GPS (Geek Powered Solutions) informed us that the site host (WPengine.com) takes automatic backups and keeps them for about 30 days.
GPS recommended that we either rely on the nightly backups before performing any site changes or that we contact GPS first and ask them to take an on-demand backup.
GPS said that if we need to restore from a backup of the entire site that we need to contact them, as Errigal doesn't have access. This is because GPS owns the WPengine account and we pay them a fee for it.
Regarding keeping up to date, GPS recommended that we follow the Wordpress development blog, so that we can be aware of any pending updates.
WPengine automatically applies Wordpress updates to all sites to keep it up to date for security.
GPS recommended that we do not update the theme, as it could break any custom code on the site.
GPS reminded us that we have a staging site enabled, so it is possible to update the plugins on the staging site and test it without applying them to the main site. We should probably do this going forward, and just update the plugins on a quarterly or semi-annual basis.