A website is never really finished. It just stops changing, which looks the same from the outside for about eighteen months.
The jobs that keep one working are individually small, none of them urgent on any particular day, and collectively the difference between a website that still earns its keep in three years and one that has quietly stopped. They are also the jobs most likely to end up assigned to nobody, because they arrive after the launch, after the invoice, and after everyone has moved on to the next thing.
What the actual jobs are
Renewals. The domain, the hosting and the security certificate all expire on their own schedules. The domain is the one with real consequences — when it lapses, the website and your email stop together, and recovery gets more expensive the longer it takes. I have written that up separately in what happens when a domain quietly expires.
Updates. If the website runs on a platform like WordPress, the platform and its plugins release updates constantly, and a good share of those are security fixes for problems that are already public. An unpatched plugin is the most common route by which a small business website gets defaced or quietly turned into something serving spam. Updates also occasionally break things, which is the reason the next item exists.
Backups you have actually tested. Most hosting includes backups. Considerably fewer businesses have ever tried restoring one. A backup nobody has tested is a plan rather than a safeguard, and the moment you discover the difference is the worst possible moment.
Uptime monitoring. Something that checks the website every few minutes and tells you when it is not answering. There are free services for this. Without one, you find out from a customer, and only if they bother to mention it.
Form deliverability. Enquiry forms stop working silently and more often than people expect — a mail setting changes, a plugin updates, a forwarding address is closed, a spam filter gets stricter. Nothing on the website looks wrong. Enquiries simply stop, and it reads like a quiet month.
Content that has gone out of date. Prices, opening hours, staff who have left, a service you no longer offer, a copyright year in the footer that stopped at 2021. Individually trivial; together they are the main reason a website reads as neglected to a visitor deciding whether you are still trading.
Broken links. Both internal ones and links out to other websites that have since moved or closed. A free link checker will find them all in one pass.
Old access. Accounts belonging to people who have left, the developer from two agencies ago, a shared password in a group chat. Worth a review once a year.
Two of these — a test restore of a backup, and a test enquiry through your own form — are things you can do this week and almost nobody has done. They cover the two failures that are invisible until they matter.
Who is doing it
There are four honest answers, and only the last one is a problem.
You, or someone in the business. Entirely workable if it is written down and diarised. It needs to be someone specific rather than "the office", because a job owned by everybody is owned by nobody.
Whoever built it, informally. Very common and fine while it lasts. The risk is that it depends on one relationship and one person's memory, and there is no agreement about what is covered, so both sides quietly assume different things.
A care plan or maintenance arrangement. A monthly arrangement with defined scope. The value is that the small jobs happen on a schedule rather than when somebody notices.
Nobody. This is the common one, and it is rarely a decision. It is what happens when a launch goes well, the developer's involvement tapers off, and no one ever says out loud that the ongoing jobs are now unassigned. Two years later the copyright line reads 2024, three plugins are out of date, and the form has not delivered anything since March.
You do not need to buy anything to fix this. You need to name who is responsible and write down what that involves. If the answer is you, that is a legitimate answer — an unwritten answer is not.
If you are considering a paid arrangement
Care plans vary enormously in what they actually contain, so it is worth asking for the specifics rather than the summary:
- What is included, itemised? Hosting, updates, backups, monitoring, certificate renewal — and whether the domain is in there or billed separately.
- How much content change is covered, and what counts as a change versus a new piece of work. This is where most disagreements start.
- What is the response time if the website goes down on a Saturday? An honest "next working day" is more useful than a vague promise.
- Do I get told what was done? A short monthly note is the thing that keeps the arrangement honest in both directions, and it is a reasonable thing to expect.
- What happens if I leave? Where the website goes and what I take with me. Worth agreeing at the start rather than at the end.
The minimum, if you do nothing else
Four calendar reminders and one page of notes:
- Monthly: send yourself a test enquiry through the form.
- Quarterly: read the homepage and contact page as a stranger would, and fix whatever has gone out of date.
- Annually: check the domain renewal, the registrant name and who has access.
- Once, now: restore a backup somewhere safe and confirm it works.
That is perhaps two hours a year, and it covers most of what actually goes wrong. It is not sophisticated, and the reason I keep writing about the unsophisticated end of this is that the survey I ran found the faults were concentrated there — the ordinary maintenance that had stopped, not the ambitious work that was never attempted.
The full list of what a website needs to get right is in what a small business website actually needs. If you would rather this ran on a schedule without you holding it, the Website Care Plan and the other recurring items are set out on the Services page, with the rates published there.
