A real website backup usually needs more than the visible files. Depending on the platform, you may also need the database, uploads, configuration and a clear restore path.
A backup is useful only if you can recover from it
Copying a folder to your computer is not necessarily a complete backup. A business website may depend on a database, uploaded files, configuration, scheduled jobs and external services.
1. Identify what makes the site work
For a CMS, identify the database and uploaded media as well as the application files. For a custom application, identify environment configuration and deployment dependencies. Never place passwords or API secrets into an insecure backup location.
2. Create a known recovery point
Take the backup before the change you are about to make. Label it with the date and what was about to change so the recovery point is easy to identify later.
3. Keep the backup somewhere separate
A backup stored only on the same server does not protect you from a server failure or account problem. Keep an independent copy with appropriate access control.
4. Know how restoration works
A backup is not proven until you know how it would be restored. For important sites, periodically test restoration in a staging environment or another safe location.
5. Back up before DNS or hosting changes too
Website files are not the only risk. Before changing hosting or DNS, record the existing configuration and make sure you can reconstruct the previous state.
Make backups part of the process
The best time to discover a missing backup is not after the website breaks. Include a recovery step in maintenance, migration and major update procedures.