Cloud Computing · BACKUP

A Backup That Doesn’t Work? The Story of a Company That Lost Everything Over One Mistake

Remote Admin SysOps Team·April 24, 2026·6 min read

It was a Friday evening. Marta, the owner of a fast-growing online store selling children’s accessories, had just closed her laptop. The best sales month in the company’s history. 240 orders, tens of thousands of zloty in revenue. Everything was going perfectly.

On Saturday morning she woke up to a notification from her bank – zero incoming online payments. The store’s website wasn’t working. Instead of products, it displayed a database error message. An hour of login attempts, two calls to the IT specialist, and one devastating diagnosis: the server had crashed. The database was corrupted beyond repair.

“But we have a backup!” Marta was convinced this was just a temporary problem.

The technician was silent for a long moment. Then he said something that chilled her to the bone: “Unfortunately, the backup was only ever made to the same server. The copy is corrupted too. There’s nothing to recover.”

240 orders, customer data, transaction history, product descriptions, photos – all gone. The company she had spent three years building disappeared in a single night. The reason? One mistake: a false sense of security created by a backup that didn’t meet even the basic standards.

Marta’s story is not an exception. In 2026, with ransomware attacks constantly on the rise and infrastructure failures growing more sophisticated, thousands of companies in Poland still live by the assumption that “it’ll probably be fine.” Let’s check whether your company might be heading down the same road.

Why is most company backup an illusion of security?

Over years of working with clients, we’ve seen dozens of situations where business owners were absolutely convinced they had a backup. When a crisis hit, it turned out their backup hadn’t worked for weeks, was stored in the same location as the production data, or – worse still – didn’t cover key elements at all.

Many decision-makers still confuse two fundamentally different mechanisms: the snapshot and the full-fledged backup. This isn’t an academic distinction – it’s the line between a quick return to business after an incident and total bankruptcy. A snapshot is a virtual “photo” of a machine’s state at a given moment, tied to the original disk array – if that array fails or gets encrypted by ransomware, the snapshot disappears with it. We explained this crucial difference in detail in our article on intelligent backup as the foundation of a Disaster Recovery strategy.

A real backup is a fully independent, compressed, and encrypted copy of your data, stored on a completely different medium and in a different location. A mechanism that lets you recover your infrastructure even if your primary server literally burns down.

The ironclad 3-2-1 rule – the standard without which you don’t have a backup

If there’s only one thing you remember from this article, let it be this. The 3-2-1 rule is a proven engineering standard that has saved companies from disaster for years. In 2026 it’s no longer just a good practice – it’s an audit requirement and often a legal one too (particularly in the context of NIS2 and DORA). We covered it in detail in our guide on effective data backup.

The rule is simple:

  • 3 copies of your data – the original plus two independent backup copies. Not one. Not “somewhere out there.” Three.
  • 2 different media types – copies stored on two different types of media (e.g., a disk array and object storage), so a failure of one media type doesn’t destroy everything.
  • 1 off-site (isolated) copy – at least one copy must be located in a physically separate data center, completely isolated from the main network.

Failing to implement these standards means any IT security audit will end in a devastating verdict – and in the event of a real incident, you’re left with nothing.

WordPress backups – do they really cover everything you need?

Owners of WordPress and WooCommerce-based sites are a particular risk group. Many of them install a free backup plugin, tick “back up everything,” and consider the matter closed. The reality is brutal – most simple plugins:

  • Don’t back up files outside the wp-content directory.
  • Don’t secure the database transactionally (meaning the copy may be inconsistent).
  • Store the backup on the same server as the site.
  • Don’t automatically test whether the backup can actually be restored.

In practice, this means that at the moment of failure you may discover your backup is useless. We described step by step what a proper backup setup should look like for a WooCommerce store in our guide on a secure WooCommerce store.

Disaster Recovery – what to do when the worst actually happens?

Backup is only half the battle. The other half is the ability to quickly restore your data and get the business running again. A Disaster Recovery (DR) plan is a detailed procedure that spells out who restores what, in what order, and within what timeframe after a failure.

Without a DR plan, even the best backup can turn out to be useless – because in the panic, no one will know where to start. In 2026, given the scale of ransomware threats and the requirements of the NIS2 directive, a Disaster Recovery plan is an absolute must-have for every company.

How do you check whether your backup actually works?

You already know the theory. Time for a practical test. Answer the following questions honestly – if you answer “no” or “I don’t know” to any of them, you’re in the risk group:

  1. Do you have at least three copies of your key data? (not counting the original)
  2. Is at least one copy physically located away from where your main server sits?
  3. Have you tested restoring your backup on a clean environment within the last 30 days?
  4. Does your backup cover files, databases, AND company email?
  5. Do you have a documented procedure that spells out what to do, minute by minute, in the event of a failure?

If you answered “no” to even one of these questions, your backup isn’t a backup – it’s a hope. And you can’t rebuild a company on hope.

A backup that lets you sleep at night – how we do it at Remote Admin

At Remote Admin, we don’t believe in half measures. That’s why every one of our hosting packages – from Micro at PLN 9.99 to Cloud Medium – includes a daily, automatic backup covering files, databases, and email. Copies are stored on separate media, encrypted, and ready to restore within minutes. You’ll find the details on our hosting page.

For companies that need an even higher level of security – compliant with NIS2, DORA, or audit requirements – we offer a dedicated Data Backup service, which includes:

  • Backup for VPS, bare metal, and company computers.
  • Copy storage across multiple locations (multi-region).
  • Data encryption, deduplication, and compression.
  • Regular restore testing.
  • Compliance with GDPR, NIS2, DORA, and MiCA.

Don’t wait for your own “Friday evening”

Marta, the owner of the children’s accessories store, had to start from scratch. A new website, re-entering products, recreating descriptions from Google Cache screenshots. Her store was back up and running after three months – but the customers who found a competitor in the meantime never came back.

This story doesn’t have to be yours. A reliable data backup isn’t an investment in technology – it’s an investment in peace of mind and the security of everything you’ve built over the years.

👉 Find out whether your backup really works – book a free consultation:

Check out our hosting plans with daily backup → | Order a dedicated Data Backup service →