All The Foundations

Backups and What Breaks

The short list of what actually goes wrong — the expired card, the hacked plugin, the lost laptop, the untested backup — and the minimal safety net for each.

Digital disasters in small practices are boring. No one is targeting you personally; there is no cinematic hacker. What actually happens is a credit card expires quietly, a plugin goes eighteen months without updates, a laptop bag is left on a train, or — the classic — the backup that's "definitely running" turns out, on the day it's needed, to be a setting nobody ever tested. The failure list is short and known, which is the good news: a threat list this predictable can be fully covered by a safety net this small.

What actually breaks, in order of likelihood: payment lapses (the expired card silently killing the domain, the hosting, the email); stale software (the unpatched site system or plugin — the actual cause of nearly every small-practice "hack," all of it automated and impersonal); account lockouts (the password nobody wrote down, the two-factor phone that left with the departed provider or employee); lost devices; and backups that were never tested. Not on the list: sophisticated attacks on your practice specifically. The mundane kills; the mundane is preventable.

The minimal safety net

Against payment lapses: every foundational service — domain, hosting, email — on one business card that gets updated first when reissued, with renewal notices reaching an inbox someone reads. One annual fifteen-minute review of "what renews where, from what card" (the audit's billing pass) closes this permanently.

Against stale software: know who updates your site's software, and confirm it's someone. On managed platforms it's automatic — a real argument for them. On self-managed conventional sites, it's a named responsibility (yours or a maintenance arrangement) — and an "anything pending?" glance monthly. Unowned updates are how practice sites end up serving pharmaceutical spam and vanishing from search until cleaned.

Against lockouts: a password manager for the practice, holding the credentials and recovery codes for the accounts that matter — with emergency access configured so exactly two trusted people can get in. Two-factor everywhere, with recovery codes stored, and never tied solely to one person's personal phone number.

Against loss: device encryption on (a checkbox on modern laptops and phones), and client files living in synced practice storage rather than solely on any single machine — which converts a lost laptop from a breach-plus-catastrophe into an inconvenience plus a password reset.

Against untested backups: the rule that separates real safety from vibes — a backup exists when you have restored from it. Once a year, actually retrieve something: a file from the practice storage's history, a page from the site backup. Ten minutes, and you now know — about both the backup and the procedure. What needs backing up is shorter than feared: the site's content, the client record, the list, the practice files. Most of it already lives in systems with export buttons — the discipline is pressing them on a schedule, and storing the exports somewhere that isn't the same account.

Questions practices actually ask

Isn't this my web person's / IT person's job? The doing, perhaps; the knowing it's done is unavoidably the owner's — the same split as everywhere in the foundations. The annual restore test is precisely a test of whoever claims to have this covered.

What about ransomware and the scary things in the news? For a small practice, the entry doors are the mundane list above — stale software and phished passwords. Cover those and you've closed the doors the automated attacks actually use; the news-grade threats target infrastructure you don't run.

Client confidentiality raises the stakes — does that change the plan? It raises the duty, same plan: encryption, access control, tested backups, and knowing where data lives are the technical half of confidentiality. Your professional body's rules may add specifics; the net above is the floor beneath all of them.

How much should all this cost? Almost nothing but habit: the password manager is coffee money, encryption and two-factor are free, exports are free, the restore test is ten minutes. The expensive version of this page is only ever the one where it wasn't done.


Part of The Foundations — the ground everything stands on.

Explore further

Based on the themes in this article, you might find these topics interesting.