not "it should be running," an actual date you or someone checked.
- When was it last restored? To a staging copy, not the live site, just to see it actually works. If the honest answer is never, you have an assumption where you need an answer.
If your site went down tonight, whoever answers that call needs those three answers in minutes, not a guess made under pressure.
What this looks like when it is someone's actual job
We build this into how we run care plans: a recurring check with a paper trail, not a one-off audit. Which site, which backup provider, off-site or not, the date of the last backup, the date of the last restore test, the result. Every Platform care client gets a real quarterly restore test, logged with a pass or fail, not an email that says "backup complete" taken on trust.
It does not take enterprise disaster-recovery software or a dedicated IT team. It takes someone whose job it is to check, on a schedule, with a record that shows it happened.
What to ask your web supplier, in plain terms
Four questions, and you are entitled to a straight answer to all of them:
- Where do our backups live, and is that separate from where the site is hosted?
- How often are they taken?
- When was one last restored, and by whom?
- If the site went down right now, how long until it is back, and who makes that happen?
If any answer is vague, that is the actual risk your website carries, and no insurance policy changes it. Our step-by-step guide to a site that is already down covers what to do once it has happened. This is about the 20 minutes now that means you never need that guide.
If you want a second opinion on what your current setup covers, book a free 20-minute call. We will tell you honestly where the gaps are, backup or otherwise.