A website doesn’t break all at once. That would actually be easier — you would know immediately that something was wrong. Instead it decays quietly over three years while everyone assumes all is well, because typing the address still opens it.
Here is what that path looks like, step by step, as we see it in practice when we take sites over.
Year one: nothing noticeable
The site works. Nobody touches it. The system it runs on issues three or four updates that nobody installs. Plugins fall one or two versions behind. Everything still works perfectly.
Only one thing has happened in the background: the gap between what you have and what is current has started to widen. That matters, because the gap doesn’t close in a straight line. An update you would install in five minutes today means half a day’s work in two years’ time, because by then it is no longer compatible with the theme you use.
Year two: the first cracks
The contact form stops sending email. Nobody notices, because messages didn’t arrive every day before and because nobody notices an absence of messages. It is the most expensive type of failure we know — enquiries come in, you don’t get them, and the customer assumes you can’t be bothered to reply.
At the same time a few typical things pile up: the SSL certificate expires and the browser stops visitors with a warning that the site isn’t secure. The PHP version on the server goes out of date and the host announces it is being switched off. Photographs somebody uploaded straight from a camera are still there, and the site takes four seconds to load on a phone.
Year three: somebody gets in
Now comes the part companies usually don’t expect, because they assume they are not interesting enough to attack. That is a misunderstanding: nobody chose you. Bots systematically scan the internet looking for known vulnerabilities in old plugin versions. They have no interest in what you sell.
What happens next is rarely dramatic. You almost never get a ransom note. Instead, a few hundred pages appear on your site advertising things you would not want next to your name, visible to Google but not to you. Or your server starts sending spam. The first sign is often that your business email starts landing in customers’ junk folders — because your domain has ended up on a blocklist.
And that is when it turns out there is no backup
This is the moment that decides whether this was an inconvenience or a disaster.
Hosts often keep backups, but usually only a few days back — and if the site has been infected for three weeks, all of those backups are infected. If there are no backups, all that is left is rebuilding. Content somebody spent months writing is gone, apart from whatever can be dug out of a web archive.
So the only question worth asking about backups is: when was a restore from backup last tested? A backup nobody has ever tried to restore is a hypothesis, not a backup.
The quiet loss that costs more than the break-in
Through all of this something else is happening that doesn’t look like a fault. Google slowly pushes your site down, because it is slow, because it performs badly on a phone and because the content is three years old. A competitor who published ten useful pages in the meantime goes past you.
Nobody sends you a notification about that. There are simply slightly fewer enquiries each month than before, and there is always an easier explanation available — the season, the economy, the competition.
So what is the minimum
It isn’t much work. What matters is that it is assigned to somebody:
- Updates to the system, the plugins and the PHP version, regularly and not once every two years.
- Backups to a second location, with an occasional check that they can actually be restored.
- Uptime monitoring, so you don’t hear about an outage from a customer.
- Automatic renewal of SSL and the domain — and a domain registered to your company.
- Checking that the forms really send. Send a test message once a month. It is the cheapest thing on this list and the most often forgotten.
- An occasional look at mobile speed and at Search Console.
If you read that with an uncomfortable feeling
Then you probably know where you stand. The good news is that you almost never need a new site. An existing site can be taken over: collect the logins, inventory the content, run a security review and move it onto properly managed infrastructure. With us that is 290 € one-off, after which the site runs on a monthly plan from 27 €/month — with hosting, domain, SSL, email and updates; content changes are billed separately (65 €/hour or a fixed quote). The site stays yours.
If the previous supplier won’t co-operate, or can no longer be reached, that isn’t a blocker; we need access to the domain and the hosting, and the rest we can recover ourselves. The details are on the website maintenance page and the prices are in the price list.
If you would first just like to know what state the site is actually in — with no subscription and no commitment — that is what a website audit is for: a written review of visibility, speed and security within two working days, with an estimate of how much work each finding takes. Write through the contact form or call +386 40 529 425.