Your hosting is where your website lives: the server, the computer that shows your site to the world. “Managed” hosting should mean someone looks after that server for you, but the word gets stretched a long way. For some providers it means a dashboard and a padlock certificate (your site's secure connection) that renews itself. For others it means a team that applies updates, keeps watch, takes backups and steps in when something breaks. Both are sold under the same label, so it is worth knowing what to ask for.
This is the checklist we use when we take over a website or online system, and the standard we hold our own hosting to. You don't need to be technical to use it. At the end there is a short list of questions you can put to any provider.
1. Updates on a schedule, with a safety net
Everything that runs your website needs updating. That includes the site itself: if it is built with WordPress, a widely used system for building websites, that means WordPress and every plugin (add-on) it uses. It also includes the layers of software on the server that you never see. Ask who applies each of these, how often, and what happens first. The right answer is a schedule, a backup taken just before, and a check afterwards that your site still works.
2. Backups you know will work
- Copies are kept away from the server they protect, ideally with a different company.
- They include both your files and your site's data, such as pages, orders and customer accounts, copied together so the two match.
- Old copies are kept long enough to recover from a problem noticed late, such as a hacked plugin found weeks afterwards.
- Restoring is tested: someone actually puts a copy back to check it works. A backup that has never been restored is a hope, not a plan.
3. A person warned when something goes wrong
As a minimum, there should be automatic checks, made from outside, that your site is online. There should also be warnings before the padlock certificate expires, before the server runs out of space, and when the site shows errors. For systems your business can't do without, add security monitoring on the server itself, which looks out for signs of a break-in. Then ask the question that matters: when a warning goes off, who receives it, and what do they do?
4. Knowing who can get into your server
Every person and every system that can get into your server should have its own named account and its own key. With shared passwords and a single master login, it is impossible to know who changed what, or to remove someone's access when they leave. Ask for a list of who can get into your server today.
5. Security built in, not bolted on
- A firewall that keeps everything closed except what the public needs to reach.
- Admin screens reachable only through safe, private access for your team, not open to the whole internet.
- Sensible settings for the secure connection (the padlock), and for the security instructions your site gives to browsers.
- A protective filter in front of public websites, to soak up abusive traffic before it reaches your server.
- Each site and service kept separate, so if one is broken into, it cannot be used to read everything else.
6. Speed tuned to your kind of site
An online shop built with WooCommerce (the shop add-on for WordPress), a simple company website and a custom system each need a different setup to be fast. Take caching, which keeps ready-made copies of pages to show instantly. Set aggressively, it speeds up a simple website but can break the basket and customer accounts on a shop. Good managed hosting is set up for the software it actually runs, not with one template for everyone.
7. Email that lands in the inbox
If email goes out under your domain name (the part after the @ in your email address), from your team's mailboxes or from your website, your domain settings need a few email records. They must match the services actually sending it, and your provider will know them as SPF, DKIM and DMARC. Without them, your quotes and password reset emails end up in spam. This is often overlooked because it sits between the hosting, the email and the website, so check who is responsible for it.
8. Written instructions, and a way out
Ask for documentation: what is installed, how changes go live, where the backups go and how to restore them. Then ask how you would leave. Could you get a complete copy of your site, its data and your email, in standard formats another provider can use? A provider who makes leaving easy is usually confident you won't want to.
Questions to ask any hosting provider
- Who applies the updates, and when was the last one?
- When did you last restore one of my backups, and how long did it take?
- Who is warned if something stops working outside office hours?
- Who can get into my server right now?
- In which country is my data stored, and is there a data processing agreement (the contract that covers how you handle it)?
- If I leave, what do I get, and in what format?
You don't need the top plan to get good answers. What matters is that someone is clearly responsible for every point on this list. If you are not sure who looks after some of them today, it is worth finding out before something breaks. If you'd like us to check your current setup against the list, get in touch.