You take a snapshot before updating your VPS. The update fails, you restore the snapshot, and your website works again. That is a useful recovery tool—but it does not answer what happens if your hosting account is compromised or essential data lives outside the server’s main disk.
Snapshots and backups can overlap technically. The important questions are what they capture, how long they survive, and whether you can restore them after the failure you are trying to protect against.
A Snapshot Records a Point in Time
A disk snapshot preserves a recoverable view of storage at a particular moment. Its implementation depends on the platform: the word alone does not tell you whether it is independent of the original storage.
DigitalOcean, for example, describes its snapshots as on-demand disk images. They remain available after the original Droplet is deleted and can be used to create another server. The company also says it backs snapshots up offsite.
This makes a snapshot useful before a risky configuration change. However, restoring Monday’s image on Thursday also returns the captured disk to Monday’s state. Later orders, uploads or edits need another recovery source.
A Backup Service Adds Scheduling and Retention
A managed backup service commonly creates recovery points automatically and keeps them according to a retention policy. It may use snapshots internally: DigitalOcean explicitly describes its backups as snapshot-based.
Frequency determines how far apart your recovery points are. Retention determines how far back you can go. A daily copy is not necessarily sufficient for an application that cannot afford to lose a day of transactions.
Check What the Copy Leaves Out
A server image is not automatically a backup of the entire application. Attached storage, an external database and files stored in another service may require separate protection.
Both Hetzner’s cloud-server images and DigitalOcean’s automated Droplet backups exclude attached volumes. If your website uploads live on such a volume, restoring the system disk alone will not recover them.
Database consistency also matters. Hetzner recommends powering off a server before creating an image to ensure disk consistency. DigitalOcean describes its running-server backups as crash-consistent. Neither description should replace checking your database’s supported backup and recovery procedure.
Deletion Rules Can Surprise You
At Hetzner, deleting a cloud server also deletes its associated backups, while snapshots survive. This is a provider-specific rule, not a universal distinction between the two technologies.
Storage location is another separate question. DigitalOcean documents that automated Droplet backups remain in the same data center as the source server. Check the actual placement and access controls rather than assuming that “backup” means a separate region or account.
Build a Recovery Plan You Can Test
CISA recommends offline, encrypted backups and regular recovery testing as part of ransomware preparedness. A copy that an attacker can delete using the same compromised credentials may fail when you need it.
For a first VPS, use this practical checklist:
- List the data: system configuration, application files, databases, uploads and attached storage.
- Set recovery targets: decide how much recent data you can lose and how long the service can remain unavailable.
- Protect recovery copies: choose retention and isolation that address accidental deletion and compromised access.
- Restore into an isolated test environment: prevent the restored application from sending real emails, taking payments or running production jobs.
- Verify the application: check records, uploads and login functionality, and record how long recovery takes.
A successful backup notification confirms that a job finished. A tested restore gives you evidence that the service can actually be recovered.







