Practical guide

Database backups: what they do and how recovery works

Last materially reviewed 2026-10-01

Quick answerChoose by the recovery you need, not by the green backup badge.
What to know

Name the event first

A database backup preserves data for later restoration. Recovery uses that copy and its dependencies to return an application to useful operation. A deleted table, a lost server and a compromised storage account are different incidents. Write the event you need to recover from, then name the data, configuration and access needed. CISA recommends protected offline backups and regular recovery testing; this is general guidance, not an endorsement of any service.

What to know

Compare three operating models

An included managed-database backup is convenient but remains bounded by that provider’s retention and recovery options. Native tools give you control but leave scheduling, storage, monitoring and rehearsals to your team. An orchestration service can centralize recurring jobs, yet still needs credentials, reachable databases and an operator who owns exceptions.

What to know

Keep the smallest adequate answer

Do not add a subscription merely to have another dashboard. Keep an existing process if someone can identify a usable recovery point, retrieve it without the production account, restore it safely and demonstrate the application checks. Add a tool when a named gap—such as unowned failed jobs across providers—justifies its ongoing cost.

What to know

A decision you can record

Fictional team: two databases on separate providers and one weekly manual dump. The weakness is not database count; it is that nobody notices a missed dump. Compare alert ownership and offsite recovery before comparing storage allowances. If the team instead needs continuous failover, a scheduled-dump product alone is not the answer.

What to know

What happens between copying and recovery?

The lifecycle has four separate steps: produce an appropriate artifact, retain it where it can be reached, restore it into a compatible target, and accept the application behavior. Give each step an owner and an evidence reference. A successful upload answers only the second step’s transport question. For a small order system, the accepted result might be opening an approved sample order with its attachment while outbound notifications remain disabled. This makes the purchasing brief about an observable result rather than about collecting more backup features.

Continue when useful

Next: Recovery objectives

Separate acceptable data loss from acceptable time to recover.

Open Recovery objectives →

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. PostgreSQL: backup and restore — Platform documentation · postgresql.org · Merchant-controlled · checked 2026-10-01
  2. SimpleBackups database backup overview — Merchant documentation · simplebackups.com · Merchant-controlled · checked 2026-10-01
  3. CISA: StopRansomware Guide — Regulatory guidance · cisa.gov · Publisher independence not verified · checked 2026-10-01